The Information System Security Manager (ISSM) is responsible for applying Information System (IS) security principles, practices, and procedures under the Risk Management Framework (RMF) to maintain compliance with applicable security regulations such as NIST, CNSSI, and NISPOM and governing the development and management of classified information systems. This position will be responsible for managing the program’s overarching security effort and representing the program to the sponsor’s security organization. This position requires the ISSM to be a strong advocate for integrating security into front-end requirements and overseeing the implementation and sustainment of security controls in all stages of the program lifecycle.
Working directly or through collaboration with peers, the ISSM shall:
Create and maintain information security related documentation
Implement, maintain, and monitor security controls
Advise developers on integrating security requirements
Achieve and maintain Authorization to Operate classified information systems
Coordinate with sponsor(s) and corporate security organization
Oversee Continuous Monitoring program
Maintain operational security posture for information systems
Provide security related training and guidance to program management and staff
Assist in maintaining compliance with Open Storage Areas
Maintain eligibility for personal security clearance
Perform other duties as assigned
Required Education, Experience, & Skills
Must possess a secret clearance or be able to qualify for one.
Must possess a secret clearance or be able to qualify for one.
Understanding of NIST 800 series, CNSSI 1253, NISPOM, and related publications
Ability to perform risk assessment and risk management for classified information systems
Familiarity with the RMF process and experience in drafting RMF documentation
Experience achieving approvals for classified material on computer systems through the DCSA eMass system is highly desired.
Experience in implementing and monitoring technical, administrative, and operational security controls
Ability to maintain organized and complete records
Ability to prioritize competing demands and complete tasks on schedule
The successful candidate must have previous experience with classified information system security management, network and/or system administration, network and/or system engineering, and the RMF process. A successful candidate will have experience in the assessment and authorization of classified information systems. The candidate must also hold a high-level Security or Information Technology related certification and have demonstrated experience applying certification related skills.
Preferred Education, Experience, & Skills In addition to the required skills for this position, a qualified candidate for this position will demonstrate a combination of training and hands-on experience in many of the operational and technical skills as follows:
Security Technical Implementation Guides (STIGs)
Information Assurance Vulnerability Alerts (IAVAs)