Information Systems Security Manager II

AFORGE LLC
Washington, DC, United States
12 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Shift work

Tech stack

Configuration Management CompTIA Security+ Cyber Security Data Systems Information Security Management Security Content Automation Protocol Data Streaming Plan of Action and Milestones

Job description

The Information System Security Manager II supports cybersecurity governance, RMF authorization, security-control validation, and continuous monitoring for iPDM, IWS 5, and related Task Area 3 systems. The position authors and reviews cybersecurity plans and evidence, coordinates security activities across system elements, and protects Government IT and digital environments throughout their lifecycle., * Support system categorization, control selection and tailoring, implementation, assessment, authorization, and continuous monitoring in accordance with DoDI 8510.01 and Government direction.

  • Develop, review, and maintain applicable RMF artifacts, including security plans, assessment evidence, POA&Ms, inventories, diagrams, control implementation statements, and authorization-package records.
  • Apply and validate DISA STIG checklists and coordinate credentialed ACAS and SCAP assessments, manual checks, findings adjudication, and remediation verification.
  • Assess outside applications proposed for migration into the iPDM authorization boundary, including components, interfaces, data flows, vulnerabilities, dependencies, and control inheritance.
  • Support IWS 5 systems in acquiring and maintaining ATOs; prepare evidence and recommendations for Government cybersecurity authorities and the designated AO.
  • Monitor vulnerabilities, configuration changes, POA&M milestones, evidence currency, and significant-change impacts throughout authorization sustainment.
  • Coordinate incident reporting, access control, audit, configuration management, risk assessments, and cybersecurity training as assigned.
  • Communicate security risk, remediation priorities, residual risk, and authorization status to technical and Government leadership.

Requirements

  • Bachelor’s degree from an accredited university, CNSSI 4012 certificate, ADQ GA7, or successful completion of one of the qualifying military training courses identified in Attachment 05 or a Government-accepted DoD Service equivalent.
  • Three to five years of validated specialized experience in Specialty Area 72, Information Systems Security Management.
  • Current CompTIA Security+ CE or CASP certification.
  • Ability to complete and maintain applicable Cybersecurity Workforce qualification and OJT requirements within Government-directed timelines, including the applicable NAVEDTRA pathway.
  • Ability to maintain at least 40 continuing-education hours annually while assigned to the Cybersecurity Workforce.
  • Active U.S. Government Secret clearance at the time of award and ability to obtain and maintain a Top Secret clearance.
  • Ability to support contractor sites serving the Washington Navy Yard and NSWC Crane., * Six or more years of relevant cybersecurity or ISSM experience.
  • Experience with DoDI 8510.01 RMF, Navy authorization processes, STIGs, ACAS, SCAP, POA&Ms, and continuous monitoring.
  • Experience supporting iPDM, IWS 5, Navy product-data systems, or application migration into an accredited boundary.

About the company

AFORGE is a federal contractor providing innovative solutions and engineering services to the DOD and Intel space. AFORGE is a well-respected, up-and-coming veteran owned small business with approximately 50 employees and growing. Our philosophy is to provide our employees with a rewarding career in support of the warfighter.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:57 min

Securing sensitive defense infrastructure with dual-vendor cloud strategies

Boris Hecker Boris Hecker +3 · World Congress 2025

2:37 min

Classifying and anonymizing data during system design

Reto Kaeser · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:50 min

Lowering pipeline latency with data streaming

Nathaniel Okenwa Nathaniel Okenwa · World Congress 2024

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:15 min

Bridging operational and analytical systems using formal data contracts

Matthias Niehoff Matthias Niehoff · World Congress 2024

Videos

See all

Related articles

See all