Information Systems Security Manager

Parsons View all jobs
Columbia, MD, United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$157,500.0 - $283,500.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Systems Engineering Microsoft Azure Spreadsheets Cloud Engineering Cyber Security Continuous Delivery Continuous Integration Identity and Access Management Information Systems Security Architecture Professional Open Source Technology Software Deployment
+9 more
Kubernetes Helm Charts Information Technology CIS Benchmarks Terraform Devsecops Plan of Action and Milestones Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

In a world of possibilities, pursue one with endless opportunities. Imagine Next! At Parsons, you can imagine a career where you thrive, work with exceptional people, and be yourself. Guided by our leadership vision of valuing people, embracing agility, and fostering growth, we cultivate an innovative culture that empowers you to achieve your full potential. Unleash your talent and redefine what’s possible., Parsons is looking for an amazingly talented Information Systems Security Manager to join our team! In this role you will get to lead the shift from static, point-in-time compliance assessments to a dynamic, real-time risk authorization posture RMF. What You’ll Be Doing:

  • Govern a secure, pre-accredited DevSecOps platform designed for downstream applications to inherit security controls seamlessly.
  • Define, implement, and maintain automated risk thresholds, security baselines, and compliance rules integrated directly into continuous integration/continuous deployment (CI/CD) pipelines
  • Oversee real-time configuration tracking, live vulnerability assessments, and threat analytics to ensure ongoing compliance
  • Act as the interface translating automated pipeline data, Software Bills of Materials (SBOMs), and tool generated security metrics into actionable risk acceptance frameworks to the Task Lead.
  • Guide and orchestrate the POA&M process, transitioning it from a manual tracking spreadsheet to an automated, tool-driven lifecycle RMF
  • Set formal governance criteria outlining exactly what level of security vulnerabilities (e.g., critical/high SAST, DAST, or container flaws) will automatically break a software build or block a production deployment DevSecOps Basics DevSecOps Roles & Responsibilities
  • Validate that Terraform scripts, Helm charts, and cloud-native templates used to spin up environments are programmatically hardened against DISA STIGs and NIST baselines
  • Enforce rigorous software supply chain security standards, including automated container scanning, open-source dependency tracking, signature validation, and compliance with SLSA frameworks Software Composition Analysis DoD Continuous Authorization Implementation Guide
  • Govern the Least Privilege Access model across the entire development community, strictly partitioning and isolated tenant developer environments from live, production-level pipelines
  • Serve as a collaborative bridge between system administrators, software engineers, cloud architects, and compliance officers to shift security left into the early design phases
  • Establish goals and plans that meet project objectives., JOB SUMMARY: Arundel Mills Supervision of all employees assigned to the Security department, with full responsibility for performance management of said staff. Manage and oversee…
  • 1 day ago, JOB SUMMARY: Arundel Mills Supervision of all employees assigned to the Security department, with full responsibility for performance management of said staff. Manage and oversee…
  • 1 day ago +

Requirements

  • Minimum 15 years relevant experience with Masters Degree in Computer Science, Cybersecurity, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or University.
  • Active DoD IAM and/or IAT Level III, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or SecurityX
  • Mastery of the Risk Management Framework (RMF) and associated federal cybersecurity standards, including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
  • Demonstrated understanding and experience with Enterprise-level Cloud Architecture & Security principles, including control inheritance and shared responsibility models across AWS and Azure.
  • DevSecOps practices, automated pipeline security (SAST, DAST, SCA), and CI/CD tools.
  • Experience as SETA contractor.
  • Demonstrated experience providing technical leadership on assignments.
  • Active TS SCI w/Polygraph required

Benefits & conditions

Security Clearance Requirement: An active Top Secret SCI w/Polygraph security clearance is required for this position. This position is part of our Federal Solutions team. The Federal Solutions segment delivers resources to our US government customers that ensure the success of missions around the globe. Our intelligent employees drive the state of the art as they provide services and solutions in the areas of defense, security, intelligence, infrastructure, and environmental. We promote a culture of excellence and close-knit teams that take pride in delivering, protecting, and sustaining our nation’s most critical assets, from Earth to cyberspace. Throughout the company, our people are anticipating what’s next to deliver the solutions our customers need now. Salary Range: $157,500.00 - $283,500.00 We value our employees and want our employees to take care of their overall wellbeing, which is why we offer best-in-class benefits such as medical, dental, vision, paid time off, 401(k), life insurance, flexible work schedules, and holidays to fit your busy lifestyle! Parsons is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, veteran status or any other protected status. We truly invest and care about our employee’s wellbeing and provide endless growth opportunities as the sky is the limit, so aim for the stars! Imagine next and join the Parsons quest-APPLY TODAY! Parsons is aware of fraudulent recruitment practices. To learn more about recruitment fraud and how to report it, please refer to .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:32 min

Recognizing the persistence and utility of spreadsheet applications

John Bettiol · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all