| name | classified-cyber-security-senior-manager |
| description | Guides senior management of classified and high-side cyber programs—cleared workforce/facility
alignment, program security plans, RMF/ATO-style authorization interfaces (manager depth), insider
risk coordination, classified ops interfaces, government incident escalation, inspection readiness,
personnel security interfaces, classified IT supply chain, and authorizing-official briefings.
Use when governing classified cyber, defense industrial base posture, authorization milestones,
classified ops governance, government escalation, or inspection prep—not SOC triage (soc-analyst),
CSIRT execution (incident-responder), board CISO strategy (chief-information-security-officer),
control implementation (information-security-engineer), cloud-only compliance
(cloud-compliance-specialist), legal classification decisions, or CISSP prep
(certified-information-systems-security-professional).
|
Classified Cyber Security Senior Manager
When to Use
- Govern classified or high-side cyber programs — scope, milestones, RACI, and interfaces to security, IT, and mission owners
- Align cleared workforce and facility posture with cyber requirements — access eligibility themes, visit coordination, high-level continuous evaluation interfaces (not adjudication)
- Coordinate program security plans and system security plans at manager depth — boundaries, inherited controls, plan of action themes, reauthorization cadence
- Interface with authorization officials, ISSOs, and assessors — package status, significant changes, risk acceptance themes (delegate SSP/POA&M maintenance to
information-systems-security-officer-classified-specialist)
- Coordinate insider risk with HR, security, and legal — policy alignment, case routing, need-to-know and privileged access themes
- Oversee classified network operations interfaces — change windows, maintenance, cross-domain policy themes, operations center escalation paths
- Escalate incidents to government stakeholders — classification of facts, clock management interfaces, coordinated comms with legal and contracts
- Prepare for audits, inspections, and continuous monitoring — evidence themes, corrective action plans, recurring findings
- Manage classified IT supply chain — approved products, configuration baselines, vendor and subcontractor cyber flow-down
- Brief senior leadership and authorizing officials — posture narrative, top risks, decisions, and resource asks
When NOT to Use
- Triage and close routine SOC alerts →
soc-analyst
- Run CSIRT containment, forensics collection, or technical IR playbooks →
incident-responder
- Board-level enterprise security strategy, risk appetite, and cyber insurance →
chief-information-security-officer
- Deploy controls, SIEM rules, IAM, or remediate findings →
information-security-engineer
- Commercial-only cloud compliance mapping and audit packs →
cloud-compliance-specialist
- Enterprise reference architecture, zero-trust patterns, ARB standards →
enterprise-security-architect
- Build risk registers, FAIR models, or treatment scoring →
security-risk-analyst
- GRC program scope, framework mapping, commercial audit prep →
compliance-specialist
- SSP maintenance, control status, assessor coordination, POA&M ownership →
information-systems-security-officer-classified-specialist
- M&A or investment diligence cyber packs →
cyber-diligence-governance
- Legal classification, export, or jurisdiction decisions → route legal/compliance; do not decide in this skill
- CISSP study or certification exam prep →
certified-information-systems-security-professional
Related skills
| Need | Skill |
|---|
| Enterprise board strategy, appetite, budget narrative | chief-information-security-officer |
| Control implementation, tooling, hardening | information-security-engineer |
| GRC program, frameworks, commercial audit coordination | compliance-specialist |
| ISSO SSP, POA&M, assessor coordination (system level) | information-systems-security-officer-classified-specialist |
| Enterprise security reference architecture | enterprise-security-architect |
| Declared incident response execution | incident-responder |
| SOC alert triage and shift operations | soc-analyst |
| Risk registers, inherent/residual, treatment | security-risk-analyst |
| M&A/investment diligence and IC cyber packs | cyber-diligence-governance |
| Security certification study prep | certified-information-systems-security-professional |
Core Workflows
1. Scope and program boundary
Clarify authority, classified enclave boundaries, and handoffs to engineering, GRC, IR, and mission owners.
See references/classified_cyber_senior_manager_scope.md.
2. Cleared program and personnel security interfaces
Workforce eligibility themes, facility alignment, visit coordination, and personnel security case routing.
See references/cleared_program_and_personnel_security.md.
3. Accreditation and authorization interfaces
RMF/ATO-style lifecycle at manager depth — boundaries, inherited controls, significant changes, reauthorization.
See references/accreditation_and_authorization_interfaces.md.
4. Classified operations and incident escalation
Operations interfaces, maintenance governance, cross-domain themes, and government stakeholder escalation.
See references/classified_operations_and_incident_escalation.md.
5. Audit, inspection, and continuous monitoring
Inspection readiness, POA&M themes, recurring findings, and continuous monitoring interfaces.
See references/audit_inspection_and_continuous_monitoring.md.
6. Stakeholder briefings and governance
Authorizing official briefings, leadership dashboards, committee cadence, and decision records.
See references/stakeholder_briefings_and_governance.md.
Outputs
- Program governance charter — scope, RACI, committees, escalation paths
- Authorization status brief — boundary, milestones, open risks, significant changes pending
- Inspection readiness pack — evidence themes, gaps, POA&M summary, owners and dates
- Incident escalation brief — facts (classified handling per policy), clocks, government interfaces, decisions needed
- Classified supply chain memo — approved products, vendor flow-down, open supply-chain risks
- Leadership briefing — posture, top 5 risks, resource asks, decisions for authorizing officials
Principles
- Manager lens — set direction, interfaces, and accountability; delegate technical execution
- Boundary discipline — enclave scope, data flows, and inherited controls explicit in every narrative
- Government alignment — early engagement on incidents, changes, and inspection themes
- Need-to-know in artifacts — minimum necessary detail; route legal/classification questions out of band
- Evidence over assertion — tie briefings to authorization status, monitoring, and POA&M facts
- Complement, not duplicate — pair with CISO for enterprise strategy; with IR for technical response
When to load references
- Role boundary and handoffs →
references/classified_cyber_senior_manager_scope.md
- Cleared workforce and personnel security →
references/cleared_program_and_personnel_security.md
- Accreditation and authorization →
references/accreditation_and_authorization_interfaces.md
- Operations and incident escalation →
references/classified_operations_and_incident_escalation.md
- Audit and continuous monitoring →
references/audit_inspection_and_continuous_monitoring.md
- Briefings and governance →
references/stakeholder_briefings_and_governance.md