
Information Systems Security Manager
- Orlando, FL
- Permanent
- Full-time
- Develop and conduct risk assessment procedures for verification of RMF/Assessment and Authorization (A&A) safeguards to meet various regulatory requirements based upon NIST 800 series guidelines.
- Author and provide oversight of various artifacts supporting RMF package artifacts to include the System Security Plan (SSP), Security Control Traceability Matrix (SCTM), Plan of Actions & Milestones (POA&M), Continuous Monitoring (ConMon) Plan, CONOPS, and other RMF BoE artifacts.
- Responsible for analyzing and/or administering security controls for information systems.
- Configuration of change management processes (hardware/software, account Management, Disposition, Assured File Transfers (AFT) and related documentation in accordance with policies and procedures.
- Review audit data of the IS and IS components (technical & physical) for anomalous or unauthorized activities.
- System Administration (Linux/Windows) and Cybersecurity sustainment activities (hardware/software change management, account management, auditing, media protection, file transfers, etc.)
- Interface with internal and external customers, program managers, engineers, etc
- Prepare and conduct general/privileged cybersecurity training and awareness
- Develop, maintain, and execute DoD compliant cybersecurity policies and procedures for primary customer base
- Bachelor's Degree and minimum 9 years of prior Cybersecurity or Cyber Intelligence experience. Graduate Degree and a minimum of 7 years of prior cybersecurity or cyber intelligence experience. In lieu of a degree, minimum of 13 years of prior cybersecurity or cyber intelligence experience
- 5+ year of experience working with assessment & authorization processes to include risk management framework (RMF), DIACAP, NISPOM
- Prior ISSO/ISSM experience
- DoD 8570.1 compliant certification (e.g. Security +, CISSP, etc.)or ability to attain within 6 months
- Communications security (COMSEC) experience
- Knowledge of NISPOM Chapter 8 and DAAPM requirements
- System administrator experience with operating systems: Microsoft Windows, Linux
- Experience with various information system security assessment/hardening tools - SCAP Compliance Checker, ACAS, Nessus
- Working knowledge of WAN/LAN, to include Cisco-based routers, switches, and firewalls
- Experience with NIST 800-53 implementation
- Prior Enterprise Mission Assurance Support Service (eMASS)
- Self-starter with ability to work independently
- Customer service orientation