Information Systems Security Manager

3 weeks ago


Washington, United States The Consortium Full time

Develops and administers information security procedures for systems in support of government agencies in the performance of classified programs and projects. Performs self-inspections and ensures compliance with applicable government security policies and procedures. Investigates information system security violations and implements corrective actions. Develops and implements information system security education and awareness programs. Serves and liaison to and interacts with government agencies to ensure compliance with policies and regulations.

Acts as a technical expert on program security. Performs work requiring advanced technical knowledge, often involving multiple phases and significant collaboration. Applies in-depth technical knowledge to independently and innovatively solve a full range of complex and sometimes unusual problems that impact organizational success. Brings industry-level expertise to function and recommends changes to remain up-to-date or competitive. Establishes processes and procedures to ensure the effective and efficient operation of a complex function. Has authority to take whatever action deemed advisable or necessary, subject only to organizational and departmental policies and processes. May provide work direction for less senior employees.

Responsibilities

Develops and administers information security procedures for information systems in support of government agencies in the performance of classified programs and projects.

  • Develops and executes an IT program detailed security policies, plans, and procedures that exceeds customer expectations and minimizes security risks.
  • Serves as management official and point-of-contact for all information system issues involving sensitive and classified information.
  • Manages security controls to ensure confidentiality, integrity, and availability of information and information systems; builds security into the development process and defines security specifications to support the acquisition of new systems, reviews all secure systems procurements to ensure that security has been considered and included.
  • Provides strategic guidance and advice on secure meetings and state-of-the-art conference room technologies.
  • Serves as liaison with program staff and other customers and can respond to short-notice tasks and provides security engineering and integration services to staff and other customers.
  • Investigates information system security violations and prepares reports specifying corrective actions for the current situation and preventative actions to be taken in the future.
  • Proactively coordinates the establishment of system security controls to protect sensitive government and institution information using authentication techniques, encryption, firewalls, and access controls.
  • Maintain systems in accordance with the security plan and Authorization to Operate (ATO).
  • Audits, monitors, and performs self-inspections of applications, systems, and security logs for security threats, vulnerabilities, and suspicious activities.
  • Implement measures to protect data from physical destruction or theft. Ensure that back-up procedures are in place for data recovery.
  • Conducts risk assessments of all systems and mitigates vulnerabilities wherever feasible.
  • Develops and implements information system security training, education, and awareness programs for all system users.
  • Interacts with government agencies to obtain rulings, interpretations, and acceptable deviations for compliance with Chapter 8 of NISPOM and other regulations.
  • Ensures compliance with the National Industrial Security Program Operating Manual (NISPOM), DCSA Assessment and Authorization Process Manual (DAAPM), Department of Defense (DoD) regulations, Intelligence Community Directives (ICDs) and Security Technical Implementation Guides (STIGs).
  • Prepares documentation, including Information Security Plans, outlining regulations, and establishing information security policy.
  • Ensures all users have the requisite security clearances, authorization, and Need-to-Know (NTK).
  • Complete required ISSM training within 6 months of hire.
  • Maintains appropriate standard of confidentiality. When handling secure, privileged, sensitive, or confidential information and matters, maintains strict confidence and exercises care to prevent disclosure to others. Accesses confidential information for work-related reasons only, following the policies and procedures of the organization. Ensures that any privileged, sensitive, or confidential information is securely stored, disposed of, and transmitted according to the Institutional guidance.

NONESSENTIAL JOB DUTIES

  • Related duties and special projects as assigned.

Requirements

Required Knowledge, Skills, and Abilities:

  • Thorough understanding of the NISPOM chapter 8 requirements.
  • Experience developing Information Systems security plans, policy, and procedures.
  • Experience configuring laptops/desktops/servers, install applications, setup network infrastructure and troubleshoot as required.
  • Have a strong understanding of computer operating systems (Windows and Linux), software and computer hardware.
  • Experience with Windows account administration, group policy administration, and directory permissions.
  • Experience with Windows Active Directory, Domain Controllers, Certificate Authority, DNS, DHCP, and Windows Update Services.
  • Experience maintaining and auditing Cisco ISE, switches, routers, and firewall.
  • Experience maintaining and auditing Palo Alto Intrusion Detection System.
  • Experience with security event and Incident management utilizing Splunk.
  • Experience with vulnerability management utilizing Tenable Nexus.
  • Experience establishing and maintaining SIPRNet connectivity.
  • Information Systems Security knowledge in system auditing.
  • Lead Defense Counterintelligence and Security Agency (DCSA) Security Vulnerability Assessments (SVA), Command Cyber Readiness Inspections (CCRI) and Other Government Agency (OGA) inspections.
  • Knowledge of the DoD Risk Assessment Methodology (DRAM).
  • Experience with Plan of Actions and Milestones (POA&M) tracking.
  • Experience with a Risk Management Framework (RMF) accreditation processes.
  • Experience working in complex environments with a high degree of organizational effectiveness.
  • Ability to work independently and with a team in a fast-paced environment.
  • Excellent communication skills with a proven ability to effectively interact with all levels of employees, contractors, and customers.

Minimum Education/Training Requirements: Bachelor’s degree in applicable field of Information Technology study including Computer Science or a related field, or equivalent knowledge.

Minimum Experience: Five years of related experience in an information systems security environment.

Physical Capabilities: Ability to work at a computer for extended periods of time.

Required Licenses, Certification or Registration: U.S. Citizenship. Active DoD Top Secret/DOE Q clearance. Possess a DoD 8570 IAM level III baseline certification (CISM, CISSP or other).

Supervisory Responsibilities/Controls: Reports to Director. General direction is provided. Works closely with Information Technology Services (ITS) department.



  • Washington, United States Watershed Security Full time

    COMPANY OVERVIEW Watershed Security is a Veteran Owned Small Business and a leader in providing quality Cyber Security Services to the Federal Government. Watershed is a great place to work, offering a challenging and respectful work environment. We are growing fast and strive to deliver our vision every day: “To inspire trust and respect with our...


  • Washington, United States Watershed Security Full time

    Job DescriptionJob DescriptionCOMPANY OVERVIEWWatershed Security is a Veteran Owned Small Business and a leader in providing quality Cyber Security Services to the Federal Government. Watershed is a great place to work, offering a challenging and respectful work environment. We are growing fast and strive to deliver our vision every day: “To inspire trust...


  • Washington DC, United States Watershed Security Full time

    COMPANY OVERVIEW Watershed Security is a Veteran Owned Small Business and a leader in providing quality Cyber Security Services to the Federal Government. Watershed is a great place to work, offering a challenging and respectful work environment. We are growing fast and strive to deliver our vision every day: “To inspire trust and respect with our...


  • Washington, United States Information Protection Solutions Full time

    Job DescriptionJob DescriptionRESPONSIBILITYAnalyze science, engineering, business, and other data processing problems to implement and improve computer systems. Analyze user requirements, procedures, and problems to automate or improve existing systems and review computer system capabilities, workflow, and scheduling limitations. May analyze or recommend...


  • Washington, United States General Dynamics Information Technology Full time

    Information Systems Security Officer (ISSO) – Active Top Secret / SCI Eligibility Required Seize your opportunity to make a personal impact as a n INFORMATION SYSTEMS SECURITY OFFICER (ISS0) . Join a high optempo , mission critical team in support of a DoD joint service organization at the highest levels of the federal government in the heart of our...


  • Washington, United States Information Protection Solutions Full time

    Job Description Job Description Information systems security officers (ISSO) research, develop, implement, test and review an organization's information security in order to protect information and prevent unauthorized access. Officers inform users about security measures, explain potential threats, install software, implement security measures and monitor...


  • Washington, United States Information Protection Solutions Full time

    Job DescriptionJob DescriptionInformation systems security officers (ISSO) research, develop, implement, test and review an organization's information security in order to protect information and prevent unauthorized access. Officers inform users about security measures, explain potential threats, install software, implement security measures and monitor...


  • Washington, United States Associates Systems LLC Full time

    Information System Security Engineer (ISSE) Washington Navy Yard, DC Secret Clearance required Job details Perform, and/or review, technical security assessments of enclaves within network to identify points of vulnerability, non-compliance with established IA standards and regulations and recommend mitigation strategies. Validate and verify system security...


  • Washington, United States Open Systems Technologies Corporation Full time

    Open Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with software development, scientific and engineering technical assistance, systems...


  • Washington, United States Treasury, Departmental Offices Full time

    As a/an Information Systems Security Manager, you will: Plan, develop, and oversees vital IT programs for OCIO Work closely with the Contracting Officer's Representative (COR) to ensure quality and timeliness of assigned deliverables. Advise program leads and serve as a single point of contact for an assigned program area (security domain) to track,...


  • Washington, Washington, D.C., United States Treasury, Departmental Offices Full time

    As a/an Information Systems Security Manager, you will:Plan, develop, and oversees vital IT programs for OCIO Work closely with the Contracting Officer's Representative (COR) to ensure quality and timeliness of assigned deliverables. Advise program leads and serve as a single point of contact for an assigned program area (security domain) to track, manage,...


  • Washington, United States US Treasury, Departmental Offices Full time

    **Duties**: As a/an Information Systems Security Manager, you will: - Plan, develop, and oversees vital IT programs for OCIO - Work closely with the Contracting Officer's Representative (COR) to ensure quality and timeliness of assigned deliverables. - Advise program leads and serve as a single point of contact for an assigned program area (security domain)...


  • Washington, United States Open Systems Technologies Full time

    Open Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with software development, scientific and engineering technical assistance, systems...


  • Washington DC, United States Associates Systems LLC Full time

    Information System Security Engineer (ISSE) Washington Navy Yard, DC Secret Clearance required Job details Perform, and/or review, technical security assessments of enclaves within network to identify points of vulnerability, non-compliance with established IA standards and regulations and recommend mitigation strategies. Validate and verify system...


  • Washington DC, United States The Consortium Full time

    Develops and administers information security procedures for systems in support of government agencies in the performance of classified programs and projects. Performs self-inspections and ensures compliance with applicable government security policies and procedures. Investigates information system security violations and implements corrective actions....


  • Washington, United States BTI Full time

    Job DescriptionJob DescriptionBusiness Technology Integrators (BTI) is seeking an Information Systems Security Manager (ISSM) to lead a team in executing risk management efforts against our customer's inventory of on premise, vendor and cloud-based systems. The successful candidate will provide support in the following areas:• Manage Information...


  • Washington, United States Open Systems Technologies Corporation Full time

    Open Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with software development, scientific and engineering technical assistance, systems...


  • Washington, United States Super Systems Inc Full time

    This role is hybrid - 2x a week onsite-3x a week REMOTE The Senior Information Systems Security Analyst will support IT management with control assessment, development, and maintenance, and risk assessment and response development. Specifically, this job requires the following: - Develop and maintain IT security controls per NIST SP 800-53 and Agency...


  • Washington, United States GTSC Talent Solutions Full time

    Job Description Employer: AEITS, a GTSC company Location: Washington, DC area ~~~~~~~~~~ All work is on-site, in-person in a SCIF environment. This is not a hybrid or remote position. Security Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Certifications: current DoD 8570 IAT II or IAM II certification Job Details: Perform...


  • Washington, United States Super Systems Inc Full time

    The Senior Information Systems Security Analyst will support IT management with control assessment, development, and maintenance, and risk assessment and response development. Specifically, this job requires the following: - Develop and maintain IT security controls per NIST SP 800-53 and Agency Security Policy standards. - Consult with experts to ensure...