Information System Security Manager providing cybersecurity and RMF support at KBR. Collaborating with military and contractor personnel to lead security and compliance activities.
Responsibilities
Deliver documentation to include: Executive level briefings, Assessments, Self-Assessments, RMF packages, and supporting RMF documentation
Review Cybersecurity tool reports, ACAS, HBSS, for the purposes of reporting and compliance
Software Certification package development
Work directly with the TRMC SISO on all TRMC RMF packages and ATO Status updates
Support security engineering projects and solution delivery.
Lead security audit and compliance activities for each system responsible for
Responsible for auditing all artifacts provided in each RMF package to determine system readiness for ATO packet submissions.
Provide recommendations to the SISO, PM, and AO regarding remediation and mitigation of identified vulnerabilities on test reports and plan of action and milestones (POA&Ms).
Monitor system status updates and report to senior leadership. Includes monthly executive reports, vulnerability reports, JFHQ DODIN reporting and briefing.
Monthly executive briefing to SISO, PM on security metrics
Interface with PMs and SISO on issues needing input/concurrence
Draft and present RMF deliverables to senior leadership
Attending Executive Program Reviews as the ISSM
Work with outside agencies on Memorandums of Understanding / Interconnection Service Agreements, and other senior level agreements etc.
Work directly with a distributed team to reduce travel
Travel 25% of time
Requirements
A minimum of 2 years of Information Technology Information Assurance, or Cyber Security engineering experience.
A minimum of 2 years of experience in conducting security assessments by reviewing security controls with the ISSO/ISSM and guide programs through RMF process.
Bachelor’s Degree in Engineering, Computer Science, or 8 years IT field experience in lieu of degree; Master’s Degree preferred
Proven expertise with assessing security controls in accordance with NIST Special Publications (i.e.: NIST 800 Series)
Proven in-depth knowledge of Cybersecurity principles technologies, and processes.
Experience with NIST 800-53, Security Development
Familiarity with performing assessments for Unclassified and Classified environments
Ability to adapt to process changes
Ability to interface with senior leadership
Ability to support high visibility or high priority projects
Possession of excellent oral and written communication skills.
Cloud Security Engineer supporting and securing client environments across AWS and hybrid infrastructures. Collaborating with Cloud Operations to monitor, investigate, and remediate security events.
Cybersecurity Risk Coordinator at Globo ensuring operational security across digital content. Analyzing risks and developing strategies to enhance business resilience.
Account Cybersecurity Lead providing cybersecurity governance and oversight at Capgemini. Leading client relationships, security management systems, and risk compliance oversight.
Senior SAP Security Specialist managing SAP Security responsibilities and projects. Collaborating on security tools and conducting workshops in Hamburg.
Sales Account Manager for Cyber Security and Awareness role at HvS - Consulting GmbH. Providing holistic consulting on Cyber Security services and managing client relationships.
Security Engineer at PRC - Saltillo safeguarding IT infrastructure from cyber threats. Collaborating with IT teams to design and maintain security controls in a hybrid work environment.
Information Security Manager leading cyber security initiatives at NVISO, enhancing clients’ security posture and managing a team of consultants in Germany.
Cybersecurity Assessment Expert at IT - Strat managing A&A of information systems for U.S. federal clients. Ensuring compliance with DOD cybersecurity policies and standards in complex IT environments.
Senior Security Engineer responsible for deploying and maintaining endpoint security solutions. Collaborating across teams to enhance security posture and supporting incident response activities.