DescriptionThe ISSM is responsible for developing, implementing, and managing the organization's information security program, ensuring compliance with Federal regulations and industry best practices. This role requires a deep understanding of cybersecurity principles, Federal security requirements, and the ability to manage and mitigate risks effectively.
Duties
- Develop and maintain the organization's information security program, policies, and procedures.
- Ensure compliance with Federal regulations, standards, and guidelines (e.g., NIST, FISMA, FedRAMP).
- Conduct risk assessments and vulnerability analyses to identify potential threats and weaknesses.
- Implement security controls and mitigation strategies to safeguard information systems.
- Monitor and audit information systems to ensure ongoing compliance and effectiveness of security measures.
- Provide security training and awareness programs for employees.
- Coordinate with Federal customers and other stakeholders on security-related matters.
- Lead incident response efforts, including investigation, containment, remediation, and reporting.
- Manage and oversee the certification and accreditation process for information systems.
- Stay current on emerging cybersecurity threats, technologies, and best practices.
Requirements- Must be a U.S. citizen and have the ability to obtain and maintain a Secret security clearance.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 5+ years of relevant cybersecurity experience, with a focus on Federal systems and risk management
- Strong understanding of Federal security standards and frameworks, such as FISMA, NIST, and FedRAMP.
- Experience with risk assessment and management, vulnerability analysis, and incident response.
- Experience with security tools and technologies including firewalls, intrusion detection/prevention systems, and SIEM.
- Excellent communication and interpersonal skills, with the ability to effectively communicate security concepts to non-technical stakeholders.
- Certified Information Systems Security Professional (CISSP), CISM, or equivalent certification.
- Experience with implementing and managing security controls in cloud environments.
- Proven experience in developing and implementing information security programs.
- Ability to work independently and manage multiple tasks and priorities in a fast-paced environment.
- Strong analytical and problem-solving skills, with keen attention to detail.