Information System Security Manager supporting data and analytics capabilities across DoD organizations. Leading security solutions and risk management for mission-critical programs with emerging AI technologies.
Responsibilities
Serves as the primary liaison between stakeholders and technical teams to ensure a unified understanding of security requirements and address questions or concerns proactively
Interprets mission, warfighter, and user needs to ensure security solutions align with program objectives and system requirements
Analyzes security-related Service Level Agreements (SLAs), Technical Performance Measures (TPMs), and Key Performance Indicators (KPIs) to support reporting, risk assessment, and service delivery
Oversees and prioritizes remediation activities involving NIST Risk Management Framework (RMF) requirements and other security issues to ensure timely resolution
Manages and executes security controls and compliance activities across development and operations, strengthening the organization’s overall security posture
Lead the team responsible for the ISSMs
Establish a centralized ISSM pool to coordinate, review, validate, and approve all activities, which contribute to the assessment and authorization of automated information systems
Expected to be able to address anything from physical security matters to information assessments, security tests and evaluations, preparation of Contingency Plans, and administration of Life Cycle Management and Configuration Management documentation
Assess the vulnerability of AISs
Recommend and implement changes to IT systems in accordance with the DoD directives
Function as a technical specialist and assess the risk management security and contingency planning programs
Implement measures to protect data from physical destruction or theft
The contractor ISSM shall ensure that back-up procedures are in place for recovery from loss, destruction of data and program files, or from physical damage
Implement SOPs and periodically tests recovery procedures to make sure recovery procedures are operational
Develop policy and guidance and establish implementation and oversight plans to ensure compliance with Risk Management requirements
Coordinate the review and evaluation of cyber security programs and effectiveness of implementation; identify problem areas; updates and establishes new requirements in response to new technologies and threats; and make recommendations to achieve a fully compliant IT architecture
Develop Systems Security Contingency Plans and Disaster Recovery Procedures
Develop and implement training and awareness programs to ensure that Advana systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures
Requirements
T S/SCI with CI Poly security clearance
Bachelor degree (Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, Mathematics or Engineering) or higher from an accredited college or university OR Offerings listed in DoD 8140 Training Repository OR CISSP-ISSMP or GSLC
12+ years' experience in the Cybersecurity area
10+ years' experience with technology
8+ years' experience with IA technology
5+ years' experience with Risk Management Framework experience
5+ years' of project management work experience
Expert knowledge of NIST SP 800-37, CNSSI 1253, FIPS 199 and NIST SP 800-53
Knowledge of the DoD Risk Assessment Methodology (DRAM) and POAM tracking
Expert in RMF and A&A accreditation processes
Certifications in Cybersecurity like Security plus, DOD IA/IAT Level II certification
Application Security Specialist conducting SAST and DAST analyses at TEHORA to enhance digital healthcare security. Responsible for code reviews, OWASP recommendations, and participation in intrusion tests.
Facilities and Security Coordinator providing operational support for facility operations at Westinghouse. Coordinating administrative tasks, reporting, and ensuring compliance in facility management.
Information Security Specialist ensuring digital security and compliance at cyberunity AG in Zürich. Collaborating with IT teams to implement security measures and address vulnerabilities.
Data & Cloud Security Manager overseeing security programs for protecting sensitive data at Digital Realty. Leading initiatives in data protection and cloud security across various environments.
Cybersecurity GRC Lead responsible for governance, risk, and compliance at Emerson's Industrial IoT division. Shaping the cybersecurity agenda within a fast - evolving environment.
Security Personnel responsible for access and entry controls, ensuring safety standards at proSicherheit. Collaborating on reports and preventing criminal activities in various settings.
Security staff conducting access and entry controls and ensuring safety standards in Hamburg, Germany. Team collaboration and reporting tasks required for effective security measures.
Event Security role for Milwaukee Bucks, ensuring the safety of guests and employees at events. Interacting with various stakeholders and handling security - related issues effectively.
Wachleitung / Fachkraft für Schutz und Sicherheit managing security operations at PTB. Overseeing personnel and ensuring compliance with safety protocols in Braunschweig.
Senior Cyber Security Consultant leading AppSec strategies and hands - on execution for software platforms. Focused on security engineering, vulnerability management, and compliance in the construction software industry.