Cyber and Data Security Manager
2 days ago
ERG is seeking an experienced Cyber and Data Security Manager with a minimum of 10 years working in IT security operations including 3+ years of hands-on experience implementing and maintaining controls under NIST SP 800-171 (CMMC Level 2) within a U.S. Government contractor environment where CUI is processed.
The ideal candidate will be responsible for developing, maintaining and updating comprehensive compliance documents and procedures, for growing our security capabilities.
Job Description:
- Develop, maintain, and update comprehensive compliance documentation including System Security Plan (SSPs), Plans of Action and Milestones (POA&M), implement policies and procedures and other supporting artifacts to ensure adherence to security standards
- Collaborate with both internal resources as well as external consultants and auditors, to facilitate compliance reviews, assessments and gap analyses
- Prepare for and facilitate CMMC assessments, including self-assessments and third-party audits by Certified Third-Party assessor Organizations (C3PAO)
- Ensure that our information security assets, policies, and processes are reliable, available, provide confidentiality, and are generally safe from unauthorized use and intrusion
- Provide day-to-day security support around the infrastructure and procedures used to protect and secure Controlled Unclassified Information (CUI), including ERG's related computer systems, data, and network
- Perform risk analysis on threats, security alerts, and other suspicious systems or network activity
- Lead incident response efforts, including investigation, containment, and recovery
- Identify and analyze existing processes and procedures to meet new IT Security goals and objectives
- Evaluate security incidents to determine impact & escalate appropriately
- Monitor, aggregate, label, and manage artifacts related to the Security Program assessment and external audits
- Develop, document, and assist with implementing ISO 270001 and NIST/CMMC framework standards, procedures, processes, and guidelines
- Plan and monitor security measures for the protection of computer systems, networks, and information, including the use of Security Information and Event
- Management (SIEM) products
- Develop and deliver cyber-related training programs for employees and stakeholders
- Provide security awareness training on recognizing and reporting potential indicators of external insider threats
- Ensure integrity and security of company data
- Support ERG's Change & Configuration Control Board (CCB) through actions such as documenting change requests and participating in regular CCB meetings
- Bachelor's degree in computer science, Cyber / Information Security, or a related field
- 10+ years working in IT security operations, including a minimum of 3years in a Corporate IT environment, in a hands-on role dedicated to information security compliance, systems security, IT risk management, IT audit, or similarly related
- Must be able to obtain/maintain US DOD Security Clearance
- Experience in recommending and implementing policies and procedures to ensure adherence to security standards, including the requirements of NIST SP 800-171 and CMMC Level 2
- Demonstrated hands-on experience with NIST 800-171 and ISO 27001 Controls
- Experience performing security audits with specialized SIEM tools (i.e., CrowdStrike, Arctic Wolf, Microsoft Sentinel) in the following environments: Microsoft GCC High, Microsoft 365, Azure AD, and Virtual Desktop
- Ability to interpret technical vulnerability findings and work to develop and implement remediation plans
- Strong knowledge of enterprise Information Security pillars including Perimeter security, Identity Management and Governance, Privileged Account Management, Compliance, Penetration testing, Encryption, Cloud Security, Incident Response, Vulnerability Management
- Ability to effectively communicate security-related concepts to a broad range of technical and non-technical professionals
- Hybrid position, ideally within commuting distance of one of ERG's Massachusetts, Northern Virginia, or North Carolina offices for occasional meetings
- Excellent project and time management skills with the ability to plan, organize, and manage tasks on time with minimal supervision
- Certified CMMC Professional (CCP), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISM), Certified Information Systems Manager (CISA), GIAC (Global Information Assurance Certification)/GSNA (GIAC Systems & Network Auditors) or other similar certification(s)
- Demonstrated experience with NIST 800-53, NIST CSF, SANS / CIS Top 20, FedRAMP, FISMA, GDPR
- Security clearance (active or recent expiration)
-
Cyber and Data Security Manager
2 days ago
Alexandria, VA, United States ERG Inc Full timeERG is a research and consulting firm that provides a wide range of support to federal, state, and commercial clients. ERG offers multidisciplinary teams with nationally recognized skills in engineering, science, economics, public health, informational technology, and communications. We hire people with the best minds and then provide them with a vibrant and...
-
Cyber and Data Security Manager
8 hours ago
Alexandria, VA, United States ERG Inc Full timeERG is a research and consulting firm that provides a wide range of support to federal, state, and commercial clients. ERG offers multidisciplinary teams with nationally recognized skills in engineering, science, economics, public health, informational technology, and communications. We hire people with the best minds and then provide them with a vibrant and...
-
Cyber Security Engineer III
6 days ago
Alexandria, VA, United States ECS Limited Full timeECS is seeking a Cyber Security Engineer III to work in Springfield, VA or Seaside, CA where you will be supporting DMDC. In this position will be expected to serve as the ACEM (Automated Continuous Endpoint Monitoring) /Tanium Engineer. We are currently seeking a skilled Tanium Engineer who possesses a keen interest in expanding their expertise to encompass...
-
Cyber Security Engineer III
6 days ago
Alexandria, VA, United States ECS Limited Full timeECS is seeking a Cyber Security Engineer III to work in Springfield, VA or Seaside, CA where you will be supporting DMDC. In this position will be expected to serve as the ACEM (Automated Continuous Endpoint Monitoring) /Tanium Engineer. We are currently seeking a skilled Tanium Engineer who possesses a keen interest in expanding their expertise to encompass...
-
Cyber Security Engineer III
4 days ago
Alexandria, VA, United States ECS Limited Full timeECS is seeking a Cyber Security Engineer III to work in Springfield, VA or Seaside, CA where you will be supporting DMDC. In this position will be expected to serve as the ACEM (Automated Continuous Endpoint Monitoring) /Tanium Engineer. We are currently seeking a skilled Tanium Engineer who possesses a keen interest in expanding their expertise to encompass...
-
Cyber Security Engineer III
8 hours ago
Alexandria, VA, United States ECS Limited Full timeECS is seeking a Cyber Security Engineer III to work in Springfield, VA or Seaside, CA where you will be supporting DMDC. In this position will be expected to serve as the ACEM (Automated Continuous Endpoint Monitoring) /Tanium Engineer. We are currently seeking a skilled Tanium Engineer who possesses a keen interest in expanding their expertise to encompass...
-
Cyber Security Analyst
2 days ago
Alexandria, VA, United States VetJobs Full timeJob Description ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their roles. The following position is available to Veterans, Transitioning Military, National Guard and Reserve Members, Military Spouses, Wounded Warriors, and their Caregivers. If you have the required skill set,...
-
Cyber Security Analyst
9 hours ago
Alexandria, VA, United States VetJobs Full timeJob Description ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their roles. The following position is available to Veterans, Transitioning Military, National Guard and Reserve Members, Military Spouses, Wounded Warriors, and their Caregivers. If you have the required skill set,...
-
Cyber Security Analyst
9 hours ago
Alexandria, VA, United States NANA Regional Corp Full timeTuvli is seeking a highly motivated and self-directed individual to fill the role of a Cyber Security Analyst for our existing government client in the Alexandria/Kingstown, VA area. Responsibilities Collect relevant data from a variety of sources to perform incident and vulnerability analysis to recommend threat and vulnerability risk mitigation...
-
Cyber Operations Splunk Engineer
2 weeks ago
Alexandria, VA, United States Booz Allen Hamilton Full timeJob Number: R0226862Cyber Operations Splunk Engineer Key Role: Support enterprise vulnerability management and cyber defense operations. Provide cyber operations monitoring and notification capabilities, to include developing and enhancing Splunk dashboards and adjudicating alerts and notifications in a timely manner. Apply expertise in Python scripting,...