Information Systems Security Manager (ISSM)

Tetrad Digital Integrity LLC
Washington, DC, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Databases Desktop Computing Information Systems Security Architecture Professional Cloud Services Smartsuite Network Server

Job description

TDI is seeking an Information Systems Security Manager (ISSM) to provide expertise needed to align and help mature the organization and technology-specific risk management plans and processes, through the implementation of the Risk Management Framework (RMF). This position is hybrid with commute to the DC area 3 times per week. RESPOSIBILITIES:

  • Ensure client security policies and standards are enforced to support assessment, authorization and continued operation of information systems
  • Lead a five-person Information Systems Security Officer team
  • Support the client Information Assurance (IA) leadership in maturing risk management processes tailored for their environment and security control requirements
  • Research and recommend innovative, secure, and automated solutions to improve the risk management processes
  • Participate in the technical security risk evaluation and assessment of new technologies and support security policy reviews
  • Provide guidance to ISSO’s on conducting technical reviews, risk analyses, mitigation and strategies to address assessment and vulnerability findings
  • Manage the overall process for Plan of Action and Milestones (POA&M) and IT Risk Acceptance (ITRA) to ensure the required risk posture is maintained
  • Provide quality assurance reviews of Assessment and Authorization (A&A) deliverables to ensure consistency and clarity for internal and external stakeholders
  • Provide technical briefings to senior leadership as requested

Requirements

Do you have experience in System security?, Do you have a Bachelor’s degree?, * Bachelor’s degree in a related field, or equivalent relevant coursework, with 7-10 years of demonstrated experience in cybersecurity risk management

  • 5+ years of demonstrated experience leading efforts for systems security assessments, preparing system security documentation, and/or performing security upgrades for live networks, desktop systems, servers, and enterprise databases leading to successful certification and accreditation or security authorization of such systems
  • Strong working knowledge of NIST publications, with demonstrated experience using GRC tools to execute Assessment & Authorization activities
  • Active certification in one or more of the following information security disciplines: Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or Certified Information Systems Security Professional (CISSP), * Demonstrated understanding of cloud service model tools is preferred

About the company

Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all