AYN

Information Security Manager (Job ID: 1533)

Colonna's Shipyard · Norfolk, VA

Information Security Manager

Purpose:

The Information Security Manager leads and maintains the company's cybersecurity, information assurance, compliance, and Microsoft 365 technology programs. This role protects company systems, customer information, and Controlled Unclassified Information (CUI); supports compliance with contractual and regulatory cybersecurity requirements; and serves as a senior escalation point for complex technical issues across the commercial technology environment.

The position is located onsite in Norfolk, VA and will often require hours beyond a standard work week with flexible schedule availability to support production/operations. Position may require limited travel.

Job Description:

Information Security and Compliance

- Lead the organization's information security and cybersecurity programs.

- Develop, implement, and maintain cybersecurity policies, standards, procedures, and security controls.

- Manage compliance initiatives related to CMMC, NIST SP 800-171, DFARS, FAR, and customer cybersecurity requirements.

- Conduct risk assessments and oversee remediation efforts, Plans of Action and Milestones (POA&Ms), and continuous improvement activities.

- Coordinate internal and external cybersecurity audits, assessments, and evidence collection.

- Oversee incident response planning, exercises, investigations, containment, recovery, and reporting.

- Monitor threats, vulnerabilities, and emerging risks and recommend appropriate mitigation strategies.

- Manage security awareness and role-based training programs.

- Collaborate with business leaders and IT teams to implement practical security controls that support operations while reducing risk.

Microsoft 365 and Cloud Technology Management

- Manage and support the company's Microsoft 365 technology environment, including Microsoft Entra ID, Exchange Online, SharePoint Online, Microsoft Teams, Intune, Microsoft Defender, and related cloud services.

- Maintain Microsoft 365 security, identity, access, endpoint-management, governance, and compliance configurations.

- Oversee privileged access, conditional access, multifactor authentication, information protection, retention, and data loss prevention capabilities.

- Evaluate and implement Microsoft 365 features and integrations that improve security, reliability, governance, and operational efficiency.

- Coordinate licensing, service changes, platform standards, and administrative practices with IT leadership and business stakeholders.

Technical Leadership and Escalation

- Act as a senior escalation point for complex technical issues across the commercial environment, including infrastructure, cloud platforms, identity, endpoints, collaboration services, enterprise applications, and cybersecurity incidents.

- Lead or coordinate troubleshooting and resolution of high-impact technology issues affecting business operations.

- Partner with infrastructure, applications, support, and business teams to deliver secure, reliable, and supportable technology services.

- Provide technical guidance for system architecture, integrations, identity management, access control, and technology modernization initiatives.

- Support business continuity, disaster recovery, and operational resilience planning and testing.

- Mentor IT personnel on cybersecurity practices, Microsoft 365 administration, operational procedures, and advanced troubleshooting.

Governance and Strategic Planning

- Develop cybersecurity roadmaps, budgets, metrics, and strategic initiatives aligned with business objectives.

- Communicate cybersecurity risks, compliance status, technical concerns, and recommended investments to leadership.

- Support vendor risk management, third-party security reviews, and cybersecurity requirements within contracts and procurement activities.

- Evaluate emerging technologies and industry trends and recommend solutions that improve security and business operations.

Qualifications:

- Bachelor's degree in cybersecurity, information technology, information systems, computer science, or a related field; equivalent education and experience may be considered.

- Must have five (5) years of experience in information security, cybersecurity, compliance, systems administration, cloud administration, or a related technology role.

- Working knowledge of security frameworks and requirements such as NIST SP 800-171, CMMC, CIS Controls, or comparable standards.

- Hands-on experience administering Microsoft 365 and cloud-based security technologies.

- Strong leadership, communication, analytical, project-management, and advanced troubleshooting skills.

- Ability to translate security and technical risks into clear business recommendations.

- Must be able to handle difficult situations requiring a well-developed sense of strategy, timing, persuasion, and management ability.

Preferred Qualifications:

- CISSP, CISM, Security+, CRISC, Microsoft Security, or related certifications.

- Experience supporting Department of Defense contractors, CUI environments, or other regulated organizations.

- Experience coordinating CMMC assessments and cybersecurity compliance programs.

- Experience with Microsoft Defender, Microsoft Sentinel, Intune, Entra ID, Microsoft Purview, and enterprise security monitoring solutions.

Travel Requirements:

- Minimal Travel; 10% or less.

Physical Requirements:

- Sit, Stand, Walk, Bend, Squat, Climb, Reach, Push and Pull, Stoop, Crawl, Kneel, Balance, Lift and Carry various objects and equipment.

- General office environment. Work is generally sedentary in nature but may require standing and walking for up to 50% of the time.

- Specific vision abilities required by this job include close vision, peripheral vision, and the ability to adjust focus.

- Work is generally performed within an office environment, with standard office equipment available, but also requires safe navigation and regular partnership with operations teams within shipyard/industrial environments.

- Movement through the yard often requires personal protective equipment.

- Lighting and temperature are adequate and there is minimal exposure to unpleasant conditions caused by noise and dust.

Respect, Pride, Truth, Family – These are our VALUES and the guidelines that make us a leader in our industry. We are pleased and confident in stating that our skilled employees are among the most respected experts in the ship repair industry.

Colonna’s Shipyard, Inc. is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

Additionally, Colonna’s Shipyard provides a variety of benefits to support your best health, wellness, and future, to include medical/dental/vision options, company paid disability insurances, 401k with match, legal services, as well as company paid holidays and paid time off (PTO).

Pay Range: $97,334 - $126,167

Determination of base salary considers various factors, including but not limited to scope of responsibility, candidate’s relative and specific experience, education level, key skills, as well as other business considerations. The company also provides a variety of benefits to support employees’ best health and wellness. Additionally, the company offers a 401k retirement program with match, paid holidays, and competitive paid time off (PTO)

Apply on the employer’s site