Information System Security Manager

Peraton

Silver Spring (MD)

On-site

USD 140,000 - 200,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Peraton is seeking an Information System Security Manager to lead information assurance efforts in its Silver Spring, MD offices. This full-time, on-site role involves applying RMF controls, coordinating with ISO/PM, and preparing documentation for A&A packages, SCRs, and POA&Ms.

You will oversee Linux and Windows environments, perform continuous monitoring, and drive security with DoD STIGs, ACAS/Nessus scanning, and risk remediation across multiple programs.

Qualifications

  • Minimum qualifications are defined with 8 years with BS/BA; 6 years with MS/MA; 3 years with PhD, and a DoD 8570 IAM Level III equivalent.
  • Active TS clearance with ability to obtain SCI.
  • Experience with SAP and/or DCSA assessments and authorizations.
  • Experience with RMF, NIST 800-37/800-53 Rev4/Rev5, and coordination with ISO/PM.

Responsibilities

  • Lead and manage information assurance efforts across Silver Spring, MD environments.
  • Perform ISSM roles as prescribed by applicable regulations.
  • Create and maintain RMF package documentation and artifacts.
  • Prepare and update documentation using approved templates and regulations.
  • Meet continuous monitoring requirements including backups, patching, and vulnerability scanning.
  • Track and remediate security vulnerabilities and report security concerns.
  • Oversee Linux and Microsoft classified systems maintenance and deployment.

Skills

CISSP certification
DCSA assessments
ATO process
SCAP/STIGs
Communication skills
TS clearance

Education

Bachelor's degree in Computer Science/Cybersecurity/Information Technology

Tools

ACAS
Nessus
eMASS
SCAP

Job description

Required Qualifications/Skills:

  • Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD
  • CISSP or equivalent certification (DoD 8570 IAM Level III).
  • Experience with SAP and/or DCSA assessments and authorizations.
  • 5+ years experience with Authority to Operate (ATO) process, continuous monitoring, POA&Ms, Security Authorizations (SA), NIST 800-37, NIST 800-53 Rev4/ Rev5, working with Information System Owners (ISO) and Program Managers (PM).
  • Experience with SCAP, STIGs, and other compliance tools.
  • Proven written and verbal communication skills, and the ability to work well with team members.
  • Active TS clearance with ability to obtain SCI.

Desired Skills/Qualifications

  • Preferred degree in a technical discipline such as computer science, cybersecurity, or information technology.
  • Experience with Ongoing Authorizations
  • Experience with eMASS
  • Experience with ACAS, Nessus, and/or other vulnerability scanners
  • 3+ years of solid Linux system administration working experience with specific focus on Ubuntu and RedHat distributions.
  • Experience with Linux shell scripting include writing new scripts and troubleshoot existing codes.
  • In-depth knowledge of TCP/IP and networking concepts and a solid understanding of the well-known services including DHCP, DNS, SSH, TLS, IPSec, etc.

Peraton is seeking an Information System Security Manager in support of Peraton Labs’ information assurance and information technology operations. This is a full-time on-site position working out of the Silver Spring, Maryland office.

Responsibilities include but are not limited to:

  • Lead and manage information assurance efforts, and systems across numerous environments in Silver Spring, MD.
  • Perform Information System Security Manager (ISSM) roles and responsibilities as prescribed by the DAAG, JSIG, ICD-503, and other applicable regulations.
  • Create, manage, and maintain RMF Package documentation, submissions, and associated artifacts. This will include A&A packages, ASA packages, SCRs, etc.
  • Prepare, deliver and update all required documentation using the current approved templates, forms, regulations, and methods.
  • Meet continuous monitoring requirements for the accredited information systems, to include weekly auditing, performing of backups, AV updates, OS patching, vulnerability scanning, and other prescribed tasks.
  • Manage security vulnerabilities, implement timely remediation, monitor security logs for violations and anomalous events, and report information security concerns and problems when necessary.
  • Generate Plan of Actions & Milestones (POA&Ms) for each non-compliant control, manage all applicable POA&Ms throughout the information system lifecycle. Proper documentation shall be filed and updated as required.
  • Oversee the management and maintenance of Linux and Microsoft classified information systems, with the ability to assist in technical efforts when needed. This may include building systems, installing software, and/or troubleshooting information systems and network devices.
  • Apply security controls based on the DoD Security Technical Implementation Guidance and other customer requirements.
  • Work closely with the key stakeholders to identify any additional controls that are applicable to the system(s) to maintain a favorable security posture.
  • Assist in incident response, annual self-inspection, and inventory efforts.
  • Track the deployment of all applicable software and hardware to classified environments.
  • Provide, track, and report security requirements throughout the system life cycle of all information systems that are within the accreditation boundary.
  • Provide timely and detailed responses to user and customer requests.
  • Continuously maintain a thorough understanding of all relevant corporate policies, security control plans as well as system configurations, architecture, installed software, accounts, (both Operating System and Application), data flows, ports, protocols, and other relevant data for each Information System.
  • Maintain required certifications for this role.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000
Information System Security Manager
Information System Security Manager

Peraton Labs • Silver Spring (MD)

On-site
USD 112,000 - 179,000
Medical insurance
Dental insurance
Vision insurance
+6
External Job Posting Title Information System Security Manager
External Job Posting Title Information System Security Manager

Peraton • Silver Spring (MD)

On-site
USD 112,000 - 179,000
Information Systems Security Manager
Information Systems Security Manager

Modern Technology Solutions, Inc. • Dayton (OH)

On-site
USD 80,000 - 110,000
Limited travel required.
Information Systems Security Manager
Information Systems Security Manager

Modern Technology Solutions, Inc. (MTSI) • Dayton (OH)

On-site
USD 90,000 - 130,000
Flexible schedules
401k match
Tuition reimbursement
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Astrion • Columbia (MD)

On-site
USD 137,000 - 205,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Abacus Technology Corporation • Colorado Springs (CO)

On-site
USD 110,000 - 170,000
Senior Cyber Security Engineer/Information Systems Security Manager (ISSM)
Senior Cyber Security Engineer/Information Systems Security Manager (ISSM)

Modern Technology Solutions, Inc. (MTSI) • Bedford (MA)

On-site
USD 120,000 - 150,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Koitecc Solutions • Oklahoma City (OK)

On-site
USD 120,000 - 150,000
Information System Security Manager
Information System Security Manager

Peraton Labs • Basking Ridge (NJ)

On-site
USD 112,000 - 179,000
Medical, dental, and vision insurance
401(k) plan
Paid time off (PTO)