Information Systems Security Manager (ISSM)
STR has an exciting opportunity for an Information Systems Security Manager of Record (IoR) that will be responsible for collateral classified information systems Cybersecurity/Risk Management Framework (RMF) posture in accordance with government directives and program requirements. In this dynamic position you will interface directly with the government cognizant security agency (CSA) and collaborate with other Cybersecurity professionals, Security professionals, System Administrators, engineering community, and other government customers on overall compliance and configuration change management.
Responsibilities:
- Responsible for the Cybersecurity program as stipulated by various US Government requirements including (but no limited to): National Industrial Security Operating Manual (NISPOM), DCSA Authorization and Assessment Process Manual (DAAPM), and customer/contract regulations.
- Monitor cybersecurity compliance by performing periodic self-inspections, tests, and reviews of information systems to ensure that workstations/servers are operating as authorized/accredited.
- Coordinate with program/project stakeholders, Cybersecurity staff (other ISSM’s, ISSO’s, ISSE’s), the Facility Security Officer (FSO), and other Security and IT team members to define, implement and maintain an acceptable information systems security posture.
- Performs Assessment and Authorization (A&A) activities such as information system certification testing of required configuration controls and preparing/maintaining various documentation such as: Standard Operating Procedures (SOP), System Security Plan (SSP), Risk Assessment Report (RAR), Security Controls Traceability Matrix (SCTM), etc.
- Manages and maintains Continuous Monitoring (ConMon)/Plan of Action and Milestones (POA&M) reports.
- Responsible for security sustainment activities including (but not limited to): hardware change management, software change management, account management, media protection, user interface, file transfers, etc.
- Assists the FSO and Computer Incident Response Team (CIRT) in data spill incident response.
- Maintain thorough understanding of NIST 800-53 controls, determines controls applicable to the application, and documents control implementation in the SCTM.
- Perform other tasks as assigned by manager/supervisor.
Requirements
- Two (2) to four (4) years’ experience as an ISSM implementing NISPOM Chapter 8, DAAPM, ICD503 and/or JSIG IS requirements.
- Currently holds an active DoD Secret clearance.
- DoD 8570 IAM Level III certification (CISA, CISM, CISSP, etc.) or the ability to obtain within 6 months upon being hired.
- Experience with eMASS and/or Xacta authorization/accreditation databases
- Familiarity/understanding of maintaining/managing SIPRNet.
- Experience with configuration/certification and auditing/analysis of Windows/Linux operating systems in a Peer-to-peer, LAN & WAN network environment.
- Excellent communications skills.
- Demonstrated strong critical thinking and problem-solving skills.
- Detail oriented and self-motivated.
- Ability to effectively prioritize multiple projects.
- Ability to work with people in a team environment and deal effectively with changing project priorities.
- Strong customer service skills.
All STR employees may be subject to COVID-19 vaccination requirement in response to Executive Order 14042 and accompanying Task Force Guidance, unless a medical or religious accommodation is formally approved by STR.
STR is a rapidly growing technology company with locations north of Boston, MA, Arlington, VA and near Dayton, OH. We specialize in advanced research and development for defense, intelligence, and national security, trying to understand how to protect our society: from stopping malicious botnet attacks, to understanding cyber vulnerabilities, providing next generation sensors, radar, sonar, communications, and electronic warfare to developing artificial intelligence algorithms and analytics to make sense of the complexity that is exploding around us.
STR is committed to creating a collaborative learning environment that supports deep technical understanding and recognizes the contributions and achievements of all team members. Our work is challenging, but you go home at night knowing that you pushed the forefront of technology and made the world a little safer. We recognize that the world is changing, that it is becoming more connected than ever before, making things change faster than before, and reshaping society in the process. We all want to understand this changing world and leave it better for our work.
STR is not just any company. Our people, culture, and attitude along with their unique set of skills, experiences, and perspectives put us on a trajectory to change the world. We can't do it alone, though - we need fellow trailblazers. If you are one, join our team and help to keep our society safe! Visit us at www.str.us for more info.
STR is an equal opportunity employer. We are fully dedicated to hiring the most qualified candidate regardless of race, color, religion, sex (including gender identity, sexual orientation and pregnancy), marital status, national origin, age, veteran status, disability, genetic information or any other characteristic protected by federal, state or local laws.
If you need a reasonable accommodation for any portion of the employment process, email us at [email protected] and provide your contact info.
Pursuant to applicable federal law and regulations, positions at STR require employees to obtain national security clearances and satisfy the requirements for compliance with export control and other applicable laws.