Role: Cybersecurity Lead / Information Systems Security Manager (ISSM)
Location: Redstone Arsenal, AL
Foundational Qualifications (Education, Training, or Certifications): Must fulfill at least one of the following –
- Option A: Masters or Doctorate degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering, or Masters in Strategic Information & Cyberspace Studies (NDU CIC); OR
- Option B: Completion of military training 4C-FA26A (Network Systems Engineer), A-531-0009 (ISSM), ISSM (Advanced) Credential / Playlist, M09CHN1 (Communications Chief Course), M09D3H1 (ISSM); or M09DRX1 (MAGTF Communications Planner); OR
- Option C: Active certification as CISM, CISSP (including ISSMP), FITSP-M, GCIA, GCIH, GICSP, or GSLC; OR
- Option D: Experience alternative
Years of Experience: 8+ years
Clearance Level & Investigation: Secret minimum; TS/SCI and SAP access as required by assigned systems/workspaces; CAC/NACI required.
Job Description:
- Responsible for cybersecurity of a program, organization, system, or enclave.
- Leads cybersecurity/ISSM execution, RMF Assess and Authorize support, SSP/PPSM/POA&M artifacts, vulnerability management, security documentation, ATO/ATC/IATT support, incident coordination, and DoD/Army cybersecurity compliance.
- Maintain network security and authorization for mission network operations; responsibilities include controlling connections, user accounts, and access privileges, as well as providing data and information related to system security; collaborate with security team to identify, resolve, and report vulnerabilities and incidents.
- Implement cybersecurity program by maintaining adequate security expertise to provide input to all levels of systems engineering, software design and integration, testing, & training; comply with all applicable regulations, policies, and guidance in field support; meet all hardware and firmware compatibility requirements of hardware design required for compatibility and interoperability with all maintained systems.
- Provide program management, systems engineering, software engineering, CS documentation to support CS Assess and Authorize (A&A) of Customer systems; deliver an operational system that satisfies requirements to obtain an Authorization to Operate/Authorization to Connect (ATO/ATC) or Interim Approval to Test (IATT) as appropriate for mission.
- Act as primary point of contact (POC) for all CS and IS Systems Engineering (ISSE) issues.
- Support Engineering TIMs and CS TIMs with program management, systems engineering, software engineering, test, and CS staff.
- Ensure that CS design, engineering, and implementation is compliant with required NIST 800 Series CS controls.
- Ensure that selection of CS and CS-enabled information technology (IT) products within system are identified, implemented, and IAW NIST 800 Series.
- Design, engineer, and implement technical and non-technical security configuration or implementation throughout system security architecture; develop Threat Assessment, Vulnerability Assessment, and Risks Assessment documentation.
- Ensure that exceptions to selection, limitations to implementation, configuration, alternative engineering solutions, discrepancies to implementation of required CS policies and requirements, to include CS and CS-enabled IT products, are approved by Government Change Control Board (CCB) prior to implementation.
- Submit Contractor’s Risk Management to support use of any third-party, public domain, Free and Open Source Software (FOSS) products to include SBOM where feasible, software libraries, components, and applications within System for Government CCB approval prior to implementation.
- Obtain Government CS ISSM email approval at either Engineering or CS TIM or CCB prior to use of Mobile Code within System IAW NIST SP 800-53.
- Implement software assurance program for all software applications created on behalf of Customer, using industry best practices to support software development; apply and support application development requirements under RMF to include static code analysis, DISA APP DEV STIG implementation, OWASP Top 10 implementation and NETCOM Software Assurance TTP.
- Produce and maintain Hardware Baseline Inventory IAW authoritative cybersecurity repository requirements using NIST SP 800-53 and NIST SP 800-160 as guide for all System components.
- Develop and document Vulnerability Management Plan (VMP) report to include control summary, overview, IAVM process overview, IAVA implementation, and vulnerability monitoring.
- Review, evaluate and update security patches released and update system software with any industry patches to operating system or applications resident on system software.
- Prepare an IAVM Test Report to specify information assurance and security test/scans, patches assessed/checked per system software versions, new patches implemented and not implemented for each security scan performed and IAVA distribution; conduct CS scans with DISA approved CS scanning tools.
- Produce, maintain, and deliver cybersecurity artifacts/documentation to support RMF A&A process, including SSP, PPSM, POA&M.
- Identify and prioritize proposed remediation for all identified vulnerabilities and weaknesses discovered through CS testing, addressing High and Moderate risks (formerly CAT I and CAT II) as highest priority to ensure timely mitigation of critical and significant risks to system; identify proposed remediation action(s) for identified Low risk (formerly CAT III) vulnerabilities and weaknesses.