Information Systems Security Manager (ISSM) I
TS/SCI is required (must be active/in scope).
The ISSM’s primary function is to serve as an advisor on all matters, technical and otherwise, involving the security of information systems under their purview. The role involves working within Special Access Programs (SAPs) supporting Department of Defense agencies such as HQ Air Force, Office of the Secretary of Defense, and Military Compartment efforts. The position provides day-to-day support for Collateral, Sensitive Compartmented Information (SCI), and SAP activities.
Responsibilities include:
- Overseeing the development, implementation, and evaluation of information system security policies, with emphasis on integrating existing SAP network infrastructures.
- Developing and overseeing operational security implementation policies based on the Risk Management Framework (RMF), with an emphasis on Joint standards.
- Managing the Special Access Program Implementation Guide (JSIG) authorization process.
- Advising on RMF assessment and authorization issues.
- Performing risk assessments and providing recommendations to DoD agency customers.
- Guiding government program managers on security testing methodologies.
- Evaluating authorization documentation and recommending actions for authorization.
- Maintaining a formal Information Systems Security Program.
- Ensuring all cyber security personnel receive necessary technical and security training.
- Reviewing and endorsing system assessment documentation.
- Ensuring procedures are in place for hardware/media sanitization and destruction.
- Developing security assessment plans and verifying protection levels.
- Maintaining authorization documentation repositories.
- Implementing a Configuration Control Board (CCB) charter.
- Developing policies for security incident response and investigating violations.
- Ensuring proper measures are taken when vulnerabilities are discovered.
- Establishing data ownership and responsibilities for each authorization boundary.
- Implementing security education, training, and awareness programs.
- Evaluating threats and vulnerabilities, and assessing system changes.
- Ensuring valid authorizations are in place for all boundaries.
- Reviewing AIS assessment plans.
- Coordinating external system approvals.
- Conducting periodic security posture assessments.
- Managing configuration changes and documentation.
- Performing periodic security testing.
- Developing system recovery and reconstitution processes.
- Maintaining current authorization documentation.
- Addressing security requirements throughout the system lifecycle.
- Developing Assured File Transfers in accordance with JSIG.
- Participating in self-inspections.
- Performing ISSO duties if necessary.
Qualifications:
- 5+ years of related experience.
- Experience as ISSO or ISSM.
Education:
- Bachelor’s degree or equivalent experience (4 years).
Certifications:
- IAT Level II (or in lieu within 6 months of hire).
Security Clearance:
- TS/SCI, willing to obtain CI polygraph.
Other Requirements:
- Knowledge of DoD and federal security policies and standards.
- Ability to lift up to 50 lbs. regularly.
Additional information about salary, benefits, and our organization is available on our website. We are an equal opportunity employer committed to diversity and inclusion.