Get more replies from employers
Send a job-specific resume in minutes.
MORSE Corp in Cambridge, MA is seeking an Information System Security Manager (ISSM) to guide security in both classified and unclassified IT environments and advise on information system security matters.
You will collaborate with ISSMs, System Administrators, and Network Administrators to ensure compliance, draft security policies, implement controls, and perform continuous monitoring per NIST 800-37 and the Cybersecurity Maturity Model Certification (CMMC).
Cambridge, MA
MORSE Corp is an employee owned, small business based in Cambridge, MA, Arlington, VA, and Seattle, WA with a history of fielding cutting-edge technology. MORSE boasts a specially selected team of scientists, engineers, and software developers to deliver best-in-class technical solutions that solve difficult multidisciplinary problems faced by the US National Security Ecosystem.
The Information System Security Manager (ISSM) is responsible for ensuring that security considerations are taken into account in both classified and unclassified IT environments. The ISSM serves as an advisor for all matters related to the security of the information systems. The Cybersecurity Analyst uses various information security frameworks and agency-specific implementation guidance to obtain and maintain compliance for information systems
Ensure that systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan.
Participate in the systems development life cycle to ensure that the systems are designed with proper security features and safeguards.
Maintain security architecture (SIEM, Vulnerability Scanning, DS/IPS).
Collaborate with ISSMs, System Administrators, and Network Administrators to ensure information systems remain compliant.
Draft policies and procedures related to the security of the information system and ensure compliance with government requirements.
Test required controls, record assessments, and maintain the POA&M.
Perform continuous monitoring of security controls as required by NIST 800-37 and the Cybersecurity Maturity Model Certification (CMMC).
Analyze vulnerability scans for Linux, Windows, and AWS machines.
Research CVEs to understand remediation actions and present findings to System Administrators.
1 years of relevant cybersecurity experience.
A strong understand of NIST 800-37, NIST 800-171, or similar regulatory frameworks.
Prior experience implementing and assessing compliance with ACAS (