Information Systems Security Manager
1 month ago
Overview
Abacus Technology is seeking an Information System Security Manager (ISSM) to ensure system and application deliverables meet all required cyber security policies and regulations for the Technical Advisory and Assistance Services (TAAS) program at Hanscom AFB. This is a full-time position.
Responsibilities
- Manage the system/application Assessment and Authorization (A&A) efforts, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Air Force policies (i.e., RMF).
- Develop and conduct a Continuous Monitoring plan in support of A&A activities to maintain ongoing awareness of cybersecurity, vulnerabilities, and threats to facilitate risk-based decision making.
- Maintain and report system assessment and authorization status and issues in accordance with DoD Component guidance.
- Participate in meetings/teleconferences, change control boards (CCBs) and working groups (WGs) to ensure the continued alignment of cybersecurity requirements in the technical baselines, the system security architecture, information flows, design, and the security controls.
- Evaluate system sources of changes such as Deficiency Reports (DRs), Problem Reports (PRs), Change Requests/Proposals (CRs/CPs), and AF Form 1067s; provide inputs to the root cause analysis reporting and the formulation of recommended solution from alternatives; determine the security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and if any, document in written reports the changes/revisions to the system’s RMF artifacts.
- Review and provide inputs to modification packages, program/system documents and support agreements updates, and communications and network infrastructure upgrades to ensure proper cybersecurity configuration modification management; implementation of technical, managerial, operational requirements; and support requirements (e.g. planning, testing, test infrastructure, documentation, training, etc.) are identified.
- Review system test plans and test results and if necessary, observe system testing for security control implementation in accordance with cybersecurity policies, guidance, and plan.
- Perform security impact analysis on any system change and appropriately prepare letters of assurance, security impact letters, and risk assessment letters to include exceptions, deviations, or waivers to cybersecurity requirements when applicable.
- Continuously monitor intelligence and open-source information for vulnerabilities affecting AFNWC/NCL systems, assess risk, and provide POA&M recommendations to ISSM and PM as required.
- Act as the primary cybersecurity technical advisor to Program Management and System Engineers for systems under their purview.
- Coordinate Trusted Systems and Networks (TSN) and Supply Chain Risk Management (SCRM) evaluation of program information, software, and hardware throughout the program life cycle.
- Ensure that cybersecurity-related events or configuration changes that may impact systems authorization or security posture are formally reported to the AO and other affected parties, such as IOs and stewards and AOs of interconnected DoD ISs.
- Ensure that cybersecurity inspections, tests, and reviews are synchronized and coordinated with affected parties and organizations.
- Perform cybersecurity inspections, tests, and reviews.
- Ensure that Information and System Owners associated with DoD information received, processed, stored, displayed, or transmitted on each system are identified to establish accountability, access approvals, and special handling requirements.
- Ensure implementation of IS security measures and procedures including reporting incidents to the appropriate reporting chains and coordinating system-level responses to unauthorized disclosures in accordance with DoD Manual 5200.01, Volume 3 for classified information or DoD Manual 5200.01, Volume 4 for Controlled Unclassified Information (CUI), respectively.
- Ensure the secure configuration and approval of IT below the system level (i.e., products and IT services) in accordance with applicable guidance prior to acceptance into or connection to a DoD IS or PIT system.
- Author, monitor, and record system information in applicable databases. Prepare and record system, security status, and portfolio management information into the Air Force Information Technology Investment Portfolio Suite (referred to as ITIPS) for FISMA; Security, Interoperability, Supportability, Sustainability, Usability (SISSU); Clinger Cohen Act; and other statutory compliance.
- Author, review, certify, and/or maintain security management plans and RMF package artifacts including but not limited to: RMF Implementation Plans, System Security Management Plans, Information Support Plans, Program Protection Plans (PPPs), Security Risk Analyses, Security Vulnerability and Countermeasure Analyses, Vulnerability Management Plans, Common Control Packages, Security Concepts of Operations, OPSEC Plans, Authority-to-Connect guest system packages, and other system/network security related documents.
- Prepare, maintain, and submit a monthly report that captures the status of each A&A package to include an integrated schedule capable of showing high-level views of all packages and have the ability to delve in-depth into individual packages. Items to be addressed shall include: Authorization Status, RMF Progress, PoA&M Status, FISMA Compliance, Delivery of Documentation and Artifacts, Status of Incomplete items, Completed or Upcoming Reviews, Open Actions and Status, and Key Schedule Milestones.
- Support and assist external teams in the evaluation of systems Cybersecurity posture to include teams performing non-regular cyber tests, war-games, cyber penetration tests, and cyber studies conducted by the NSA, DISA, Air Force Audit Agency, or other organizations.
- Support the development, coordination, and implementation of cybersecurity-related special projects and taskers, e.g., Defensive Cyber Operations (DCO), Higher Headquarter requests, Notice to Airmen (NOTAMs), Technical Change Orders (TCOs), System Program Office (SPO), 16th AF, USSTRATCOM, USCYBERCOM, SAF/A6, SpOC/S6, AFGSC/A6, 460 Space Wing, and AFNWC/NC efforts.
Qualifications
15+ years experience in cyber security or information assurance. Bachelor’s degree in a related field. Must hold one of the following certifications: CISSP, CISM, GSLC, or CCISO. Experience with the certification and accreditation process. Significant experience in vulnerability scanning and analysis, including the use of automated tools and vulnerability management systems. Knowledge of intrusion prevention and network access control tools/systems. Understanding of system audit principles and security risk assessment. Strong understanding of security policy advocated by the U.S. Government including the Department of Defense and appropriate civil agencies, e.g., NIST. Able to perform work that involves ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools. Knowledge of cryptography and cryptographic key management concepts. General experience includes development of both common user and special purpose command and control/information systems with increasing responsibilities in the scope and magnitude of the systems for which solutions have been implemented. Must have a solid understanding of network infrastructure and mission assurance. Familiar with Federal government and DOD standards for IA/security including DIACAP, FISMA, NIST, and OMB. Must have solid communications skills and be capable of working with all levels of an organization. Must be a US Citizen and hold a current Secret clearance.
Applicants selected will be subject to a U.S. government security investigation and must meet eligibility requirements for access to classified information.
EOE/M/F/Vet/Disabled
-
Information Systems Security Officer
4 weeks ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeJob Summary:The Information Systems Security Officer (ISSO) will be responsible for ensuring the operational security posture of an information system. This includes working closely with the ISSM and ISO to develop and update authorization documentation, implement configuration management, and assess the security impact of changes.Key Responsibilities:Assist...
-
Information Systems Security Manager
3 months ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Security, Information Security Management, Information System SecurityCertifications:Cisco Certified...
-
Information Systems Security Manager
2 weeks ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphPublic Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Security, Information Security Management, Information System SecurityCertifications:Cisco Certified Network...
-
Information Systems Security Manager
3 weeks ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Cybersecurity, Information Security, Information System Security, Security EvaluationsCertifications:Experience:5...
-
Information Systems Security Manager
2 weeks ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphPublic Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Cybersecurity, Information Security, Information System Security, Security EvaluationsCertifications:NoneExperience:5 + years...
-
Information Systems Security Officer
3 weeks ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Security, Information Security Management, Information System SecurityCertifications:Cisco Certified...
-
Information Systems Security Manager
4 weeks ago
Hanscom Air Force Base, United States gTANGIBLE Corporation Full timeJob Title: Information Systems Security ManagergTANGIBLE Corporation is seeking a highly skilled Information Systems Security Manager to join our team. As a key member of our cybersecurity team, you will be responsible for ensuring the security and integrity of our information systems.Job Summary:The Information Systems Security Manager will serve as a...
-
Information Assurance System Security Engineer
2 months ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Assurance, Information Security, Information SystemsCertifications:Experience:15 + years of related...
-
Information Assurance System Security Engineer
2 weeks ago
Hanscom Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphPublic Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Assurance, Information Security, Information SystemsCertifications:NoneExperience:15 + years of related...
-
Information Systems Security Officer
3 weeks ago
Hanscom Air Force Base, United States GDIT Full timeJob Description:The Cybersecurity Specialist is responsible for ensuring the appropriate operational security posture is maintained for an information system. This involves working closely with the ISSM and ISO to develop and implement security measures to protect the system and its environment. The position requires a detailed knowledge of security aspects...
-
Information Systems Security Manager
6 months ago
Hanscom Air Force Base, United States gTANGIBLE Corporation Full timegTANGIBLE Corporation (gTC), , is a S corporation and a registered Government contractor that provides services and solutions in:National Security ProgramsProfessional, Administrative, and Management SupportMission and Warfighter SupportWe are a Service Disabled Veteran Owned Small Business (SDVOSB) and the founder has years of successful experience in the...
-
Information Systems Security Officer
3 months ago
Robins Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Security, Information Security Management, Information System SecurityCertifications:Cisco Certified...
-
Information Systems Security Manager II
3 weeks ago
Eglin Air Force Base, United States System High Corp Full timeJob DetailsSystem High Corporation is seeking a highly skilled Information Systems Security Manager II to join our team. As an ISSM II, you will serve as a principal advisor on all matters involving the security of information systems under your purview. Your primary function will be working within Special Access Programs (SAPs) supporting Department of...
-
Information Security Analyst SR
3 weeks ago
Tyndall Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:PipelineClearance Level Must Currently Possess:SecretClearance Level Must Be Able to Obtain:SecretSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Security, Information Systems, System Security, Vulnerability ManagementCertifications:CompTIA - Security+ - CompTIAExperience:7...
-
Information Security Analyst SR
2 weeks ago
Tyndall Air Force Base, United States General Dynamics Information Technology Full timeType of Requisition:PipelineClearance Level Must Currently Possess:SecretClearance Level Must Be Able to Obtain:SecretPublic Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Security, Information Systems, System Security, Vulnerability ManagementCertifications:CompTIA - Security+ - CompTIAExperience:7 + years of...
-
Information System Security Specialist
3 weeks ago
Eglin Air Force Base, United States Modern Technology Solutions Inc Full timeJob Title: Information System Security OfficerJob Summary:We are seeking a highly skilled Information System Security Officer to join our team at Modern Technology Solutions Inc. As an ISSO, you will be responsible for ensuring the appropriate operational security posture is maintained for an information system.Key Responsibilities:- Assist the ISSM in...
-
Information Systems Security Specialist
4 weeks ago
Eglin Air Force Base, United States TEKsystems Full timeJob DescriptionTEKsystems is seeking a highly skilled Information Systems Security Specialist to join our team. The successful candidate will administer, assure, and maintain the required operational security posture assigned information systems.Key Responsibilities:Develop and update the system security system control traceability matrix, system security...
-
Information Systems Security Officer
4 weeks ago
Edwards Air Force Base, California, United States Zachary Piper Full timeZachary Piper Solutions is seeking a skilled Information Systems Security Officer to support a long-term Air Force program at Edwards Air Force Base. As an ISSO, you will play a critical role in ensuring the security and compliance of the customer's critical systems.Responsibilities:Conduct periodic reviews of Information Systems to ensure ongoing compliance...
-
Information Systems Security Manager
2 months ago
Offutt Air Force Base, United States Booz Allen Hamilton Full timeInformation Systems Security ManagerThe Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to military organizations. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you—an information...
-
Information System Security Officer
2 weeks ago
Lackland Air Force Base, United States Insight Global Full timeTitle: TS/SCI Information System Security OfficerLocation: onsite at JBSA-LacklandDuration: 6-month contract-to-permanentPay Rate: $46-52/hour (depending on experience) Must Haves:Active TS/SCI security clearanceBachelor's Degree in Cybersecurity, Computer Science or related field3-5 years of experience in or surrounding the implementation of the Risk...