Information System Security Manager (ISSM) with Security Clearance

Cornerstone Defense

Reston (VA)

On-site

USD 140,000 - 190,000

Full time

35 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cornerstone Defense seeks an Information System Security Manager (ISSM) with TS/SCI/Polygraph to support operations in Reston, VA. You will deliver security outcomes in collaboration with cyber and information security specialists.

You will oversee RMF/A&A processes, review system documentation, and ensure compliance with ICD 503, NISPOM and sponsor policies. You will produce reports, advise on risk, and deliver training to program personnel.

Responsibilities

  • Review and analyze systems architecture diagrams and networks.
  • Support RMF A&A requirements and apply ICD 503, NISPOM and other federal guidelines.
  • Advise program system owners on creation of required system documentation and evidence.
  • Assess security controls and data protection in sponsor information systems.
  • Create POA&Ms and coordinate risk acceptance through the SA and AO.
  • Produce annual A&A trends and risk mitigation recommendations.
  • Ensure compliance with sponsor AIS policies and requirements.
  • Write reports analyzing sponsor or partner systems and propose mitigations.
  • Conduct cyber security briefings and training for program personnel.

Job description

Information System Security Manager Clearance: TS/SCI with Polygraph Reston, VA Supporting the Most Exciting and Meaningful Missions in the World Cyber and Information Security Specialist (INFOSEC) perform functions in support of the directorate's Information System Security Manager (ISSM) and deliver outcomes as follows:

  • Review and analyze systems architecture diagrams and networks.
  • Support Assessment and Authorization (A&A) requirements and process and apply ICD 503, NISPOM, and other federal guidelines in support of systems used at contractor facilities.
  • Assist program systems owners and/or service providers throughout the risk management framework (RMF), including the assessment and authorization (A&A) processes, as follows:
  • Provide advice to program system owners and/or service providers on the creation of required system documentation or body of evidence; review and provide recommendation for approval or disapproval, as appropriate.
  • Assess security and privacy controls and data protection in sponsor information systems and environments of operation as part of the initial security assessment and during operational changes affecting information systems' security posture.
  • Assist the security control accessors (SCA), as appropriate, in performing security systems assessments and reviewing risk elements in the executive Risk System (ERS) report.
  • Create plans of action & milestones (POA&Ms) and/or request risk acceptance through a security assessor(SA) , who will certify the ERS report to the appropriate authorizing official (AO) or designated AO.
  • Regarding the RMF and A&A processes, produce an annual A&A report of trends, challenges, and risk with recommended mitigation and process improvements.
  • Provide oversight and guidance to ensure compliance with program information security regulations and policies on processes and request, such as Data Transfer Request; Access Request; Service/Change Request; Purchase Request; Accountable Property Management; Waivers, including medical devises and introduction (use) of equipment /devises into SCIF; and Equipment Transport. Produce a Weekly Activity Report.
  • Facilitate development, maintenance and security review of AIS security plans for computers, networks, and information systems deployed and used at contractor facilities, ensuring that sponsor and program approving signatures are acquired and documented.
  • Conduct technical exchange meetings to facilitate AIS security solutions for both industrial contractors and government systems; and produce comprehensive solutions to technically complex systems and challenges.
  • Ensure documentation is complete and accurate in accordance with sponsor and program AIS policies and requirements.
  • As necessary, support the investigation of virus/malware alerts/incidents to determine root cause, entry point of code, damage risk, and report this information.
  • Write reports based on technical analysis of sponsor or industrial partners systems, and as applicable provide recommendations for mitigating issues in the future.
  • Analysis systems , including forensically, for malware, misuse, and/or unauthorized activity.
  • Ensure discovered cyber incidents and data spills are reported per program SOP; support investigations and remediation/clean up as necessary, and provide guidance in coordination with program security management and other groups as appropriate.
  • Provide information security training and refine, edit, and maintain training material, as necessary to ensure it is up to date with current policies, regulations, and best practices.
  • Participate in project review meetings and provide technical cyber security advise/expertise to program personnel.
  • Advise on technical and performance characteristics of new technologies, as relates to sponsor policies and regulations.
  • Review complex sponsor and industrial partners system designs for security risk and compliance with sponsor policy and regulations; propose resolution and preventive strategies.
  • Communicate complex technical concepts, project information, and security policy clearly and concisely to both technical and non-technical audiences.
  • Provide briefings and/or training on sponsor's INFOSEC policies and regulations.
  • Provide a quarterly Security Control Status Report (SCSR) that identifies security risk and trends through the ranking of the 77 Control Families.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

General Dynamics Information Technology • Bedford (MA)

On-site
USD 120,000 - 170,000
Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

TAC Integrated Solutions • Lincoln (MA)

On-site
USD 90,000 - 130,000
Information Systems Security Manager (ISSM) II
Information Systems Security Manager (ISSM) II

TAC Integrated Solutions • Lincoln (MA)

On-site
USD 110,000 - 160,000
Information Systems Security Manager
Information Systems Security Manager

Modern Technology Solutions, Inc. (MTSI) • Dayton (OH)

On-site
USD 90,000 - 130,000
Flexible schedules
401k match
Tuition reimbursement
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Abacus Technology Corporation • Colorado Springs (CO)

On-site
USD 110,000 - 170,000
Sr Systems Security Engineer
Sr Systems Security Engineer

snc • Lone Tree (CO)

On-site
USD 140,000 - 190,000
Information Systems Security Manager - Basic (ISSM-Basic)
Information Systems Security Manager - Basic (ISSM-Basic)

ACQCENTRIC INC • Huntsville (AL)

On-site
USD 90,000 - 140,000
Information Systems Security Manager (ISSM) II
Information Systems Security Manager (ISSM) II

General Dynamics Information Technology • Bedford (MA)

On-site
USD 120,000 - 150,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

Astrion • Lincoln (MA)

On-site
USD 165,000 - 175,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Astrion • Eglin Air Force Base (FL)

On-site
USD 90,000 - 120,000