Operations Roles

Industrial & Information Security

This is program-protection and information-system security, not the offensive or defensive cyber engineering STR delivers to customers. The team accredits information systems under RMF, runs facility and program security under NISPOM, manages personnel security and clearances, and establishes the physical and program protections that classified contracts require. This is the function that allows STR to hold classified work at all.

The Work
You’ll work as an ISSM, ISSE, or ISSO carrying systems through the RMF accreditation lifecycle; as a CPSO, CSSO, or FSO running program and facility security; or in personnel security, managing clearances in DISS. You’ll use AI to automate routine control assessment and documentation so you can focus on the risk decisions that require judgment. This is one of the most heavily cleared non-engineering functions at STR.
Who You Work With
You’ll work with the IT and systems teams whose environments you carry through accreditation, with program managers and engineers whose classified contracts depend on the protections you stand up, and with government security officers and customer representatives who hold STR to account. You’re the function that enables the engineers to conduct their classified work, so you work closely with leadership on the risk decisions that keep the programs safe.
What We Look For
Command of NISPOM and RMF; experience as an ISSM, ISSE, ISSO, FSO, or in PERSEC; CISSP, CISM, or CISA is valued, and SAP security is a plus.

Open Positions

Ready to find your place?

Browse every open position for this role across all capability areas and all U.S. locations.