Information System Security Manager

Peraton

$146K — $234K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret security clearance with SCI eligibility required.
  • 12+ years of experience with a BS/BA or 10+ years with an MS/MA in Information Systems security; 16 years of relevant experience may substitute for a degree.
  • Proven experience as an Information Systems Security Manager (ISSM) with knowledge of cybersecurity policies.
  • IAM Level III certification required.
  • Hands-on experience with Assessment and Authorization (A&A) package submissions.
  • Strong working knowledge of NIST SP 800-53, FISMA, and RMF security frameworks.
  • Familiarity with Scrum methodologies and risk assessment principles.

Responsibilities

  • Manage security posture of all information systems and enforce security policies.
  • Lead certification and accreditation processes in compliance with RMF and other cyber standards.
  • Conduct risk assessments and develop strategies for identified vulnerabilities.
  • Ensure compliance with cybersecurity frameworks and federal information assurance requirements.
  • Oversee incident response and manage cybersecurity breach activities.
  • Implement continuous monitoring to detect and respond to security threats.
  • Work with stakeholders to integrate cybersecurity into system design and operations.

Benefits

  • Professional development and training opportunities.
  • Access to cutting-edge cybersecurity resources and tools.
  • Collaborative work environment with interdisciplinary teams.
  • Potential for involvement in large-scale government projects.
  • Opportunities for career advancement within the organization.
Full Job Description
Responsibilities

Peraton is seeking an Information Systems Security Manager to support out customer onsite in Washington D.C. who will be responsible for the following but not limited to:

  • Manage and oversee the security posture of all information systems. Implement and enforce security policies, procedures, and best practices to ensure system integrity and confidentiality.
  • Lead the process of certifying and accrediting information systems in accordance with the Risk Management Framework(s) (RMF) and other applicable government cybersecurity standards. Ensure systems meet required security controls for authorization to operate (ATO).
  • Perform risk assessments, vulnerability scans, and security audits to identify security risks and weaknesses in information systems. Develop and implement mitigation strategies to address identified risks and ensure ongoing compliance with security standards.
  • Ensure compliance with relevant cybersecurity frameworks, such as FISMA, NIST SP 800-53, and RMF, and ensure all systems supporting operations follow federal and DoD information assurance requirements.
  • Oversee incident response activities related to information security breaches, including root cause analysis, containment, remediation, and reporting. Work with the security team and stakeholders to manage cybersecurity incidents and minimize their impact on operations.
  • Implement and manage continuous monitoring of information systems and networks to detect and respond to potential security threats. Ensure all systems are regularly tested for security vulnerabilities.
  • Maintain accurate and comprehensive documentation of security controls, certifications, accreditation reports, and incident responses. Prepare regular security reports and updates for management and program leadership.
  • Work closely with engineering teams, mission planners, IT specialists, and other stakeholders to integrate cybersecurity into all phases of system design, development, and operations. Serve as the point of contact for information security issues related to information systems.
  • Develop and implement training programs for ISSO and ISSE personnel on information assurance and security best practices. Conduct cybersecurity awareness campaigns to ensure all team members understand their role in protecting sensitive data and systems.
  • Manage relationships with external vendors, contractors, and partners to ensure their systems and operations comply with information assurance requirements for the program.
  • Ensure compliance with protection requirements, control procedures, incident management reporting, remote access requirements, and system management for all systems within the enterprise.
  • Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each IS
  • Provide liaison support between the system owner, ISSOs, ISSEs, and other IS security personnel
  • Provides technical and programmatic information assurance services to internal and external customers in support of network and information security systems.

  • Designs, develops, and implements security requirements within an organization’s business processes.

  • Prepares documentation from information obtained from customer using accepted guidelines.

  • Prepares security test and evaluation plans.

  • Provides certification and accreditation support in the development of security and contingency plans and conducts complex risk and vulnerability assessments.

  • Analyzes policies and procedures against Federal laws and regulations and provides recommendations for closing gaps.

  • Recommends system enhancements to improve security deficiencies.

  • Develops, tests, and integrates computer and network security tools.

  • Secures system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration.

  • Conducts security program audits and develops solutions to lessen identified risks.

  • Provides information assurance support for the development and implementation of security architectures to meet new and evolving security requirements.

  • Provides assistance in computer incident investigations. Performs vulnerability assessments including development of risk mitigation strategies.

     

Qualifications

Required Qualifications:

  • Must possess an active Top Secret security clearance with SCI eligibility.
  • Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 16 years of experience in Information Systems security may be considered in lieu of degree.
  • ProvenISSMexperience including knowledge of system functions, cybersecurity policies, and technical cybersecurity protection measures.
  • IAM Level III certification required.
  • Experience with A&A package submission
  • Ability to build and maintain relationships with key stakeholders and high-level management
  • Strong knowledge of security frameworks, including NIST SP 800-53, FISMA, and RMF.
  • Familiar with Scrum methodologies.
  • Hands-on risk assessment experiencethat incorporates system/mission requirements and operational constraints.
  • Experience shaping policies and programsfor Federal or DoD information security initiatives.
  • Knowledge of NIST guidelines(SP 800-37, 800-53, 800-53A) and proven experience in Security Control Assessment.
  • Advanced written and verbal communication skillsto effectively communicate security concepts and policies.
  • Experience is to include at least two (2) of the following areas: knowledge of current security tools, hardware/software security implementation; communication protocols; and encryption techniques/ tools.

Desired Qualifications:

  • ITILv4 Foundation Certification
  • Splunk experienceto enhance your threat detection capabilities.
Target Salary Range$146,000 - $234,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual27s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Information Technology Jobs

Find similar Information System Security Manager jobs: