Responsible for overseeing the compliance of MRIGlobal's information systems according to applicable Government and client requirements. Responsible for writing and maintaining compliant System Security Plans (SSPs) and Plan of Actions and Milestones (POA&Ms) that support the certification and accreditation process according to the Risk Management Framework for both Government and commercial requirements.
Essential Functions- Oversees day-to-day regulatory compliance of the institute's information systems
- Supports MRIGlobal's classified programs through the maintenance and accreditation of operational classified information systems for Federal Government clients in accordance with NISPOM standards and in coordination with the Security Department
- Supports the selection, implementation, and maintenance of cybersecurity tools to provide MRIGlobal's Cyber Incident Response Team with information necessary to determine root cause and remediation tactics for a cyber-incident
- Supports MRIGlobal's Technical Divisions by planning, designing, and implementing secure systems to meet contractual and regulatory requirements, and provides information security consulting services to staff to ensure compliance with regulatory and client-specific requirements
- Supports the writing and maintaining MRIGlobal's security policies including support the security posture of all cloud hosted systems
- Partners and coordinates with the IT department to provide security direction
- Analyzes information systems to ensure regulatory compliance. Safeguard networks against unauthorized modification, destruction, or disclosure. Research, evaluate, design, test, recommend, communicate, and implement new security software or devices
Skills and Abilities - Excellent written, oral, interpersonal, leadership, and problem-solving skills
- Ability to effectively communicate complex technical analysis, information, and concepts to all levels of the organization
- Experience in leading cross-functional project teams and groups
- Ability to handle multiple tasks simultaneously with changing priorities
- Broad knowledge of and ability to learn new software, systems, and methodologies
- Demonstrated knowledge of distributed systems technology, client/server application design, and network security
- Ability to plan and meet objectives under stringent deadlines and constraints
- Sensitivity to personal and confidential information
- Ability to work nights and weekends as needed
Minimum Qualifications Bachelor's degree in Computer Science, Information Systems, Engineering, Business, or other related disciplines with a minimum of 6 years relevant experience (or) High school diploma or equivalent with a minimum of 12 years relevant experience. Experience and certifications may be substituted for degree.
***Must be a US Citizen***- Ability to obtain and maintain required U.S. Government security clearances
- Written and maintained System Security Plans (SSPs) and Plan of Actions and Milestones (POA&Ms)
- Familiar with one or more of the following:
- NIST Risk Management Framework
- CMMC (Cybersecurity Maturity Model Certification) Level 3 or higher
- NIST SP 800-53 (Security and Privacy Controls for Federal Information Systems and Organizations)
- NIST SP 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- Professional certifications such as CISSP or CISA are preferred
Pay Range $82,300 - $96,000The salary range is intended as a general guideline and is not a guaranteed offer, as compensation depends on various factors such as scope and responsibilities of the position, candidate qualifications, experience, internal equity, and market conditions. MRIGlobal also provides a comprehensive benefits package, including health and life insurance, disability coverage, gym reimbursement, mental health support, paid holidays, and PTO.