Information Systems Security Manager in Arlington
Role details
Job location
Tech stack
Job description
n \n
-
Coordinates, reviews, validates, and approves all activities, which contribute to the Assessment and Authorization (A&A) of automated information systems. \n
-
Address physical security matters to information assessments, security tests and evaluations, preparation of Contingency Plans, and administration of Life Cycle Management and Configuration Management documentation. \n
-
Conduct cyber situational awareness activities and provide actionable recommendations. \n
-
Assess system vulnerabilities, implement risk mitigation strategies, and validate secure systems. \n
-
Ensure systems and services are configured in compliance with Risk Management Framework (RMF), STIGs, and JSIG Rev 4 standards. \n
-
Implement SOPs and periodically tests recovery procedures to ensure recovery procedures are operational. \n
-
Recommend and implement changes to IT systems in accordance with DoD directives. \n
-
Function as a technical specialist and assess the risk management security and contingency planning programs. \n
-
Implement SOPs and periodically tests recovery procedures to ensure recovery procedures are operational. \n
-
Coordinate development of Systems Security Contingency Plans and Disaster Recovery Procedures. \n
-
Develop and implement training and awareness programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures \n
-
Prepare and deliver briefings for senior leadership on cybersecurity strategies and findings. \n
-
Support continuous improvement of monitoring capabilities, automation, and security enforcing functions \n
Requirements
-
BS and 8-12 years of prior experience, add'l experience may be considered in lieu of degree \n
-
Knowledge of NIST SP 800-37, CNSSI 1253, FIPS 199 and NIST SP 800-53 \n
-
Experience in Risk Management-Experience doing Plan of Actions and Milestones (POA&M) tracking \n
-
Experience creating metrics \n
-
Experience with DOD eMASS and the Risk Management Framework (RMF) accreditation processes \n
-
Knowledge of the DoD Risk Assessment Methodology (DRAM) \n
-
Excellent communication skills with the ability to translate technical concepts for non-technical audiences. \n
-
Expert in creating presentations and presenting policies, guidance, and procedures regularity \n