Information Systems Security Manager (ISSM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
TDI is seeking an Information Systems Security Manager (ISSM) to provide expertise needed to align and help mature the organization and technology-specific risk management plans and processes, through the implementation of the Risk Management Framework (RMF). This position is hybrid with commute to the DC area 3 times per week. RESPOSIBILITIES:
- Ensure client security policies and standards are enforced to support assessment, authorization and continued operation of information systems
- Lead a five-person Information Systems Security Officer team
- Support the client Information Assurance (IA) leadership in maturing risk management processes tailored for their environment and security control requirements
- Research and recommend innovative, secure, and automated solutions to improve the risk management processes
- Participate in the technical security risk evaluation and assessment of new technologies and support security policy reviews
- Provide guidance to ISSO’s on conducting technical reviews, risk analyses, mitigation and strategies to address assessment and vulnerability findings
- Manage the overall process for Plan of Action and Milestones (POA&M) and IT Risk Acceptance (ITRA) to ensure the required risk posture is maintained
- Provide quality assurance reviews of Assessment and Authorization (A&A) deliverables to ensure consistency and clarity for internal and external stakeholders
- Provide technical briefings to senior leadership as requested
Requirements
Do you have experience in System security?, Do you have a Bachelor’s degree?, * Bachelor’s degree in a related field, or equivalent relevant coursework, with 7-10 years of demonstrated experience in cybersecurity risk management
- 5+ years of demonstrated experience leading efforts for systems security assessments, preparing system security documentation, and/or performing security upgrades for live networks, desktop systems, servers, and enterprise databases leading to successful certification and accreditation or security authorization of such systems
- Strong working knowledge of NIST publications, with demonstrated experience using GRC tools to execute Assessment & Authorization activities
- Active certification in one or more of the following information security disciplines: Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or Certified Information Systems Security Professional (CISSP), * Demonstrated understanding of cloud service model tools is preferred
About the company
Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years!
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Understanding and Mitigating Common Web Vulnerabilities
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology