U.S Government

Information System Security Manager (ISSM)

U.S Government$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Technology or a related business field.
  • 3 years of experience in Information System Security Manager (ISSM) or related cybersecurity tasks.
  • Knowledge of risk management processes and secure configuration management techniques.
  • Skill in applying security controls and conducting application vulnerability assessments.
  • Ability to analyze vulnerability and configuration data and apply cybersecurity principles.

Responsibilities

  • Manage compliance for Marine Corps NAFI activities worldwide.
  • Perform risk management framework activities in accordance with various federal standards.
  • Conduct self-assessments of authorization package assets and develop plans of action.
  • Advocate for security program policies and enforce security awareness initiatives.
  • Promote IT security awareness by tracking user training completion.
  • Oversee regulatory requirements and conduct periodic security reviews.
  • Coordinate cybersecurity initiatives across Marine Corps departments.

Benefits

  • Stability of Federal Civilian Service.
  • Work with passionate colleagues on meaningful projects.
  • Quality work-life balance.
  • Competitive pay and comprehensive benefit packages.
  • Privileges at Marine Corps Exchange and Base Facilities.
Full Job Description
Duties

Help

This position serves an Information System Security Manager (ISSM) for the Information Technology Directorate (MRI), NAF Business and Support Services Division (MR), Manpower and Reserve Affairs Department, Headquarters Marine Corps. The incumbent will provide compliance guidance and tracking for Marine Corps NAFI activities at installations and assist with the improvement of compliance items to Marine Corps installations worldwide.

- Performs risk management framework activity and authorization efforts IAW the Payment Card Industry (PCI), Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology Special Publication (NIST SP) 800 series, Federal Information Processing Standards (FIPS) series, and USMC related policies and procedures.

- Works closely with and receives reports from Program Manager(s), Cyber operational personnel, and system administrators.

- Conducts self-assessments of authorization package assets, assess level of risk, IT policy compliance, and develops and/or recommends appropriate plan of actions and milestones (POA&M).

- Serve as an advocate for all disciplines within the security program including the development and subsequent enforcement of the organization's security awareness programs, business continuity and disaster recovery plans, and all industry and governmental compliance issues.

- Promotes IT security awareness to the user community by validating the user community is completing annual security training.

- Oversees and maintains regulatory requirements and completes periodic reviews for security implications and security applications.

- Coordinates with all departments within the Marine Corps Community Services (MCCS) and higher Marine Corps to support cybersecurity awareness initiatives.

Requirements

Help

Conditions of employment

  • See Duties and Qualifications


EVALUATIONS:

Qualifications

Bachelors' Degree in Information Technology or Business related field appropriate to the work of position AND three years of experience performing specific tasks for Information System Security Manager (ISSM), security assessments, vulnerability management, or cybersecurity (CY): OR an appropriate combination of education and experience that demonstrates possession of knowledge and skill equivalent to that gained in the above, OR appropriate experience that demonstrates the applicant has acquired the knowledge, skills, and abilities equivalent to that gained in the above.

Knowledge of risk management processes, secure configuration management techniques, Government laws and policies, cyber threats and vulnerabilities, encryption algorithms, host/network access control mechanisms, vulnerability information dissemination sources, Payment Card Industry (PCI) data security standards, Personally Identifiable Information (PII) data security standards, incident response and handling methodologies, intrusion detection methodologies and techniques for detecting host and network-based intrusions, and organization's risk tolerance and/or risk management approach.

Skill in applying security controls, analyzing traffic to identify network devices, conducting application vulnerability assessments, assessing security systems designs, interpreting vulnerability scanner results to identify vulnerabilities, assessing cloud security measures and microservices, preparing Test & Evaluation reports, and running Security Content Automation Protocol (SCAP) content and Security Technical Implementation Guides (STIGS) based tools for benchmark, compliance checks, and security configuration reviews.

Ability to identify systemic security issues based on the analysis of vulnerability and configuration data, apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation), conduct vulnerability scans and recognize vulnerabilities in security systems, and translate data and test results into evaluative conclusions.

As an authorized and privileged user of Department of Defense Information Systems, must fulfill the requirement to complete DoD Workforce Improvement Program certification (DoD 8140.01) as a condition of access within six months of employment. This position has been determined as an Intermediate proficiency level ISSM.

This position had been determined as Moderate Risk. As a condition of employment, the incumbent must be able to obtain and maintain an Access National Agency Check and Inquiries (ANACI/ Tier 3) Secret Clearance to access classified information.

Benefits

Help

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

The Federal government offers a number of exceptional benefits to its employees. Benefits you get to enjoy while working at MCCS include but are not limited to:
• Stability of Federal Civilian Service
• People with passion for doing work that matters
• Quality of Work Life Balance
• Competitive Pay
• Comprehensive Benefit Packages
• Marine Corps Exchange and Base Facility Privileges

Review our benefits

Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.

About U.S Government

The United States Government is the federal government of the United States, a republic in North America. The government is composed of three branches: the legislative, executive, and judicial branches. The government is responsible for the administration of public policy and the enforcement of laws. The government is funded through a combination of taxes, fees, and borrowing. The government employs more than 21 million people, making it one of the largest employers in the world.
Learn more about U.S Government
Size
21,000,000 employees
Industry

Similar Jobs

More Jobs at U.S Government

More Information Technology Jobs

Find similar Information System Security Manager (ISSM) jobs: