Information System Security Manager supporting data and analytics capabilities across DoD organizations. Leading security solutions and risk management for mission-critical programs with emerging AI technologies.
Responsibilities
Serves as the primary liaison between stakeholders and technical teams to ensure a unified understanding of security requirements and address questions or concerns proactively
Interprets mission, warfighter, and user needs to ensure security solutions align with program objectives and system requirements
Analyzes security-related Service Level Agreements (SLAs), Technical Performance Measures (TPMs), and Key Performance Indicators (KPIs) to support reporting, risk assessment, and service delivery
Oversees and prioritizes remediation activities involving NIST Risk Management Framework (RMF) requirements and other security issues to ensure timely resolution
Manages and executes security controls and compliance activities across development and operations, strengthening the organization’s overall security posture
Lead the team responsible for the ISSMs
Establish a centralized ISSM pool to coordinate, review, validate, and approve all activities, which contribute to the assessment and authorization of automated information systems
Expected to be able to address anything from physical security matters to information assessments, security tests and evaluations, preparation of Contingency Plans, and administration of Life Cycle Management and Configuration Management documentation
Assess the vulnerability of AISs
Recommend and implement changes to IT systems in accordance with the DoD directives
Function as a technical specialist and assess the risk management security and contingency planning programs
Implement measures to protect data from physical destruction or theft
The contractor ISSM shall ensure that back-up procedures are in place for recovery from loss, destruction of data and program files, or from physical damage
Implement SOPs and periodically tests recovery procedures to make sure recovery procedures are operational
Develop policy and guidance and establish implementation and oversight plans to ensure compliance with Risk Management requirements
Coordinate the review and evaluation of cyber security programs and effectiveness of implementation; identify problem areas; updates and establishes new requirements in response to new technologies and threats; and make recommendations to achieve a fully compliant IT architecture
Develop Systems Security Contingency Plans and Disaster Recovery Procedures
Develop and implement training and awareness programs to ensure that Advana systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures
Requirements
T S/SCI with CI Poly security clearance
Bachelor degree (Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, Mathematics or Engineering) or higher from an accredited college or university OR Offerings listed in DoD 8140 Training Repository OR CISSP-ISSMP or GSLC
12+ years' experience in the Cybersecurity area
10+ years' experience with technology
8+ years' experience with IA technology
5+ years' experience with Risk Management Framework experience
5+ years' of project management work experience
Expert knowledge of NIST SP 800-37, CNSSI 1253, FIPS 199 and NIST SP 800-53
Knowledge of the DoD Risk Assessment Methodology (DRAM) and POAM tracking
Expert in RMF and A&A accreditation processes
Certifications in Cybersecurity like Security plus, DOD IA/IAT Level II certification
Safety Coordinator ensuring workplace safety and compliance on client sites in Lisbon. Managing prevention activities and coordinating worksite safety for Bureau Veritas.
Internship in Cybersecurity at Mapfre, gaining hands - on experience in incident response and data analysis. Working within a collaborative team to develop cybersecurity skills and knowledge.
Senior Cybersecurity GRC Specialist shaping Orion Pharma's cybersecurity governance, risk management, and compliance. Engaging with teams to enhance security posture and meet regulatory standards.
Product Security expert ensuring secure software development at NETGEAR. Championing security practices and monitoring vulnerabilities while collaborating with development teams.
System Architect driving secure cloud - native applications using cutting - edge technologies for Product Security at Nokia. Leading AI - driven design and architecture with collaboration across global teams.
Cyber Security Engineer protecting data from threats in a fintech startup. Collaborating with the Information Security Team and implementing security controls for technical projects.
Junior Security Incident Responder in an innovative IT service company protecting clients against cyber threats. Collaborating with teams to enhance IT security and respond to incidents.
Security Incident Responder managing IT security incidents in the Security Operations Center, analyzing threats and coordinating responses effectively for clients' safety.
Senior Security Engineer developing and enhancing security infrastructure for Bank Frick, a pioneer in blockchain banking. Responsible for managing security processes and collaborating with IT teams.
Werkstudent Cyber Security bei Wavestone, Unterstützung im IT - Consulting und Entwicklung im Bereich Cyber - Sicherheit. Analyse von Trends und aktive Teilnahme an Teamaktivitäten.