OverviewSPA’s Operations Research and C5ISR Analysis Group in CA is seeking an Information System Security Manager (ISSM). This position will develop information system solutions following Risk Management Framework (RMF) with implementations following the JSIG. The ISSM is responsible for contributions to the design, procurement, configuration, deployment, and leading accreditation and continuous monitoring of ORCA and customer networks. The ISSM is responsible for attaining and maintaining system assessments and authorizations through government authorizing agencies from requirements through operational deployment. ISSM implements requirements to establish classified communication links including internet, phone, video teleconferencing, and guest systems. The successful candidates coordinate requirements with DoD agencies to ensure mission accomplishment and the protection of sensitive information.
SPA has an immediate need for an Information Systems Security Manager (ISSM). #KS
Responsibilities
ISSM Responsibilities:
- Lead a team of Cybersecurity professionals in the day-to-day cybersecurity and operations of multiple classified systems.
- Manage and mentor personnel.
- Develop and maintain enterprise-wide RMF information security policies, standards, guidelines, procedures, and artifacts following RMF.
- Oversee the development and deployment of the information security program for multiple classified systems to meet business and enterprise requirements, policies, standards, guidelines and procedures.
- Prepares, reviews, and presents technical reports and briefings.
- Create and Maintain the System Security Plans (SSP) and associated documentation.
- Create a book of business for Cybersecurity Team.
- Maintain compliance of accredited information systems based on federal and DoD security standards.
- Manages and performs security compliance continuous monitoring.
- Identifies root causes, prioritizes threats and recommends and/or implements corrective action.
- Researches and addresses information security issues as required as an authority on the subject.
- Ensure systems are operated, maintained, and disposed of in accordance with internal security policies and practices.
- Participate in internal and external security audits and inspections; performs risk assessments.
- Evaluate proposed changes or additions to the information system and assess their security relevance.
- Ensure configuration management (CM) for security-relevant IS software, hardware, and firmware is maintained and documented.
- Conduct investigations of computer security violations and incidents, reporting as necessary.
- Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered.
- Communicate, implement, and manage a formal Information Security / Information Systems Security Program together with ISSE, CPSO/CSSO, and ISO.
- Integrate lessons learned and security control policies, procedures, and artifact generation best practices with peer ISSM/ISSE.
- Contributor to the design, procurement, build, accreditation, and deployment of complex networks and systems in coordination with the ISSE and ISAs.
- Manage cyber budgets to include hardware, software, and resources.
- Receive and respond to incoming calls and/or e-mails regarding end-user or system problems.
- Interface with third-party support and equipment vendors as needed.
- Up to 20% travel required.
Qualifications
Required Qualifications:
- Bachelor's Degree in Information Security, Information Technology, or related discipline, or equivalent experience/combined education, with 10+ years of related professional experience
- Must have and maintain a DoD 8570.01-M (Information Assurance Workforce) IAM level III certification (e.g. GSLC, CISM, CCISO, or CISSP)
- Experience with RMF artifacts, obtaining and maintaining system ATOs, and implementing new and complex technologies at multiple classification levels within large enterprise environments
- Experience performing continuous monitoring and cybersecurity hygiene of a windows domains and network enclaves
- Experience with Linux operating systems in a Windows Domain
- Problem solving and time management capabilities
- Extensive experience working with federal/government agencies in sensitive and classified environments
- Experience with Risk Management Framework (RMF), NIST 800-53, JSIG, and applicable legal and regulatory guidance
- Excellent customer relations and customer support skills
- Experience working in a team-oriented, collaborative environment
- Currently hold an active TS/SCI clearance and the ability to maintain it throughout employment
Desired Qualifications:
- At least 3 years experience in the deployment, configuration, and troubleshooting of information technology equipment
- Ability to understand information systems equipment functionality and configurations (switches, routers, IDS, firewalls, servers, storage, etc...)
- Knowledge of virtualized datacenters and VDI
Pay Range InformationAt SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. California, Pay Transparency Salary range: USD $150,000.00/Yr. - USD $185,000.00/Yr.