Talent.com
Information Systems Security Manager (ISSM) Subject Matter Expert
Information Systems Security Manager (ISSM) Subject Matter ExpertSumaria Systems, Inc • Hanscom Air Force Base, MA, United States
Information Systems Security Manager (ISSM) Subject Matter Expert

Information Systems Security Manager (ISSM) Subject Matter Expert

Sumaria Systems, Inc • Hanscom Air Force Base, MA, United States
Hace 13 horas
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

Job Title : Information Systems Security Manager (ISSM) Subject Matter Expert

Job Description : Sumaria Systems is seeking an Information System Security Manager (ISSM) to ensure system and application deliverables meet all required cyber security policies and regulations for the Technical Advisory and Assistance Services (TAAS) program at Hanscom AFB. This is a full-time position.

ISSM SME responsibilities include, but are not limited to :

  • Manage the system / application Assessment and Authorization (A&A) efforts, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Department of the Air Force policies (i.e., RMF).
  • Develop and conduct a Continuous Monitoring plan in support of A&A activities to maintain ongoing awareness of cybersecurity, vulnerabilities, and threats to facilitate risk-based decision making.
  • Maintain and report system assessment and authorization status and issues in accordance with DoD Component guidance.
  • Participate in meetings / teleconferences, change control boards (CCBs) and working groups (WGs) to ensure the continued alignment of cybersecurity requirements in the technical baselines, the system security architecture, information flows, design, and the security controls.
  • Evaluate system sources of changes such as Deficiency Reports (DRs), Problem Reports (PRs), Change Requests / Proposals (CRs / CPs), and AF Form 1067s; provide inputs to the root cause analysis reporting and the formulation of recommended solution from alternatives; determine the security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and if any, document in written reports the changes / revisions to the system's RMF artifacts.
  • Review and provide inputs to modification packages, program / system documents and support agreements updates, and communications and network infrastructure upgrades to ensure proper cybersecurity configuration modification management; implementation of technical, managerial, operational requirements; and support requirements (e.g. planning, testing, test infrastructure, documentation, training, etc.) are identified.
  • Review system test plans and test results and if necessary, observe system testing for security control implementation IAW cybersecurity policies, guidance, and plan. Document findings in a report.
  • Perform security impact analysis on any system change and appropriately prepare letters of assurance, security impact letters, and risk assessment letters to include exceptions, deviations, or waivers to cybersecurity requirements when applicable.
  • Continuously monitor intelligence and open-source information for vulnerabilities affecting AFNWC / NCL systems, assess risk, and provide POA&M recommendations to ISSM and PM as required.
  • Act as the primary cybersecurity technical advisor to Program Management and System Engineers for systems under their purview.
  • Coordinate Trusted Systems and Networks (TSN) and Supply Chain Risk Management (SCRM) evaluation of program information, software, and hardware throughout the program life cycle.
  • Ensure that cybersecurity-related events or configuration changes that may impact systems authorization or security posture are formally reported to the AO and other affected parties, such as IOs and stewards and AOs of interconnected DoD ISs.
  • Ensure that cybersecurity inspections, tests, and reviews are synchronized and coordinated with affected parties and organizations.
  • Perform cybersecurity inspections, tests, and reviews.
  • Ensure ISSMs are appointed in writing and provide oversight to ensure they are following established cybersecurity policies and procedures.
  • Ensure that Information and System Owners associated with DoD information received, processed, stored, displayed, or transmitted on each system are identified to establish accountability, access approvals, and special handling requirements.
  • Maintain a repository for all organizational or system-level cybersecurity-related documentation.
  • Ensure implementation of IS security measures and procedures including reporting incidents to the appropriate reporting chains and coordinating system-level responses to unauthorized disclosures in accordance with DoD Manual 5200.01, Volume 3 for classified information or DoD Manual 5200.01, Volume 4 for Controlled Unclassified Information (CUI), respectively.
  • Ensure handling of possible or actual data spills of classified information resident in ISs, are conducted in accordance with DoD 5200.01, Volume 3.
  • Ensure the secure configuration and approval of IT below the system level (i.e., products and IT services) in accordance with applicable guidance prior to acceptance into or connection to a DoD IS or PIT system.
  • Author, monitor, and record system information in applicable databases. Prepare and record system, security status, and portfolio management information into the Air Force Information Technology Investment Portfolio Suite (referred to as ITIPS) for Federal Information Security Management Act (FISMA); Security, Interoperability, Supportability, Sustainability, Usability (SISSU); Clinger Cohen Act; and other statutory compliance.
  • Author, review, certify, and / or maintain security management plans and RMF package artifacts including but not limited to : RMF Implementation Plans, System Security Management Plans, Information Support Plans, Program Protection Plans (PPPs), Security Risk Analyses, Security Vulnerability and Countermeasure Analyses, Vulnerability Management Plans, Common Control Packages, Security Concepts of Operations, Operational Security (OPSEC) Plans, Authority-to-Connect guest system packages, and other system / network security related documents.
  • Prepare, maintain, and submit a monthly report that captures the status of each A&A package to include an integrated schedule capable of showing high-level views of all packages and have the ability to delve in-depth into individual packages. Items to be addressed shall include : Authorization Status, RMF Progress, PoA&M Status, FISMA Compliance, Delivery of Documentation and Artifacts, Status of Incomplete items, Completed or Upcoming Reviews, Open Actions and Status, and Key Schedule Milestones.
  • Support and assist external teams in the evaluation of systems Cybersecurity posture to include teams performing non-regular cyber tests, war-games, cyber penetration tests, and cyber studies conducted by the NSA, DISA, Air Force Audit Agency, or other organizations.
  • Support the development, coordination, and implementation of cybersecurity-related special projects and taskers, e.g., Defensive Cyber Operations (DCO), Higher Headquarter requests, Notice to Airmen (NOTAMs), Technical Change Orders (TCOs), System Program Office (SPO), 16th AF, USSTRATCOM, USCYBERCOM, SAF / A6, SpOC / S6, AFGSC / A6, 460 Space Wing, and AFNWC / NC efforts.
  • For each system, maintain a current software bill of materials that contains the elements identified in the National Telecommunications and Information Administration publication "The Minimum Elements for a Software Bill of Materials", July 12, 2021.
  • Shall meet the Advanced level qualification requirements for Information System Security Manager (722) or Vulnerability Assessment Analyst (541) as outlined in DoD Cyber Workforce Framework - DoDI 8140.01, DoDI 8140.02, and DoDM 8140.03.
  • Perform Information Systems Security Management (722) and Vulnerability Assessment Analyst (541) Core / Additional Tasks and meet the KSAs as outlined in DoD Cyber Workforce Framework - DoDI 8140.01, DoDI 8140.02, and DoDM 8140.03.

Required Skills / Education : Bachelor's degree in a related field. Must hold one of the following certifications : CISSP, CISM, GSLC, or CCISO. Experience with the certification and accreditation process. Significant experience in vulnerability scanning and analysis, including the use of automated tools and vulnerability management systems. Knowledge of intrusion prevention and network access control tools / systems. Understanding of system audit principles and security risk assessment. Strong understanding of security policy advocated by the U.S. Government including the Department of Defense and appropriate civil agencies, e.g., NIST. Able to perform work that involves ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools. Knowledge of cryptography and cryptographic key management concepts. General experience includes development of both common user and special purpose command and control / information systems with increasing responsibilities in the scope and magnitude of the systems for which solutions have been implemented. Must have a solid understanding of network infrastructure and mission assurance. Familiar with Federal government and DOD standards for IA / security including DIACAP, FISMA, NIST, and OMB. Must have solid communications skills and be capable of working with all levels of an organization.

Education : Master's Degree

Years of Experience : Over 10 years

Travel : Minor

Security Clearance Required : Top Secret / SCI

Position Type : Full Time

Work Location : Hanscom AFB, MA

Top salaries paid for qualified candidates.

Agency submissions are not being accepted at this time.

For more information on Sumaria Systems, please visit our website at www.sumaria.com.

Sumaria is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, creed, religion, national origin, sex, sexual orientation, gender identity and expression, age, disability, or protected veteran status.

Sumaria is a Full Lifecycle Engineering, Technical Services and Professional Solutions company in support of the Warfighter, supporting modernization, high end services and next generation capabilities in contested domains. Sumaria has been a trusted partner to U. S. Department of Defense for more than 40 years, providing Lifecycle Systems Engineering, Advisory & Analysis / SETA, C5ISR and Enterprise Information Technology solutions. With expertise to lead, insight to deliver and commitment to succeed; we staff each mission with a carefully selected team of seasoned professionals. We're Headquartered in Peabody, MA, and have regional offices across the nation.

Sumaria Systems only provides engineering services to the federal government and does not provide professional engineering or surveying services to the public within the meaning of Ohio Revised Code Section 4733.16.

Crear una alerta de empleo para esta búsqueda

Information System Security Manager • Hanscom Air Force Base, MA, United States

Ofertas relacionadas
Journeyman Information Systems Security Manager (ISSM)

Journeyman Information Systems Security Manager (ISSM)

Sumaria Systems, Inc • Hanscom Air Force Base, MA, United States
A tiempo completo
Journeyman Information Systems Security Manager (ISSM).Sumaria Systems is seeking an Information System Security Manager (ISSM) to ensure system and application deliverables meet all required cyber...Mostrar más
Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
Information Systems Security Manager

Information Systems Security Manager

Georgia Tech • Lincoln, MA, United States
A tiempo completo +1
Georgia Tech prides itself on its technological resources, collaborations, high-quality student body, and its commitment to building an outstanding and diverse community of learning, discovery, and...Mostrar más
Última actualización: hace 18 días • Oferta promocionada
Information Systems Security Engineer (ISSE)

Information Systems Security Engineer (ISSE)

STR • Woburn, MA, US
A tiempo completo
The Security team at STR is comprised of highly skilled professionals who are responsible for maintaining compliance with Government protocol and directives. The Classified Cybersecurity (CCS) team ...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Network & Information Security Manager

Network & Information Security Manager

Eclaro • Needham Heights, MA, United States
A tiempo completo
Network and Information Security Manager.Use your skills where innovative technology solutions begin.Network and Information Security Manager. ECLARO's client is a leading technology solutions provi...Mostrar más
Última actualización: hace 11 horas • Oferta promocionada • Nueva oferta
Information Systems Security Manager (ISSM) I

Information Systems Security Manager (ISSM) I

General Dynamics Information Technology • Bedford, MA, United States
A tiempo completo
Clearance Level Must Currently Possess : .Clearance Level Must Be Able to Obtain : .Cybersecurity, Information Security, Information System Security, Security Evaluations. Information Systems Security M...Mostrar más
Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
Information Security Analyst and Project Manager

Information Security Analyst and Project Manager

Harvard T.H. Chan School of Public Health • Boston, MA, United States
A tiempo completo
Information Security Analyst and Project Manager.By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovatio...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
ISSM 2

ISSM 2

IC-CAP, LLC • Bedford, MA, United States
A tiempo completo
Information System Security Manager (ISSM) 2-.This is a future position that may come open in the future.We are currently building our pipeline. The primary function serves as a principal advisor on...Mostrar más
Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
Information Security Senior Manager

Information Security Senior Manager

Pharmaron • Waltham, MA, United States
A tiempo completo
Manager, Information Security (Microsoft 365 Security SME).Exton (PA) or Waltham (MA) – On-site with travel to other USA locations. Unfortunately, we cannot support work visa permit applications for...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Information Security Analyst and Project Manager

Information Security Analyst and Project Manager

ARMA International • Boston, MA, United States
A tiempo completo
By working at Harvard University, you join a vibrant community that advances Harvard's world‑changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expert...Mostrar más
Última actualización: hace 10 días • Oferta promocionada
Information Systems Security Manager (ISSM) with TS / SCI

Information Systems Security Manager (ISSM) with TS / SCI

Macpower Digital Assets Edge • Hanscom Air Force Base, MA, United States
A tiempo completo
Serve as the primary advisor on the security of information systems.Provide support for Special Access Programs (SAPs) within Department of Defense (DoD) environments. Manage day-to-day security ope...Mostrar más
Última actualización: hace 11 horas • Oferta promocionada • Nueva oferta
Information Systems Security Manager (ISSM)

Information Systems Security Manager (ISSM)

Abacus Technology • Hanscom Air Force Base, MA, United States
A tiempo completo
Abacus Technology is seeking an Information System Security Manager (ISSM) to ensure system and application deliverables meet all required cyber security policies and regulations for the Technical ...Mostrar más
Última actualización: hace más de 30 días • Oferta promocionada
Information System Security Manager (ISSM) (Onsite)

Information System Security Manager (ISSM) (Onsite)

RTX • Westford, MA, United States
A tiempo completo
HMA03 : ISR Systems - Westford HO 7 Technology Park Drive, Westford, MA, 01886 USA.Person, or Immigration Status Requirements : . Collins Aerospace is seeking an Information Systems Security Manager (I...Mostrar más
Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
Information Systems Security Manager (ISSM)

Information Systems Security Manager (ISSM)

Antenna Research Associates • North Billerica, MA, United States
A tiempo completo
ARA is a leading C5ISR company that designs, manufactures, tests and installs innovative technologies that provide the national security community with unparalleled situational awareness, threat de...Mostrar más
Última actualización: hace 11 horas • Oferta promocionada • Nueva oferta
Information System Security Manager (ISSM) (Onsite)

Information System Security Manager (ISSM) (Onsite)

Raytheon Technologies • Westford, MA, United States
A tiempo completo
HMA03 : ISR Systems - Westford HO 7 Technology Park Drive, Westford, MA, 01886 USA.Person, or Immigration Status Requirements : . Collins Aerospace is seeking an Information Systems Security Manager (I...Mostrar más
Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
Information System Security Manager I (ISSM I)

Information System Security Manager I (ISSM I)

Falcon IT & Staffing Solutions • Bedford, MA, United States
A tiempo completo
Seeking a mid-level Information System Security Manager I (ISSM I) to provide expert oversight and advisory services on the security of information systems within Special Access Programs (SAPs) sup...Mostrar más
Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
Information Systems Security Manager

Information Systems Security Manager

STR • Woburn, MA, United States
A tiempo completo
The Security team at STR is comprised of highly skilled professionals who are responsible for maintaining compliance with Government protocol and directives. The Classified Cybersecurity (CCS) team ...Mostrar más
Última actualización: hace 11 horas • Oferta promocionada • Nueva oferta
Information Security Analyst and Project Manager

Information Security Analyst and Project Manager

Harvard University • Boston, MA, United States
A tiempo completo
By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expert...Mostrar más
Última actualización: hace 7 días • Oferta promocionada
Information Systems Security Manager (ISSM)

Information Systems Security Manager (ISSM)

GE Aerospace • Lynn, MA, United States
Indefinido
GE Aviation Systems - Edison Works in Lynn, MA is seeking an Information System Security Manager (ISSM) in support of US Government (USG), Department of Defense (DoD) activities.In this role, the s...Mostrar más
Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta