Information Systems Security Manager

Leidos

San Diego (CA)

On-site

USD 140,000 - 170,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Leidos' Corporate Information Security Office (CISO) is seeking an Information Systems Security Manager for our San Diego, CA campus. The ISSM will oversee SAP Information Systems, maintain authorization, and ensure cybersecurity compliance across the system lifecycle per JSIG, RMF, and DoD SAP requirements.

The role requires active TS clearance, DoD 8570/8140 CISSP/CISM certification, and experience leading IA/IT personnel supporting SAP environments.

Qualifications

  • Bachelor’s degree in an IT-related subject with 12+ years in operational cybersecurity or 16+ years in IT with 10+ years in cyber security.
  • Active DoD Top Secret clearance required.
  • DoD 8570/8140 CISSP or CISM certification required.
  • Experience managing RMF, JSIG, and NIST controls in SAP environments.
  • Experience with RMF authorization packages and SSPs, POA&Ms, and COIs.

Responsibilities

  • Develop, implement, and maintain cybersecurity policies and system documentation for SAP Information Systems.
  • Lead training on cybersecurity incident response and best practices for SAP environments.
  • Mentor ISSOs and IT staff on RMF, JSIG, and continuous monitoring activities.
  • Coordinate training on cybersecurity tools and procedures used within SAP environments.
  • Support authorization processes with SCAs, AOs, PSOs, and customer cybersecurity reps.
  • Oversee cybersecurity operations and risk management across SAP enclaves and WANs.
  • Ensure compliance with DSNOC, CNSSI 1253, and applicable DoD guidelines.

Skills

Top Secret clearance
CISSP/CISM
RMF/NIST/jsig
information systems security
leadership/mentoring
SCA/AO/PSO knowledge
vulnerability management
CI/CD security
PSO coordination

Education

Bachelor’s degree in IT

Tools

Tenable/Nessus
ACAS
Splunk
STIG Viewer
JIRA
Confluence

Job description

Description

Leidos' Corporate Information Security Office (CISO), reporting through our Digital sector, is seeking an Information Systems Security Manager in our San Diego, CA Campus Point office.

In this role, you will oversee Information Systems supporting Special Access Programs (SAPs) and maintain system authorization and cybersecurity compliance throughout the system lifecycle in accordance with the Joint Special Access Program Implementation Guide (JSIG), Risk Management Framework (RMF), applicable DoD SAP security requirements, and customer-specific guidance.

As the ISSM, you will serve as a Subject Matter Expert (SME) within the Information Assurance (IA) technical domain, supporting SAP Information Systems and enclaves across the enterprise. You will oversee day-to-day information system security operations, manage IA and IT personnel supporting SAP environments, resolve complex cybersecurity challenges, and develop innovative solutions to meet evolving program, customer, and security requirements.

The ideal candidate must be able to work independently while effectively collaborating with cybersecurity analysts, system administrators, engineers, program management, security personnel, site leadership, Program Security Officers (PSOs), Security Control Assessors (SCAs), and Authorizing Official (AO) representatives.

Location: All work will be performed on-site at our San Diego, CA office.

Clearance: You must currently hold an active Top Secret security clearance and be eligible for Special Access Program (SAP) clearance.

Primary Responsibilities

This role may include a combination of duties to protect SAP information, maintain cybersecurity controls, manage risk, and ensure Information Systems operate in accordance with approved authorization documentation and applicable SAP cybersecurity requirements.

  • Develop, implement, maintain, and enforce cybersecurity policies, procedures, Standard Operating Procedures (SOPs), and system-specific security documentation supporting SAP Information Systems.
  • Develop and conduct cybersecurity education and training for Information System users, privileged users, Information System Security Officers (ISSOs), system administrators, and other personnel supporting SAP environments.
  • Mentor ISSOs, system administrators, and other Information Assurance professionals regarding JSIG, RMF, secure system administration, vulnerability management, configuration management, and cybersecurity best practices.
  • Coordinate technical training on cybersecurity tools, software, technologies, and procedures used within SAP Information System environments.
  • Develop and lead training related to cybersecurity incident response, including identification, reporting, containment, remediation, recovery, documentation, and lessons learned.
  • Develop and lead Information Security projects from conceptualization through implementation, authorization, deployment, and operational acceptance.
  • Provide cybersecurity risk information and recommendations to program and senior site leadership to support risk-informed decisions regarding SAP Information Systems.
  • Demonstrated experience managing the cybersecurity and compliance posture of complex, multi-site Wide Area Networks (WANs), including interconnected systems across geographically dispersed locations.
  • Experience applying RMF, NIST, and applicable DoD security requirements to WAN architectures, boundary protections, network infrastructure, continuous monitoring, vulnerability management, and authorization activities.
Basic Qualifications
  • Must currently hold an active DoD Top Secret clearance to be considered and you must be able to meet applicable eligibility and access requirements for Special Access Program information.
  • Bachelor’s degree in an IT-related subject matter area from an accredited college or university and 12+ years of experience in an operational cybersecurity-specific role (e.g., Information Systems Security Manager, Information Systems Security Officer, cybersecurity specialist), or 16+ years of experience in an IT-related position with at least 10 years in an operational cybersecurity-specific role.
  • At least 10 years of Information Assurance/Cybersecurity management experience.
  • Current DoD 8570/8140 CISSP or CISM certification.
  • Previous ISSM and/or senior ISSO experience supporting classified Information Systems.
  • Detailed understanding and practical application of the Risk Management Framework (RMF), Joint Special Access Program Implementation Guide (JSIG), National Institute of Standards and Technology (NIST) security controls, and Committee on National Security Systems Instruction (CNSSI) 1253 requirements.
  • Working knowledge of DoD Special Access Program cybersecurity requirements, policies, processes, and procedures applicable to the authorization and operation of SAP Information Systems.
  • Experience developing, maintaining, and managing RMF authorization packages and associated cybersecurity documentation, including SSPs, security control implementation statements, POA&Ms, risk assessments, continuous monitoring artifacts, and supporting Body of Evidence.
  • Experience preparing Information Systems for cybersecurity assessments and supporting Security Control Assessors (SCAs), Authorizing Officials (AOs), Program Security Officers (PSOs), and customer cybersecurity representatives throughout the authorization process.
  • Familiarity with network technologies (LAN and WAN), network architecture, encryption technologies, key management, and cybersecurity best practices within classified and SAP environments.
  • Working knowledge of Microsoft Windows workstation/server and Linux operating systems within secure network environments.
  • Experience implementing and validating DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security configuration baselines, and system hardening requirements.
  • Experience with compliance, security monitoring, and vulnerability assessment tools such as Tenable/Nessus, ACAS, Splunk, and STIG Viewer.
  • Experience with workflow, documentation, configuration management, and change management tools such as JIRA and Confluence, as well as applicable RMF authorization management tools.
  • Ability to evaluate vulnerabilities, system changes, security control deficiencies, and cybersecurity risks and develop appropriate mitigation and remediation strategies.
  • Must be able to work in a constantly changing regulatory and mission environment with short-, mid-, and long-term timelines for resolving cybersecurity risks and compliance deficiencies.
  • Must work effectively within multidisciplinary teams and adapt quickly to changing program, customer, and mission requirements.
  • Excellent verbal and written communication skills with the ability to communicate cybersecurity risks and technical information to technical and non-technical stakeholders.
Preferred Qualifications
  • Experience working directly with PSOs, SCAs, AOs/DAOs, government cybersecurity representatives, and SAP program management.
  • Experience supporting SAP Information System Assessment and Authorization activities from initial system design through ATO and continuous monitoring.
  • Experience developing JSIG/RMF authorization documentation and providing supporting artifacts and evidence for security control assessments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Systems Security Manager (SAP/TS)
Senior Information Systems Security Manager (SAP/TS)

Leidos • San Diego (CA)

On-site
USD 140,000 - 170,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

LMI Government Consulting • Northern (KY)

Hybrid
USD 110,000 - 180,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Koitecc Solutions • Oklahoma City (OK)

On-site
USD 120,000 - 150,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

LMI Government Consulting • Washington

On-site
USD 110,000 - 180,000
Information Systems Security Manager (ISSM) III
Information Systems Security Manager (ISSM) III

General Dynamics Information Technology • Fort Walton Beach (FL)

On-site
USD 110,000 - 160,000
Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

General Dynamics Information Technology, Inc. • Bedford (MA)

On-site
USD 120,000 - 180,000
None
Information System Security Manager (ISSM) II
Information System Security Manager (ISSM) II

The Amatriot Group • Lincoln (MA)

On-site
USD 152,000 - 153,000
Information Systems Security Manager
Information Systems Security Manager

Modern Technology Solutions, Inc. • Dayton (OH)

On-site
USD 80,000 - 110,000
Limited travel required.
Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000
Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

General Dynamics Information Technology • Bedford (MA)

On-site
USD 120,000 - 170,000