Information Systems Security Manager (ISSM)
Position Summary:
As Information Systems Security Manager (ISSM), you will provide cybersecurity support to the National Geospatial-Intelligence Agency (NGA) in Springfield, VA.
Security Clearance Requirements:
• Must have an active DoD Top Secret/SCI security clearance
Essential Functions and Responsibilities:
• Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support information technology (IT) security goals and objectives and reduce overall organizational risk.
• Acquire necessary resources, including financial resources, to conduct an effective enterprise continuity of operations program.
• Collect and maintain data needed to meet system cybersecurity reporting.
• Communicate the value of information technology (IT) security throughout all levels of the organization stakeholders.
• Collaborate with stakeholders to establish the enterprise continuity of operations program, strategy, and mission assurance.
• Ensure that security improvement actions are evaluated, validated, and implemented as required.
• Ensure that cybersecurity inspections, tests, and reviews are coordinated for the network environment.
• Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s).
• Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture.
• Establish overall enterprise information security architecture (EISA) with the organization's overall security strategy.
• Evaluate and approve development efforts to ensure that baseline security safeguards are appropriately installed.
• Evaluate cost/benefit, economic, and risk analysis in decision-making process.
• Identify alternative information security strategies to address organizational security objectives.
• Identify information technology (IT) security program implications of new technologies or technology upgrades.
• Interface with external organizations (e.g., public affairs, law enforcement, Command or Component Inspector General) to ensure appropriate and accurate dissemination of incident and other Computer Network Defense information.
• Interpret and/or approve security requirements relative to the capabilities of new information technologies.
• Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
• Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards to ensure that they provide the intended level of protection.
• Participate in an information security risk assessment during the Security Assessment and Authorization process.
• Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations.
• Ability to apply techniques for detecting host and network-based intrusions using intrusion detection technologies.
• Ability to identify critical infrastructure systems with information communication technology that were designed without system security considerations.
Required Education, Skills, and Experience:
• Bachelor's degree or higher from an accredited college or university (Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree, or a degree in a Mathematics or Engineering field.)
• IAT, IAM, or IASAE Level 2 Certification
Physical Demands and Expectations:
• Regular physical activity to include walking, climbing stairs, bending, stooping, reaching, lifting (up to 30 pounds), and standing; occasional prolonged sitting
• Ability to speak, read, hear, and write with or without assistance
• Ability to use phone and computer systems, copier, fax, and other office equipment
This position description re present s a summary of the major components and requirements of the outlined job. Other duties and responsibilities may be assigned or required as business needs dictate. Questions regarding this description should immediately be addressed to the department manager or to Human Resources.