
MARLINS - Information Systems Security Manager
- Tampa, FL
- Permanent
- Full-time
- Lead and manage the Information Assurance (IA) and Security Assessment and Authorization (A&A) processes for a portfolio of new and existing information systems and applications.
- Develop and implement security strategies and policies to ensure compliance with FISMA, FedRAMP, and NIST Risk Management Framework (RMF) requirements and guidance.
- Oversee and direct vulnerability and risk assessment analysis to support accreditation and other program protection activities, with a focus on cloud-based systems (AWS, Azure, etc.).
- Provide guidance to a team of ISSOs to ensure proper implementation and monitoring of security controls and Security Technical Implementation Guides (STIGs) for all system components.
- Serve as the primary liaison for information security matters, interfacing directly with Program Managers, Acquisition Program Managers, other DoD agencies, and vendors.
- Establish and maintain a robust security posture, ensuring continuous monitoring and maintenance of security and privacy controls in accordance with the NIST 800-53 family of controls.
- Bachelor's degree in Cybersecurity, Information Security, Information Assurance, a related discipline, with a minimum of 5 years of professional experience in a cyber or IA role. An Associate's degree with 7+ years of experience or a High School diploma with 12+ years of experience may be considered.
- Clearance: Active Secret clearance with the ability to obtain a Top Secret with favorable SCI Adjudication. TS with SCI eligibility is highly preferred.
- Proven experience managing and leading security teams or initiatives in an ISSM or similar leadership role within the DoD.
- Extensive experience with the DoD RMF and A&A processes.
- Strong working knowledge of a variety of cloud platforms (e.g., AWS, Azure) and their security implications.
- Expert-level understanding of Information Assurance, Information Technology, and Information Management concepts and procedures, specifically in support of DoD systems.
- Minimum IAM Level II certification (i.e., CASP+, CISSP, or equivalent).
- TS/SCI Eligible.
- Experience with RMF management tools such as eMASS or Xacta.
- Experience with auditing and assessing security controls.
- Cloud certification(s) (e.g., AWS Certified Security, Azure Security Engineer).
- Knowledge of DoD Acquisition processes.
- Experience with DISA STIGs and STIG tools (e.g., SCAP).