IT Manager
Job details
- Pay
- $75,000 – $95,000 a year
- Work mode
- On-site
- Employment
- Full-time
- Level
- Entry level
- Experience
- 2+ years
- Education
- Bachelor's degree
- Posted
- Oct 6, 2026
- Last confirmed open
- Oct 6, 2026
About this role
Job Overview
CIE Defense is seeking an IT Manager to own our entire information technology environment and lead the company’s cybersecurity compliance program. This is primarily a hands-on IT management role: you will run all in-house systems, computers, network infrastructure, and end-user support, and administer access control both logically (identity and accounts) and physically (badging and facility access).
As a second core responsibility, you will serve as the company’s subject-matter expert for CUI protection requirements under NIST SP 800-171, DFARS, and the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework.
This is a build-it-and-run-it position reporting to the President. You will be the senior in-house authority for IT and compliance — administering systems directly, implementing and maintaining the controls that protect Controlled Unclassified Information (CUI), and keeping the company assessment-ready for CMMC Level 2 as Department of Defense requirements evolve.
Key Responsibilities
IT Operations & Infrastructure (approx. 60%)
- Administer all company systems end to end: Microsoft 365 [GCC High / commercial tenant], Entra ID (Azure AD), Windows endpoints and servers, network infrastructure (firewalls, switching, Wi-Fi, VPN), and backup systems.
- Provide Tier 1–3 technical support for all staff; own helpdesk intake, onboarding/offboarding, hardware lifecycle, and provisioning/deprovisioning of accounts and equipment.
- Implement and operate security tooling: endpoint detection & response (EDR), patch and vulnerability management, MFA and conditional access, email security, logging and monitoring with retention per DFARS 252.204-7012, and backup / disaster recovery.
- Manage IT vendors, procurement, licensing, and the IT budget; recommend and execute an infrastructure roadmap appropriate to a growing defense contractor.
- Maintain network diagrams, hardware/software asset inventory, and configuration baselines.
Access Control & Identity Management (approx. 15%)
- Design and administer identity and access management: role-based least-privilege access, privileged account controls, MFA enforcement, quarterly access reviews, and segregation of duties.
- Administer physical access control systems — badging/credentialing, visitor management, alarms, and surveillance — in coordination with the Facility Security Officer (FSO); maintain access rosters tied to clearance status and need-to-know.
- Install, configure, and maintain video surveillance/CCTV systems — camera placement and mounting, Cat6/PoE cabling and termination, NVR/recorder configuration, and video retention aligned to policy.
- Install and commission door access control panels and hardware — access panels/controllers (e.g., Lenel, UniFi Access), credential readers, electric strikes/locks, and door position devices — including hands-on low-voltage installation work.
- Ensure logical and physical access policies meet NIST SP 800-171 and NISPOM-aligned expectations and are audit-ready.
CMMC & Compliance Program (approx. 25%)
- Own the company’s CMMC 2.0 compliance program for CUI environments: implement, document, and maintain the applicable NIST SP 800-171 controls and DFARS clause requirements (252.204-7012, -7019, -7020, and -7021 as applicable).
- Author and keep current the System Security Plan (SSP), Plan of Action & Milestones (POA&M), policies and procedures, data-flow diagrams, and assessment evidence repository.
- Calculate and maintain the company’s NIST SP 800-171 self-assessment score in SPRS; run internal and mock assessments and drive remediation to closure.
- Track evolving DoD CMMC implementation guidance — including the current phased rollout and any changes to C3PAO certification requirements — and brief leadership on impacts, timelines, and budget.
- Coordinate external assessors, Registered Provider Organizations (RPOs), or C3PAOs as needed; support customer, prime contractor, and government audits and flow-down reviews.
- Develop and deliver security awareness, insider threat, and CUI handling/marking training; maintain the incident response plan and report incidents per the DFARS 72-hour requirement (DIBNet).
- Support the FSO on IT touchpoints of industrial security (cleared-roster systems, DD Form 254 reviews for IT requirements, JDIG as applicable).
Required Qualifications
- 5+ years of progressive IT experience (systems administration / IT management), including 2+ years supporting a DoD, defense, or similarly regulated (CUI / FAR / DFARS) environment.
- Deep hands-on expertise with Microsoft 365, Entra ID, Windows endpoint and server administration, and core networking (firewall, VPN, DNS, switching).
- Working command of NIST SP 800-171, DFARS 252.204-7012, and the CMMC 2.0 framework; direct experience authoring or maintaining an SSP and POA&Ms.
- Experience deploying and operating security tools: EDR, vulnerability management, MFA / conditional access, SIEM or log management, and backup/DR solutions.
- Hands-on familiarity with commercial access control and video surveillance platforms — e.g., Lenel (OnGuard/NetBox) and Ubiquiti UniFi Access/Protect — including administering, installing, and troubleshooting them.
- Excellent documentation skills; able to translate technical controls into auditor-ready evidence and executive-level reporting.
- Strong prioritization and self-direction in a small-team environment where this role is the in-house IT authority.
Preferred Qualifications
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or equivalent experience.
- Certifications such as Security+, CISSP, CISM, CCNA, or Microsoft role-based certifications (e.g., MD-102, SC-100).
- CMMC Certified Professional (CCP) — or Certified CMMC Assessor (CCA) — strongly preferred, or willingness to obtain within [12 months] of hire.
- Experience with Microsoft 365 GCC High / Azure Government, Intune/Autopilot, and CUI enclave tooling (e.g., GCC High SharePoint, PreVeil or similar).
- Familiarity with NISPOM and supporting an FSO; experience with SPRS scoring and DIBNet incident reporting.
Working Conditions
- Onsite at the Summit Point, WV facility; physical presence required for physical access control and endpoint support duties.
- Occasional travel ([X–Y]% — vendor sites, training, assessments).
- Occasionally lifts and moves computer and network equipment up to [30–50] lbs.
- Performs occasional physical installation work (cameras, access panels, cabling) — ladders, ceiling spaces, and mechanical rooms.
Compensation & Benefits
- Salary range: $75,000 – $95,000 annually, commensurate with experience.
- Medical, dental, and vision insurance; 401(k) plan; [list any additional benefits — e.g., paid time off, holidays].
How to Apply
Submit a resume to [email protected]. Brief cover letters describing IT operations and CMMC / DFARS compliance experience are encouraged.
CIE Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. [Attach or link the company’s full EEO statement.]
Pay: $78,900.00 - $95,200.00 per year
Benefits:
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Retirement plan
- Vision insurance
Work Location: In person