4510 ISSM
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
This position serves as the organization’s primary cybersecurity advisor and works collaboratively with Information Technology, Program Management, Contracts, Human Resources, and Executive Leadership to maintain compliance with applicable cybersecurity frameworks and contractual obligations. This is a hands-on leadership role that combines information systems security management with responsibility for the secure administration, engineering, configuration, and maintenance of the organization’s corporate and classified information technology environments., * Develop, implement, and continuously improve the corporate Information Security Program, serving as the primary ISSM and security lead for corporate, customer, classified, air-gapped, and standalone information systems.
- Lead cybersecurity compliance activities associated with applicable regulations, contracts, and frameworks, including NIST SP 800-171, NIST SP 800-53, CMMC, CMMI, DFARS, FAR, ISO 27001, DCSA, RMF, ATO, and customer-specific requirements.
- Design, implement, document, and oversee the secure operation and lifecycle management of corporate, cloud, classified, air-gapped, and standalone systems, ensuring appropriate security controls are implemented and maintained.
- Develop and maintain SSPs, POA&Ms, authorization packages, policies, standards, procedures, system and network diagrams, inventories, configuration records, and documentation supporting account management, media control, auditing, incident response, and continuous monitoring.
- Lead internal and external security assessments, ISO audits, CMMC readiness activities, reviews, self-inspections, vulnerability assessments, control validation, and remediation of identified findings.
- Conduct risk assessments, oversee vulnerability management and remediation tracking, monitor emerging threats and regulatory changes, and provide executive-level reporting on cybersecurity posture, compliance, vulnerabilities, and risk.
- Manage cybersecurity incidents, including reporting, investigation, documentation, corrective action, and coordination with appropriate internal, customer, and government stakeholders.
- Review system changes from a security perspective and partner with IT personnel to ensure secure configuration management, patching, endpoint protection, identity and access management, backups, system hardening, and lifecycle maintenance.
- Administer, configure, secure, maintain, and troubleshoot Windows-based servers and workstations, network and security devices, Microsoft 365 Government, Entra ID, Intune, Defender, Purview, privileged access, cloud services, and related technologies.
- Coordinate with the Facility Security Officer, Insider Threat Program Senior Official, system administrators, executive leadership, auditors, government customers, third-party assessors, vendors, and managed service providers to ensure security responsibilities are assigned and executed.
- Develop and deliver security awareness and annual cybersecurity training for employees.
- Support business development activities through proposal responses, security compliance documentation, technology evaluations, and recommendations for security and infrastructure improvements..
Requirements
- Strong knowledge of cybersecurity principles, risk management, and security architecture.
- Strong working knowledge of systems administration, endpoint and identity management, networking, cloud services, system hardening, backup and recovery, and technical troubleshooting, with the ability to translate security and contractual requirements into practical technical controls and system configurations.
- Ability to independently perform and document technical work while providing sound security guidance to leadership and balancing compliance, operational availability, cost, and business requirements.
- Ability to interpret government regulations and contractual security requirements.
- Excellent written, verbal, presentation, and executive communication skills.
- Strong analytical and problem-solving skills.
- Excellent organizational and project management abilities.
- Ability to manage multiple priorities while meeting deadlines.
- Strong customer service orientation and collaborative leadership style.
- Ability to influence stakeholders across all levels of the organization., * Bachelor’s degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent combination of education and experience).
- 7+ years of progressive cybersecurity or information assurance experience.
- Experience serving as an ISSM, ISSO, IA Manager, or similar role.
- Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, DFARS 252.204-7012, CMMC, and DoD cybersecurity requirements.
- Experience developing SSPs, POA&Ms, security policies, standards, and procedures.
- Experience supporting security audits and assessments.
- Excellent written, verbal, and presentation skills.
- Ability to effectively communicate cybersecurity concepts to both technical and non-technical audiences.
- Ability to work at a computer for extended periods.
- Occasionally lift up to 25 pounds., * CISSP certification (or ability to obtain within an agreed timeframe).
- Certifications such as CISM, Security+, CASP+, CCSP, CGRC (formerly CAP), CEH.
- Experience with Microsoft 365 Government, Microsoft Defender, Microsoft Entra ID (Azure AD), Intune, and Microsoft Purview.
- Experience with SIEM, EDR, vulnerability scanning, and cloud security platforms.
- Experience supporting CMMC Level 2 or 3, ISO 27001, and/or ISO 20000 compliance programs.
- Experience with developing policies and procedures and passing DCSA audits.
- Experience supporting Defense Industrial Base (DIB) contractors.
- Experience supporting classified and unclassified information systems.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities