Information System Security Manager (ISSM)

Modern Technology Solutions, Inc.
Alexandria, VA, United States
1 day ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Identity and Access Management Information Security Management Privacy Controls Information Technology Plan of Action and Milestones

Job description

Modern Technology Solutions, Inc. (MTSI) is seeking an Information System Security Manager (ISSM) to work within the Autonomy Portfolio at Defense Innovation Unit (DIU). The DIU supports the Department of Defense’s (DoD) efforts to create and foster commercial partnerships within multiple innovation ecosystems across the United States. It is staffed by active-duty and reserve personnel, government civilians and contracted consultants.This position allows for the ability to telework. Close proximity to one of the MTSI office locations is preferred (Las Vegas, NV; Washington, DC; Mt View, CA; Huntsville, AL; or Dayton, OH). The ISSM will lead and manage the process for enabling authority to operate (ATO) on commercial systems contracted under DIU led or supported efforts. This capability, to organically certify autonomous and other systems, is key to bringing cutting edge technology to the warfighter in the timeliest manner possible. Candidates should have a strong desire to innovate and push the boundaries of a “legacy” approach. The ISSM should be comfortable navigating the existing ATO system but also willing to challenge and improve it. This role will be critical to DoD’s continued efforts to streamline acquisitions and implementation of commercial technology; the impact will be widespread and highly valued by warfighters. Responsibilities:

  • Assemble the security authorization package and submit the package to the Authorizing Official (AO). This package consists of the security plan, the security assessment report (SAR), the plan of action and milestones (POA&M), and appropriate documentation for any security controls that are being satisfied through inheritance (e.g., security authorization packages, contract documents, memorandums of agreement (MOAs), and service level agreements (SLAs)).
  • Support implementation of the risk management framework (RMF).
  • Maintain awareness of service-level changes to internal Authority to Operate processes to facilitate reciprocity of the IS across the department.
  • Identify the security requirements provided by the organization as common requirements for organizational information systems and document the requirements in the AO Determination Brief and continuous monitoring strategy.
  • Conduct initial remedial actions based on findings and reassess remediated risk(s) as appropriate.
  • Update AO Determination Brief, SAR, and POA&M based on the results of the continuous monitoring process.
  • Report the security status of the IS (including the effectiveness of security requirements employed within and inherited by the IS) to the AO and other appropriate organizational officials on an ongoing basis and in accordance with the continuous monitoring strategy.
  • Continuous monitoring and maintenance of ATOs. * Some travel may be required to DIU or customer facilities.

Requirements

  • Minimum 5 years of experience in information security or technology
  • Proficient working knowledge of risk management frameworks (RMF)
  • Current IAM level II credentials required. Must possess the ability to obtain IAM level III credentials.
  • Ability to effectively work remotely
  • Innovative mindset
  • Excellent written and verbal communication skills Desired qualifications

  • CISSP certified
  • Commercial-sector or startup experience
  • Experience with small, unmanned aircraft systems (sUAS)
  • Familiarity with the following: o DoDI 8510.01, “Risk Management Framework (RMF) for DoD Information Technology (IT)” o NIST SP 800-30, Guide for Conducting Risk Assessments o NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations o DOD Manual 8140 The DoD Cyber Workforce Framework Educational Requirements Bachelor’s Degree preferred., Candidates must be able to qualify for and maintain a Secret level government clearance. Active Secret security clearance preferred. U.S. Citizenship is required #LI-RR1 #MTSIjobs #mts

About the company

  • Interesting Work: Our co-workers support some of the most important and critical programs to our national defense and security.
  • Values: Our first core value is that employees come first. We challenge our co-workers to provide the highest level of support and service, and reward them with some of the best benefits in the industry.
  • 100% Employee Owned: We have a stake in each other’s success, and the success of our customers. It’s also nice to know what’s going on across the company; we have company wide town-hall meetings three times a year.
  • Great Benefits - Most Full-Time Staff Are Eligible for:

  • Starting PTO accrual of 20 days PTO/year + 10 holidays/year
  • Flexible schedules
  • 6% 401k match with immediate vesting up to $9k annually
  • Semi-annual bonus eligibility (July and December)
  • Company funded Employee Stock Ownership Plan (ESOP) - a separate qualified retirement account
  • Up to $10,000 in annual educational reimbursement
  • Other company funded benefits, like life and disability insurance
  • Optional zero deductible Blue Cross/Blue Shield health insurance plan

Track Record of Success: We have grown every year since our founding in 1993.

Modern Technology Solutions, Inc. (MTSI) is a 100% employee-owned engineering services and solutions company that provides high-demand technical expertise in Digital Transformation, Modeling and Simulation, Rapid Capability Development, Test and Evaluation, Artificial Intelligence, Autonomy, Cybersecurity and Mission Assurance

MTSI delivers capabilities to solve problems of global importance. Founded in 1993, MTSI today has employees at over 20 offices and field sites worldwide.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:13 min

Requirements and licensing plans for GitHub Copilot

lgonta lgonta +1 · World Congress 2024

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all