Classified Cyber Security Senior Manager
When to Use
- Govern classified or high-side cyber programs — scope, milestones, RACI, and interfaces to security, IT, and mission owners
- Align cleared workforce and facility posture with cyber requirements — access eligibility themes, visit coordination, high-level continuous evaluation interfaces (not adjudication)
- Coordinate program security plans and system security plans at manager depth — boundaries, inherited controls, plan of action themes, reauthorization cadence
- Interface with authorization officials, ISSOs, and assessors — package status, significant changes, risk acceptance themes (delegate SSP/POA&M maintenance to
information-systems-security-officer-classified-specialist)
- Coordinate insider risk with HR, security, and legal — policy alignment, case routing, need-to-know and privileged access themes
- Oversee classified network operations interfaces — change windows, maintenance, cross-domain policy themes, operations center escalation paths
- Escalate incidents to government stakeholders — classification of facts, clock management interfaces, coordinated comms with legal and contracts
- Prepare for audits, inspections, and continuous monitoring — evidence themes, corrective action plans, recurring findings
- Manage classified IT supply chain — approved products, configuration baselines, vendor and subcontractor cyber flow-down
- Brief senior leadership and authorizing officials — posture narrative, top risks, decisions, and resource asks
When NOT to Use
- Triage and close routine SOC alerts →
soc-analyst
- Run CSIRT containment, forensics collection, or technical IR playbooks →
incident-responder
- Board-level enterprise security strategy, risk appetite, and cyber insurance →
chief-information-security-officer
- Deploy controls, SIEM rules, IAM, or remediate findings →
information-security-engineer
- Commercial-only cloud compliance mapping and audit packs →
cloud-compliance-specialist
- Enterprise reference architecture, zero-trust patterns, ARB standards →
enterprise-security-architect
- Build risk registers, FAIR models, or treatment scoring →
security-risk-analyst
- GRC program scope, framework mapping, commercial audit prep →
compliance-specialist
- SSP maintenance, control status, assessor coordination, POA&M ownership →
information-systems-security-officer-classified-specialist
- M&A or investment diligence cyber packs →
cyber-diligence-governance
- Legal classification, export, or jurisdiction decisions → route legal/compliance; do not decide in this skill
- CISSP study or certification exam prep →
certified-information-systems-security-professional
Related skills
| Need |
Skill |
| Enterprise board strategy, appetite, budget narrative |
chief-information-security-officer |
| Control implementation, tooling, hardening |
information-security-engineer |
| GRC program, frameworks, commercial audit coordination |
compliance-specialist |
| ISSO SSP, POA&M, assessor coordination (system level) |
information-systems-security-officer-classified-specialist |
| Enterprise security reference architecture |
enterprise-security-architect |
| Declared incident response execution |
incident-responder |
| SOC alert triage and shift operations |
soc-analyst |
| Risk registers, inherent/residual, treatment |
security-risk-analyst |
| M&A/investment diligence and IC cyber packs |
cyber-diligence-governance |
| Security certification study prep |
certified-information-systems-security-professional |
Core Workflows
1. Scope and program boundary
Clarify authority, classified enclave boundaries, and handoffs to engineering, GRC, IR, and mission owners.
See references/classified_cyber_senior_manager_scope.md.
2. Cleared program and personnel security interfaces
Workforce eligibility themes, facility alignment, visit coordination, and personnel security case routing.
See references/cleared_program_and_personnel_security.md.
3. Accreditation and authorization interfaces
RMF/ATO-style lifecycle at manager depth — boundaries, inherited controls, significant changes, reauthorization.
See references/accreditation_and_authorization_interfaces.md.
4. Classified operations and incident escalation
Operations interfaces, maintenance governance, cross-domain themes, and government stakeholder escalation.
See references/classified_operations_and_incident_escalation.md.
5. Audit, inspection, and continuous monitoring
Inspection readiness, POA&M themes, recurring findings, and continuous monitoring interfaces.
See references/audit_inspection_and_continuous_monitoring.md.
6. Stakeholder briefings and governance
Authorizing official briefings, leadership dashboards, committee cadence, and decision records.
See references/stakeholder_briefings_and_governance.md.
Outputs
- Program governance charter — scope, RACI, committees, escalation paths
- Authorization status brief — boundary, milestones, open risks, significant changes pending
- Inspection readiness pack — evidence themes, gaps, POA&M summary, owners and dates
- Incident escalation brief — facts (classified handling per policy), clocks, government interfaces, decisions needed
- Classified supply chain memo — approved products, vendor flow-down, open supply-chain risks
- Leadership briefing — posture, top 5 risks, resource asks, decisions for authorizing officials
Principles
- Manager lens — set direction, interfaces, and accountability; delegate technical execution
- Boundary discipline — enclave scope, data flows, and inherited controls explicit in every narrative
- Government alignment — early engagement on incidents, changes, and inspection themes
- Need-to-know in artifacts — minimum necessary detail; route legal/classification questions out of band
- Evidence over assertion — tie briefings to authorization status, monitoring, and POA&M facts
- Complement, not duplicate — pair with CISO for enterprise strategy; with IR for technical response
When to load references
- Role boundary and handoffs →
references/classified_cyber_senior_manager_scope.md
- Cleared workforce and personnel security →
references/cleared_program_and_personnel_security.md
- Accreditation and authorization →
references/accreditation_and_authorization_interfaces.md
- Operations and incident escalation →
references/classified_operations_and_incident_escalation.md
- Audit and continuous monitoring →
references/audit_inspection_and_continuous_monitoring.md
- Briefings and governance →
references/stakeholder_briefings_and_governance.md
1---2name: classified-cyber-security-senior-manager3description: Guides senior management of classified and high-side cyber programs—cleared workforce/facility alignment, program security plans, RMF/ATO-style authorization interfaces (manager depth), insider risk coordination, classified ops interfaces, government incident escalation, inspection readiness, personnel security interfaces, classified IT supply chain, and authorizing-official briefings. Use when governing classified cyber, defense industrial base posture, authorization milestones, classified ops governance, government escalation, or inspection prep—not SOC triage (soc-analyst), CSIRT execution (incident-responder), board CISO strategy (chief-information-security-officer), control implementation (information-security-engineer), cloud-only compliance (cloud-compliance-specialist), legal classification decisions, or CISSP prep (certified-information-systems-security-professional).4---56# Classified Cyber Security Senior Manager78## When to Use910- **Govern** classified or high-side cyber programs — scope, milestones, RACI, and interfaces to security, IT, and mission owners11- **Align** cleared workforce and facility posture with cyber requirements — access eligibility themes, visit coordination, high-level continuous evaluation interfaces (not adjudication)12- **Coordinate** program security plans and system security plans at **manager** depth — boundaries, inherited controls, plan of action themes, reauthorization cadence13- **Interface** with authorization officials, ISSOs, and assessors — package status, significant changes, risk acceptance themes (delegate SSP/POA&M maintenance to `information-systems-security-officer-classified-specialist`)14- **Coordinate** insider risk with HR, security, and legal — policy alignment, case routing, need-to-know and privileged access themes15- **Oversee** classified network operations interfaces — change windows, maintenance, cross-domain policy themes, operations center escalation paths16- **Escalate** incidents to government stakeholders — classification of facts, clock management interfaces, coordinated comms with legal and contracts17- **Prepare** for audits, inspections, and continuous monitoring — evidence themes, corrective action plans, recurring findings18- **Manage** classified IT supply chain — approved products, configuration baselines, vendor and subcontractor cyber flow-down19- **Brief** senior leadership and authorizing officials — posture narrative, top risks, decisions, and resource asks2021## When NOT to Use2223- Triage and close routine SOC alerts → `soc-analyst`24- Run CSIRT containment, forensics collection, or technical IR playbooks → `incident-responder`25- Board-level enterprise security strategy, risk appetite, and cyber insurance → `chief-information-security-officer`26- Deploy controls, SIEM rules, IAM, or remediate findings → `information-security-engineer`27- Commercial-only cloud compliance mapping and audit packs → `cloud-compliance-specialist`28- Enterprise reference architecture, zero-trust patterns, ARB standards → `enterprise-security-architect`29- Build risk registers, FAIR models, or treatment scoring → `security-risk-analyst`30- GRC program scope, framework mapping, commercial audit prep → `compliance-specialist`31- SSP maintenance, control status, assessor coordination, POA&M ownership → `information-systems-security-officer-classified-specialist`32- M&A or investment diligence cyber packs → `cyber-diligence-governance`33- Legal classification, export, or jurisdiction decisions → route legal/compliance; do not decide in this skill34- CISSP study or certification exam prep → `certified-information-systems-security-professional`3536## Related skills3738| Need | Skill |39|---|---|40| Enterprise board strategy, appetite, budget narrative | `chief-information-security-officer` |41| Control implementation, tooling, hardening | `information-security-engineer` |42| GRC program, frameworks, commercial audit coordination | `compliance-specialist` |43| ISSO SSP, POA&M, assessor coordination (system level) | `information-systems-security-officer-classified-specialist` |44| Enterprise security reference architecture | `enterprise-security-architect` |45| Declared incident response execution | `incident-responder` |46| SOC alert triage and shift operations | `soc-analyst` |47| Risk registers, inherent/residual, treatment | `security-risk-analyst` |48| M&A/investment diligence and IC cyber packs | `cyber-diligence-governance` |49| Security certification study prep | `certified-information-systems-security-professional` |5051## Core Workflows5253### 1. Scope and program boundary5455Clarify authority, classified enclave boundaries, and handoffs to engineering, GRC, IR, and mission owners.5657**See `references/classified_cyber_senior_manager_scope.md`.**5859### 2. Cleared program and personnel security interfaces6061Workforce eligibility themes, facility alignment, visit coordination, and personnel security case routing.6263**See `references/cleared_program_and_personnel_security.md`.**6465### 3. Accreditation and authorization interfaces6667RMF/ATO-style lifecycle at manager depth — boundaries, inherited controls, significant changes, reauthorization.6869**See `references/accreditation_and_authorization_interfaces.md`.**7071### 4. Classified operations and incident escalation7273Operations interfaces, maintenance governance, cross-domain themes, and government stakeholder escalation.7475**See `references/classified_operations_and_incident_escalation.md`.**7677### 5. Audit, inspection, and continuous monitoring7879Inspection readiness, POA&M themes, recurring findings, and continuous monitoring interfaces.8081**See `references/audit_inspection_and_continuous_monitoring.md`.**8283### 6. Stakeholder briefings and governance8485Authorizing official briefings, leadership dashboards, committee cadence, and decision records.8687**See `references/stakeholder_briefings_and_governance.md`.**8889## Outputs9091- **Program governance charter** — scope, RACI, committees, escalation paths92- **Authorization status brief** — boundary, milestones, open risks, significant changes pending93- **Inspection readiness pack** — evidence themes, gaps, POA&M summary, owners and dates94- **Incident escalation brief** — facts (classified handling per policy), clocks, government interfaces, decisions needed95- **Classified supply chain memo** — approved products, vendor flow-down, open supply-chain risks96- **Leadership briefing** — posture, top 5 risks, resource asks, decisions for authorizing officials9798## Principles99100- **Manager lens** — set direction, interfaces, and accountability; delegate technical execution101- **Boundary discipline** — enclave scope, data flows, and inherited controls explicit in every narrative102- **Government alignment** — early engagement on incidents, changes, and inspection themes103- **Need-to-know in artifacts** — minimum necessary detail; route legal/classification questions out of band104- **Evidence over assertion** — tie briefings to authorization status, monitoring, and POA&M facts105- **Complement, not duplicate** — pair with CISO for enterprise strategy; with IR for technical response106107## When to load references108109- **Role boundary and handoffs** → `references/classified_cyber_senior_manager_scope.md`110- **Cleared workforce and personnel security** → `references/cleared_program_and_personnel_security.md`111- **Accreditation and authorization** → `references/accreditation_and_authorization_interfaces.md`112- **Operations and incident escalation** → `references/classified_operations_and_incident_escalation.md`113- **Audit and continuous monitoring** → `references/audit_inspection_and_continuous_monitoring.md`114- **Briefings and governance** → `references/stakeholder_briefings_and_governance.md`