Information System Security Manager

Accede LLC
Maple Grove, MN, United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Xacta Active Directory Cyber Security Information Systems Event Logging Identity and Access Management Information Security Management Windows Servers Software Vulnerability Management Information Technology Windows Security National Industrial Security Program Operating Manual (NISPOM)
+2 more
Scap Compliance Checker Vulnerability Analysis

Job description

We are seeking an experienced Information System Security Manager (ISSM) to lead and manage the overall information security program supporting classified information systems in a U.S. Government environment. The ideal candidate will have strong experience implementing the Risk Management Framework (RMF), maintaining compliance with NIST, CNSSI, DoD, and NISPOM security standards, and overseeing the authorization and continuous monitoring of classified systems. This role requires expertise in security documentation, risk management, security control implementation, cross-functional collaboration, and ensuring compliance throughout the system lifecycle. The ISSM will work closely with government sponsors, corporate security teams, and technical staff to maintain a strong security posture and support mission-critical programs., * Lead and manage the overall information security program for classified information systems.

  • Create, maintain, and manage information security documentation and RMF artifacts.
  • Implement, monitor, and maintain technical, administrative, and operational security controls.
  • Achieve and maintain Authorization to Operate (ATO) for classified information systems.
  • Advise engineering and development teams on integrating security requirements throughout the system lifecycle.
  • Coordinate with U.S. Government sponsors and corporate security organizations to ensure regulatory compliance.
  • Oversee the Continuous Monitoring (ConMon) program and maintain the operational security posture of information systems.
  • Conduct security training and provide guidance to program management and technical staff.
  • Perform risk assessments, manage security incidents, and ensure compliance with organizational security policies.
  • Support security audits, vulnerability management, and other security-related activities as required.

Requirements

  • Bachelor’’s degree in Information Technology, Cybersecurity, Computer Science, or a related field.
  • 5+ years of Information System Security experience supporting classified or government environments.
  • 3+ years of experience as an Information System Security Manager (ISSM) or Information System Security Officer (ISSO).
  • Active Secret Security Clearance.
  • IAM Level III certification in accordance with DoD 8570.01M (such as CISSP).
  • Strong experience with the Risk Management Framework (RMF) and Authorization to Operate (ATO) processes.
  • Strong knowledge of NIST 800 Series, CNSSI 1253, NISPOM Chapter 8, and related cybersecurity frameworks.
  • Experience implementing and monitoring technical, administrative, and operational security controls.
  • Experience performing risk assessments, maintaining RMF documentation, and supporting continuous monitoring activities.
  • Excellent organizational, communication, and documentation skills.
  • Ability to prioritize multiple tasks and work effectively in a fast-paced, secure government environment., * Experience with Xacta or DCSA eMASS.
  • Knowledge of Security Technical Implementation Guides (STIGs).
  • Experience with Information Assurance Vulnerability Alerts (IAVAs).
  • Familiarity with SCAP Compliance Checker (SCC).
  • Experience with Microsoft Windows Server, Active Directory, and Group Policy Objects (GPOs).
  • Experience reviewing Windows Security Event Logs.
  • Hands-on experience with vulnerability scanning tools and interpreting scan results.
  • Experience managing security incidents and remediation efforts.
  • Experience working with hardware and software vendors.
  • Strong written, verbal, and cross-functional communication skills.
  • Ability to work collaboratively in a team-oriented environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:22 min

Implementing durable execution using event logs and replay

Maxim Fateev Maxim Fateev · WWC 2023

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:09 min

Managing current state with CQRS and data projections

Allard Buijze · WWC 2021

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all