Position: ISSM
Location: Fairfax, VA (onsite)
Clearance: TS/SCI
Salary Range: $170,000 - $195,000
The Information Systems Security Manager (ISSM) is a hands-on position that requires an advanced knowledge of information assurance principles and regulatory guidance to develop, certify, accredit, and maintain information systems (IS) that are integral to our customers, our business, and the success of our security program. The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains there Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM). The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The ISSM is required to have the ability to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The ISSM must have the ability to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands-on guidance, direction, and mentoring to the technical team. Finally, the ISSM must be extremely well-organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and Organization.
Duties and Responsibilities:
- Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
- Develop, maintain, and manage RMF documentation including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Plan of Action & Milestones (POA&Ms)
- Continuous Monitoring Strategies
- Ensure compliance with:
- NIST SP 800-53 Rev. 5 security controls
- NIST SP 800-37 Rev. 2 (RMF Guide)
- DoD Cybersecurity Manual (DoDM 5200.01)
- Manage system accreditation activities with eMASS and ensure data accuracy and completeness
- Conduct and support security control assessments, vulnerability management, and mitigation tracking.
- Ensure compliance with STIGs (Security Technical Implementation Guides)
- Support audits, inspections, and cybersecurity readiness reviews
- Acts in concert with the Facility Security Officer as required.
- Renew ATOs and implement new ATOs as required
- Provide leadership in developing and maintaining company and customer IT architectures.
- Prepare, review, and oversee all Information Systems Security Plans (SSP's)
- Ensure proper Protection and/or Corrective Measures have been taken when an Incident or Vulnerability has been discovered.
- Perform Risk Assessments.
- Liaisons with client and oversight agency security authorities
Minimum Qualifications:
- Must possess an Active Top-Secret Clearance with SCI Eligibility
- Must be eligible to maintain a US Government security clearance
- Bachelor's degree in Cybersecurity, Information Security, Information Systems, Computer Science, or related field required; Master's degree preferred
- Minimum of 10 years of Information Assurance, Information Security experience, including at least 2-3 years in an ISSO or ISSM capacity.
- Working knowledge of Information Security governing regulations (NISPOM Chapter 8, applicable NIST 800-53 Rev. 5 controls, NIST SP 800-37 Rev. 2.
- Experience managing a SIPRNet connection.
- Practical knowledge of security technologies such as encryption, data protection, zero trust architecture, privileged access management.
- IAM Level III certification preferred (CISSP, CISM, GSLC CCISO, CAP, or equivalent)