The Information Systems Security Manager/Engineer
Aptiv · Washington, D.C.
📍 USA Washington DC - WRvia workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Aptiv.
ABOUT WIND RIVERX
Wind RiverX (WRX) is a mission-driven software company focused on delivering advanced, secure, and resilient solutions that support U.S. defense and national security missions. As a subsidiary of Wind River, a global leader in intelligent systems software with over four decades of proven success in aerospace and defense, WRX builds upon a trusted legacy of innovation, reliability, and mission assurance.
Wind River’s software has powered some of the world’s most critical systems — from the Mars rovers and commercial aircraft to advanced military platforms and autonomous defense technologies. Building on this heritage, WRX extends that technical excellence to accelerate innovation at the edge, combining agility, security, and modern software practices tailored to the unique needs of defense customers.
At WRX, we partner closely with government, defense, and industry leaders to provide secure and reliable systems to the most critical missions, enhance interoperability, and strengthen digital resilience.
Our team brings deep expertise in systems integration, open architecture, customer needs, and software-defined solutions that empower our warfighters and critical partners across air, land, sea, and cyber domains.
We are a fast-growing organization that values collaboration, integrity, and technical mastery. Our culture is rooted in innovation and purpose — we move quickly, think boldly, and take pride in delivering solutions that matter. If you believe you would be an asset to a high powered team with an energetic culture where you will contribute to reducing the definition of impossible, we would like to talk to you.
YOUR ROLE
The Information Systems Security Manager/Engineer (ISSM/E) at WRX will excel in a dynamic and ever-changing environment, demonstrating adaptability, flexibility, and proactive initiative. This role focuses on creating new compliance policy and programs and continuously monitoring and improving existing security programs, ensuring it meets U.S. federal, global, and industry specific security requirements and standards. The ISSM/E will report to the and work closely with the Sr. Director of Compliance.
The ISSM/E will play a vital role in aligning internal IT security objectives with broader business goals, effectively communicating progress and potential challenges to stakeholders at various levels. Responsibilities include ensuring compliance with relevant regulations and standards, conducting risk assessments, monitoring controls, developing and implementing IT security policies and procedures, and overseeing IT security audits and assessments. The ideal candidate will bring prior ISSM/E experience from FOCI mitigated companies and a deep knowledge in with network and systems engineering and architecture.
RESPONSIBILITIES Governance, Risk & Compliance (GRC) Execution
Maintain enterprise compliance readiness aligned to ISO 27001, NIST 800-171, CMMC, SOX, TISAX, GDPR, NIS2, and similar regulatory frameworks.
Drive engagement with control owners, SMEs, and leadership to track risk exceptions, POA&Ms, maturity improvements, and audit-ready evidence.
Support continuous improvement of the cybersecurity policy, standards, and governance framework to ensure consistency across multi-entity operations.
Developing architecture documentation and Systems Security Plans (SSP) to support Accreditation and Authorization (A&A) reviews
Enterprise Resilience & Continuity
Own documentation, updates, and execution of business impact assessments (BIAs), continuity plans, disaster recovery strategies, and tabletop exercises.
Partner with cross-functional teams to ensure IT and cyber security compliance across the business.
Maintain continuity and response playbooks, leveraging prior experience leading large-scale DoD and enterprise network operations.
Knowledge of the complex environment involving shared networks and multiple security enclaves.
Engineering for Cyber engineering and integration services including security, authentication, identity management, authorization, and access control engineering.
Third-Party Risk Management (TPRM) & Cyber Training
Execute WRX’s vendor risk assessments, evidence reviews, and remediation tracking, applying DoD and federal acquisition (ISA Level III) experience to strengthen supply-chain posture.
Enforce cybersecurity right-to-audit clauses and support contract redline reviews for both buy- and sell-side agreements.
Support mandatory cybersecurity training initiatives, awareness campaigns, and development of role-based materials.
Audit & Assurance Leadership
Lead enterprise IT audit preparation for internal reviews, external audits, customer assessments, and regulatory inquiries.
Manage and maintain System Security Plans (SSPs), Electronic Communications Plan (ECP), Plans of Action & Milestones (POA&Ms), and required customer assurance documentation.
Coordinate walkthroughs, interviews, and evidence collection across matrixed teams, operating with the discipline gained from federal audit, CMMC AUDIT and certification, RMF, and DoDIN environments.
Cross-Functional Operations & Leadership
Provide high-quality execution support for strategic initiatives led by the President and Government Security Committee, Training, and continued monitoring.
Work closely with Architecture, Product Security, Engineering, and vendor partners to unblock dependencies and support compliance-aligned implementations.
Self-starter able to work independently and build relationships with technical reps across divisions, comfortable with cyber security and able to brief issues to the customer
Key skills and competencies for succeeding in this role are:
Cyber security.
Security Development and Operations (SecDevOps)
Cloud security controls and implementation
STIG compliance and vulnerability management
Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, X
More Washington, D.C. jobs
Washington, D.C. jobs · Browse all locations