Cybersecurity Controls Manager

2 weeks ago


Washington, Washington, D.C., United States Vantage Point Consulting Inc. Full time

The Cybersecurity Controls Manager will oversee the implementation, management, and continuous improvement of Information Security Management System (ISMS) controls based on ISO 27001 and NIST standards.

This role will support client reporting and audit/assessment requirements, as well as the assessment, remediation and reporting of cyber risk, identifying the appropriate controls and protocols to reduce or manage IT risk.

Main Responsibilities:

  • Demonstrate fluency with ISO 27002:2022 controls;
  • Support ISO 27001 efforts by evaluating (i.e., assessing or auditing), recommending, developing, coordinating, monitoring and maintaining cyber security policies, procedures, processes, standards, guidelines and controls library;
  • Manage or support the enforcement of the InfoSec policy, procedure and process portfolio, including standards, guidelines and processes to verify alignment to Firm and Client InfoSec requirements and make recommendations for improvement;
  • Lead the remediation efforts associated with gaps in the information security program based on ISO 27001 and 27002 standards, independent assessments, regulatory and Client requirements;
  • Ability to explain technical threats, controls and remediation activities to both technical and non-technical stakeholders;
  • Oversee and support the Firm's InfoSec responses to client assessments and presentations;
  • Operationalize guidelines and roadmaps into actionable project plans, as well as manage multiple workstreams across matrixed teams;
  • Implement and socialize security related standards, procedures, processes and guidelines, as well as enforce and monitor/track adoption across stakeholder groups;
  • Provide stakeholder guidance regarding the development of and provides quality assurance reviews to procedure, process, standards and guidelines deliverables to validate alignment to Firm and Client requirements;
  • Assist with the creation and maintenance of the Cyber risk register and associated remediation activities;
  • Handles additional related projects as assigned.

Requirements:

  • Understanding of operational risks as related to technology solutions;
  • Awareness of additional information security standards (CSF, NIST, ISO), as well as the emerging cyber threat landscape;
  • Technical understanding of security auditing and assessment practices, applications, platforms and architectures;
  • Ability to develop and maintain a solid working relationship across multiple stakeholder groups;
  • Strong analytical skills.

Preferred Qualifications:

  • CISA, CISM, GSEC, CISSP or other security-related certification;
  • Strong understanding of information security concepts and technologies;
  • Strong understanding of industry control frameworks, risk management concepts, frameworks, and methodologies;
  • Client facing experience (e.g., consulting);
  • Fundamental knowledge of the operation of law practices;
  • Advanced knowledge of MS Outlook, Word, Excel, Visio, and PowerPoint.

Education:

  • Bachelor degree in Information Security, Information Assurance, Computer Science, Information Systems, or other related field (two years of additional experience may be substituted for two years of college credits);
  • At least seven (7+) years of combined information technology and information security experience (preferred).


  • Washington, Washington, D.C., United States LMI Full time

    Job SummaryWe are seeking a highly experienced Senior Cybersecurity Manager to join our team at LMI. As a key member of our cybersecurity team, you will be responsible for overseeing the entire Risk Management Framework (RMF) cycle, developing and maintaining system security plans, and ensuring compliance with relevant security policies and guidelines.The...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    Job Opportunity: We are seeking a highly skilled Industrial Control Systems Cybersecurity Specialist to join our team at Booz Allen Hamilton. As a key member of our cybersecurity team, you will be responsible for conducting cybersecurity assessments, security design engineering, and threat monitoring of non-IT systems, including industrial control systems...


  • Washington, Washington, D.C., United States ST2 ManTech Advanced Systems Intl Full time

    Job SummaryST2 ManTech Advanced Systems Intl is seeking a highly skilled Security Controls Engineer to join our team. As a Security Controls Engineer, you will be responsible for assessing and implementing security controls to ensure the confidentiality, integrity, and availability of sensitive information.Key ResponsibilitiesAssess and implement security...


  • Washington, Washington, D.C., United States PKH Enterprises Full time

    Job OpportunityWe are seeking a highly skilled Cybersecurity Subject Matter Expert (SME) and Supply Chain Risk Management (SCRM) Analyst to provide expert-level systems analysis, design, integration, and implementation advice on complex cybersecurity challenges, with a specific focus on managing supply chain risks.Key Responsibilities:Provide high-level...


  • Washington, Washington, D.C., United States Vets Hired Full time

    Job SummaryVets Hired is seeking a highly skilled Cybersecurity Risk Manager to join our team. As a key member of our security team, you will be responsible for conducting initial security assessments, maintaining security authorizations, and continuously updating security documentation to ensure compliance with NIST SP 800-37 Rev. 2.Key...


  • Washington, Washington, D.C., United States World Wildlife Fund Full time

    Cybersecurity SpecialistWorld Wildlife Fund (WWF) is seeking a highly skilled Cybersecurity Specialist to support our cybersecurity initiatives. The successful candidate will be responsible for monitoring, analyzing, and enhancing the security posture of our information systems.Key Responsibilities:Monitor and analyze security alerts and logsRespond to and...


  • Washington, Washington, D.C., United States ASRC Federal Holding Company Full time

    Cybersecurity Program ManagerWe are seeking a highly skilled and motivated Cybersecurity Program Manager to oversee cybersecurity and Supply Chain Risk Management (SCRM) programs. The Program Manager will be responsible for leading day-to-day project management, ensuring the successful execution of cybersecurity and SCRM initiatives, and managing the...


  • Washington, Washington, D.C., United States Group SSI Full time

    Group SSI is seeking a highly skilled Cybersecurity Specialist to support new Authority to Operate (ATO) packages in eMASS and XACTA. The ideal candidate will have a strong background in cybersecurity planning and maintenance, with experience in updating security documentation to reflect new or changed physical configurations and security requirements.The...


  • Washington, Washington, D.C., United States Zachary Piper Full time

    Cybersecurity Advisor RoleZachary Piper Solutions is seeking a highly skilled Cybersecurity Advisor to support international cybersecurity initiatives for a US Federal agency.Key Responsibilities:Develop and manage engagement and business strategy for cybersecurity critical infrastructure and threat intelligenceSupport mission-specific cyber efforts for...


  • Washington, Washington, D.C., United States Synergy ECP Full time

    About the Role:SPYROS Information & Technology Consulting, a wholly owned subsidiary of Synergy ECP, is seeking a highly skilled Cybersecurity Specialist to join our team. As a Service-Disabled Veteran Owned Small Business (SDVOSB), we provide unique and exceptional services to our clients in the government and national defense sectors.We are looking for a...


  • Washington, Washington, D.C., United States RIVA Solutions Full time

    Cybersecurity Project ManagerRIVA Solutions is seeking a highly skilled Cybersecurity Project Manager to oversee the successful execution of cybersecurity projects supporting our Federal Government customer.The ideal candidate will have hands-on experience in managing security projects, knowledge of the latest cybersecurity threats, and a strong...


  • Washington, Washington, D.C., United States Sayres and Associates Full time

    Cybersecurity AnalystSayres, a leading provider of defense support services to the DOD in the shipbuilding industry, is seeking a skilled Cybersecurity Analyst with Secret Clearance in Washington, DC.The Cybersecurity Analyst will play a vital role in ensuring the security and integrity of shipboard and shore-based operational sites, laboratory/development...


  • Washington, Washington, D.C., United States Envisioneering Full time

    Envisioneering, Inc. is seeking a highly skilled Cybersecurity Specialist to oversee the development and maintenance of a system's cybersecurity solutions. This position will be responsible for the following:Key Responsibilities:Develop and implement a system's cybersecurity solutions.Identify and categorize the system's security requirements.Assist with the...


  • Washington, Washington, D.C., United States Customer Value Partners Full time

    Job OverviewCyber Defense LeadCyber Value Partners (CVP) is seeking a seasoned Cyber Defense Lead to spearhead the implementation of a comprehensive cybersecurity program. This individual will lead a team of cybersecurity professionals in executing and supporting the program's objectives, ensuring the security and integrity of our clients' systems and...


  • Washington, Washington, D.C., United States Tetrad Digital Integrity Full time

    Tetrad Digital Integrity Job DescriptionWe are seeking a highly skilled Information Systems Security Officer to join our team at Tetrad Digital Integrity. As a leading-edge cybersecurity firm, we are committed to safeguarding and protecting our customers from increasing threats and vulnerabilities in the digital age.The successful candidate will support the...


  • Washington, Washington, D.C., United States Group SSI Full time

    Job Title: Cybersecurity SpecialistGroup SSI is seeking a highly skilled Cybersecurity Specialist to join our team. As a Cybersecurity Specialist, you will be responsible for providing cybersecurity planning and maintenance services, including updates of security documentation to reflect new or changed physical configurations and security requirements.Key...


  • Washington, Washington, D.C., United States Tria Federal Full time

    About This Opportunity:Tria Federal is seeking a highly skilled Cybersecurity Specialist to join our team. As an Information Systems Security Officer, you will be responsible for researching, developing, implementing, testing, and reviewing an organization's information security to protect information and prevent unauthorized access.This role requires a...


  • Washington, Washington, D.C., United States Vets Hired Full time

    Job Description for Cybersecurity SpecialistVets Hired is seeking a highly skilled Cybersecurity Specialist to join our team. The ideal candidate will have expertise in developing, implementing, and maintaining security policies, procedures, and controls in accordance with organizational and regulatory requirements.Main Responsibilities:Security Policy...


  • Washington, Washington, D.C., United States VISTA Technology Services Full time

    Cybersecurity Acquisition SpecialistVISTA Technology Services, Inc. is seeking a highly skilled Cybersecurity Acquisition Specialist to work in Washington, DC. The successful candidate will provide acquisition support for cybersecurity tools and products for shipboard application.Key Responsibilities:Provide program management support to US Navy customer in...


  • Washington, Washington, D.C., United States VISTA Technology Services Full time

    Cybersecurity Acquisition AnalystVISTA Technology Services, Inc. (VISTA) is a leading provider of cybersecurity solutions. We are currently seeking a highly skilled Cybersecurity Acquisition Analyst to join our team in Washington, DC.The successful candidate will be part of a highly professional, results-oriented company and will provide acquisition support...