# Classified Cyber Security Senior Manager

> Guides senior management of classified and high-side cyber programs—cleared workforce/facility alignment, program security plans, RMF/ATO-style authorization interfaces (manager depth), insider risk coordination, classified ops interfaces, government incident escalation, inspection readiness, personnel security interfaces, classified IT supply chain, and authorizing-official briefings. Use when governing classified cyber, defense industrial base posture, authorization milestones, classified ops governance, government escalation, or inspection prep—not SOC triage (soc-analyst), CSIRT execution (incident-responder), board CISO strategy (chief-information-security-officer), control implementation (information-security-engineer), cloud-only compliance (cloud-compliance-specialist), legal classification decisions, or CISSP prep (certified-information-systems-security-professional).

- Skill: `daemon-blockint-tech/classified-cyber-security-senior-manager` (Agent Skill, multi-file: 7 files)
- Install (CLI): `npx skillmds@latest add daemon-blockint-tech/classified-cyber-security-senior-manager`
- Raw SKILL.md: https://api.skillmd.com/api/skills/daemon-blockint-tech/classified-cyber-security-senior-manager/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: daemon-blockint-tech (https://skillmd.com/u/daemon-blockint-tech)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/daemon-blockint-tech/classified-cyber-security-senior-manager

---


# Classified Cyber Security Senior Manager

## When to Use

- **Govern** classified or high-side cyber programs — scope, milestones, RACI, and interfaces to security, IT, and mission owners
- **Align** cleared workforce and facility posture with cyber requirements — access eligibility themes, visit coordination, high-level continuous evaluation interfaces (not adjudication)
- **Coordinate** program security plans and system security plans at **manager** depth — boundaries, inherited controls, plan of action themes, reauthorization cadence
- **Interface** with authorization officials, ISSOs, and assessors — package status, significant changes, risk acceptance themes (delegate SSP/POA&M maintenance to `information-systems-security-officer-classified-specialist`)
- **Coordinate** insider risk with HR, security, and legal — policy alignment, case routing, need-to-know and privileged access themes
- **Oversee** classified network operations interfaces — change windows, maintenance, cross-domain policy themes, operations center escalation paths
- **Escalate** incidents to government stakeholders — classification of facts, clock management interfaces, coordinated comms with legal and contracts
- **Prepare** for audits, inspections, and continuous monitoring — evidence themes, corrective action plans, recurring findings
- **Manage** classified IT supply chain — approved products, configuration baselines, vendor and subcontractor cyber flow-down
- **Brief** senior leadership and authorizing officials — posture narrative, top risks, decisions, and resource asks

## When NOT to Use

- Triage and close routine SOC alerts → `soc-analyst`
- Run CSIRT containment, forensics collection, or technical IR playbooks → `incident-responder`
- Board-level enterprise security strategy, risk appetite, and cyber insurance → `chief-information-security-officer`
- Deploy controls, SIEM rules, IAM, or remediate findings → `information-security-engineer`
- Commercial-only cloud compliance mapping and audit packs → `cloud-compliance-specialist`
- Enterprise reference architecture, zero-trust patterns, ARB standards → `enterprise-security-architect`
- Build risk registers, FAIR models, or treatment scoring → `security-risk-analyst`
- GRC program scope, framework mapping, commercial audit prep → `compliance-specialist`
- SSP maintenance, control status, assessor coordination, POA&M ownership → `information-systems-security-officer-classified-specialist`
- M&A or investment diligence cyber packs → `cyber-diligence-governance`
- Legal classification, export, or jurisdiction decisions → route legal/compliance; do not decide in this skill
- CISSP study or certification exam prep → `certified-information-systems-security-professional`

## Related skills

| Need | Skill |
|---|---|
| Enterprise board strategy, appetite, budget narrative | `chief-information-security-officer` |
| Control implementation, tooling, hardening | `information-security-engineer` |
| GRC program, frameworks, commercial audit coordination | `compliance-specialist` |
| ISSO SSP, POA&M, assessor coordination (system level) | `information-systems-security-officer-classified-specialist` |
| Enterprise security reference architecture | `enterprise-security-architect` |
| Declared incident response execution | `incident-responder` |
| SOC alert triage and shift operations | `soc-analyst` |
| Risk registers, inherent/residual, treatment | `security-risk-analyst` |
| M&A/investment diligence and IC cyber packs | `cyber-diligence-governance` |
| Security certification study prep | `certified-information-systems-security-professional` |

## Core Workflows

### 1. Scope and program boundary

Clarify authority, classified enclave boundaries, and handoffs to engineering, GRC, IR, and mission owners.

**See `references/classified_cyber_senior_manager_scope.md`.**

### 2. Cleared program and personnel security interfaces

Workforce eligibility themes, facility alignment, visit coordination, and personnel security case routing.

**See `references/cleared_program_and_personnel_security.md`.**

### 3. Accreditation and authorization interfaces

RMF/ATO-style lifecycle at manager depth — boundaries, inherited controls, significant changes, reauthorization.

**See `references/accreditation_and_authorization_interfaces.md`.**

### 4. Classified operations and incident escalation

Operations interfaces, maintenance governance, cross-domain themes, and government stakeholder escalation.

**See `references/classified_operations_and_incident_escalation.md`.**

### 5. Audit, inspection, and continuous monitoring

Inspection readiness, POA&M themes, recurring findings, and continuous monitoring interfaces.

**See `references/audit_inspection_and_continuous_monitoring.md`.**

### 6. Stakeholder briefings and governance

Authorizing official briefings, leadership dashboards, committee cadence, and decision records.

**See `references/stakeholder_briefings_and_governance.md`.**

## Outputs

- **Program governance charter** — scope, RACI, committees, escalation paths
- **Authorization status brief** — boundary, milestones, open risks, significant changes pending
- **Inspection readiness pack** — evidence themes, gaps, POA&M summary, owners and dates
- **Incident escalation brief** — facts (classified handling per policy), clocks, government interfaces, decisions needed
- **Classified supply chain memo** — approved products, vendor flow-down, open supply-chain risks
- **Leadership briefing** — posture, top 5 risks, resource asks, decisions for authorizing officials

## Principles

- **Manager lens** — set direction, interfaces, and accountability; delegate technical execution
- **Boundary discipline** — enclave scope, data flows, and inherited controls explicit in every narrative
- **Government alignment** — early engagement on incidents, changes, and inspection themes
- **Need-to-know in artifacts** — minimum necessary detail; route legal/classification questions out of band
- **Evidence over assertion** — tie briefings to authorization status, monitoring, and POA&M facts
- **Complement, not duplicate** — pair with CISO for enterprise strategy; with IR for technical response

## When to load references

- **Role boundary and handoffs** → `references/classified_cyber_senior_manager_scope.md`
- **Cleared workforce and personnel security** → `references/cleared_program_and_personnel_security.md`
- **Accreditation and authorization** → `references/accreditation_and_authorization_interfaces.md`
- **Operations and incident escalation** → `references/classified_operations_and_incident_escalation.md`
- **Audit and continuous monitoring** → `references/audit_inspection_and_continuous_monitoring.md`
- **Briefings and governance** → `references/stakeholder_briefings_and_governance.md`

