Talent.com
Cyber and Data Security Manager
Cyber and Data Security ManagerEastern Research Group, Inc. • Alexandria, Virginia, United States, 22301
Cyber and Data Security Manager

Cyber and Data Security Manager

Eastern Research Group, Inc. • Alexandria, Virginia, United States, 22301
10 hours ago
Job type
  • Part-time
Job description

Cyber and Data Security Manager

ERG is a research and consulting firm that provides a wide range of support to federal, state, and commercial clients. ERG offers multidisciplinary teams with nationally recognized skills in engineering, science, economics, public health, informational technology, and communications. We hire people with the best minds and then provide them with a vibrant and flexible environment in which to develop their careers. The qualified individual must be highly motivated with the skills to prioritize, perform, and communicate effectively in a fast-paced environment.

ERG is seeking an experienced Cyber and Data Security Manager with a minimum of 10 years working in IT security operations including 3+ years of hands-on experience implementing and maintaining controls under NIST SP 800-171 (CMMC Level 2) within a U.S. Government contractor environment where CUI is processed.

The ideal candidate will be responsible for developing, maintaining and updating comprehensive compliance documents and procedures, for growing our security capabilities.

Job Description :

  • Develop, maintain, and update comprehensive compliance documentation including System Security Plan (SSPs), Plans of Action and Milestones (POA&M), implement policies and procedures and other supporting artifacts to ensure adherence to security standards
  • Collaborate with both internal resources as well as external consultants and auditors, to facilitate compliance reviews, assessments and gap analyses
  • Prepare for and facilitate CMMC assessments, including self-assessments and third-party audits by Certified Third-Party assessor Organizations (C3PAO)
  • Ensure that our information security assets, policies, and processes are reliable, available, provide confidentiality, and are generally safe from unauthorized use and intrusion
  • Provide day-to-day security support around the infrastructure and procedures used to protect and secure Controlled Unclassified Information (CUI), including ERGs related computer systems, data, and network
  • Perform risk analysis on threats, security alerts, and other suspicious systems or network activity
  • Lead incident response efforts, including investigation, containment, and recovery
  • Identify and analyze existing processes and procedures to meet new IT Security goals and objectives
  • Evaluate security incidents to determine impact & escalate appropriately
  • Monitor, aggregate, label, and manage artifacts related to the Security Program assessment and external audits
  • Develop, document, and assist with implementing ISO 270001 and NIST / CMMC framework standards, procedures, processes, and guidelines
  • Plan and monitor security measures for the protection of computer systems, networks, and information, including the use of Security Information and Event
  • Management (SIEM) products
  • Develop and deliver cyber-related training programs for employees and stakeholders
  • Provide security awareness training on recognizing and reporting potential indicators of external insider threats
  • Ensure integrity and security of company data
  • Support ERGs Change & Configuration Control Board (CCB) through actions such as documenting change requests and participating in regular CCB meetings

Qualifications and Skills :

  • Bachelors degree in computer science, Cyber / Information Security, or a related field
  • 10+ years working in IT security operations, including a minimum of 3years in a Corporate IT environment, in a hands-on role dedicated to information security compliance, systems security, IT risk management, IT audit, or similarly related
  • Must be able to obtain / maintain US DOD Security Clearance
  • Experience in recommending and implementing policies and procedures to ensure adherence to security standards, including the requirements of NIST SP 800-171 and CMMC Level 2
  • Demonstrated hands-on experience with NIST 800-171 and ISO 27001 Controls
  • Experience performing security audits with specialized SIEM tools (i.e., CrowdStrike, Arctic Wolf, Microsoft Sentinel) in the following environments : Microsoft GCC High, Microsoft 365, Azure AD, and Virtual Desktop
  • Ability to interpret technical vulnerability findings and work to develop and implement remediation plans
  • Strong knowledge of enterprise Information Security pillars including Perimeter security, Identity Management and Governance, Privileged Account Management, Compliance, Penetration testing, Encryption, Cloud Security, Incident Response, Vulnerability Management
  • Ability to effectively communicate security-related concepts to a broad range of technical and non-technical professionals
  • Hybrid position, ideally within commuting distance of one of ERGs Massachusetts, Northern Virginia, or North Carolina offices for occasional meetings
  • Excellent project and time management skills with the ability to plan, organize, and manage tasks on time with minimal supervision
  • A plus if you have :

  • Certified CMMC Professional (CCP), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISM), Certified Information Systems Manager (CISA), GIAC (Global Information Assurance Certification) / GSNA (GIAC Systems & Network Auditors) or other similar certification(s)
  • Demonstrated experience with NIST 800-53, NIST CSF, SANS / CIS Top 20, FedRAMP, FISMA, GDPR
  • Security clearance (active or recent expiration)
  • ERG offers competitive salaries and excellent benefits, including health and dental insurance, life insurance, long-term disability, educational benefits, FSAs, a generous 401k plan, profit sharing, an EAP, 11-20 paid vacation days per year, 10 paid holidays per year, 56 hours or more of sick leave (based on the state you work in) per year (pro-rated for part-time) and more. The salary range for all positions depends on the years and type of experience. ERG is an equal opportunity employer and complies with all applicable EEOC regulations. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual preference, national origin, disability, or status as a protected veteran. Please be aware, the only authentic corporate domain for ERG is https : / / www.erg.com. ERG may, on occasion, screen applicants via telephone or video interviews via Skype, Teams, GoToMeeting, or another type of video platform. However, any candidate extended a job offer might be asked to meet in person with an ERG employee before providing confidential personal information associated with new employment. If youre a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access ERGs online application process as a result of your disability. To request accommodation, please contact Human Resources via email at Resumes-Lex@erg.com or call (781) 674-7293. ERG fosters a friendly, flexible work environment. ERGers are dedicated to serving clients who are committed to making the world a better place. We promote and recognize principles of fairness and respect in the work we do, the partnerships we foster, and the culture we value both within and outside of our organization.

    $150,000 - $200,000 a year

    Compensation details : 150000-200000 Yearly Salary

    PIe57828f37ce6-30511-39136525

    Create a job alert for this search

    Manager Cyber Security • Alexandria, Virginia, United States, 22301

    Related jobs
    Identity Access Management (IAM) Manager - Cyber Security - Bowie, MD

    Identity Access Management (IAM) Manager - Cyber Security - Bowie, MD

    WesBanco Bank Inc. • Bowie, MD, United States
    Full-time +1
    Identity Access Management (IAM) Manager - Cyber Security.Bowie, Maryland, United States.This position is 100% remote within the Bank's footprint. Employee will work full time remote outside of a We...Show more
    Last updated: 21 days ago • Promoted
    Senior Network Security Engineering Manager (Cloud Implementation exp required)

    Senior Network Security Engineering Manager (Cloud Implementation exp required)

    Bank of America • Washington, DC, US
    Full-time
    Senior Network Security Engineering Manager (Cloud Implementation exp required).Boston, Massachusetts;Washington, District of Columbia. Chicago, Illinois; Denver, Colorado.To proceed with your appl...Show more
    Last updated: 12 hours ago • Promoted • New!
    Senior Security Manager

    Senior Security Manager

    Leidos Inc • Chantilly, VA, United States
    Full-time
    The Leidos Security Operations is seeking a proven, experienced security professional for a Senior Security Manager, to lead a multi-functional team and manage a portfolio of programs supporting ou...Show more
    Last updated: 28 days ago • Promoted
    Network Security SME, Lead

    Network Security SME, Lead

    Booz Allen Hamilton • Washington, DC, United States
    Full-time
    Your growth matters to us - explore our career development opportunities.Connect with others in our people-first culture and enhance our collective ingenuity. Learn how we’ll support you as you purs...Show more
    Last updated: 30+ days ago • Promoted
    Cloud Infrastructure Security, Assistant Manager

    Cloud Infrastructure Security, Assistant Manager

    Bloomberg Industry Group • Arlington, VA, United States
    Full-time
    You will be working on a team of Information Security specialists that are accountable for Bloomberg INDG's on-prem and cloud infrastructure security program. We are looking for a candidate who is e...Show more
    Last updated: 30+ days ago • Promoted
    Cyber and Data Security Manager

    Cyber and Data Security Manager

    Eastern Research Group, Inc. • Fairfax, Virginia, United States, 22030
    Part-time
    Cyber and Data Security Manager.ERG is a research and consulting firm that provides a wide range of support to federal, state, and commercial clients. ERG offers multidisciplinary teams with nationa...Show more
    Last updated: 17 days ago
    Cybersecurity Assessments Lead

    Cybersecurity Assessments Lead

    CompQsoft • Fort Meade, MD, United States
    Full-time
    Position : Cybersecurity Assessments Lead.Clearance : Top Secret, SCI eligible.Determines enterprise IA and security standards. Develops and implements IA / security standards and procedures.Coordinates...Show more
    Last updated: 1 day ago • Promoted
    Information System Security Manager (ISSM)

    Information System Security Manager (ISSM)

    The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
    Full-time
    Do you love solving problems while enabling impactful research to operate securely?.Are you passionate about making meaningful contributions to national security cyber missions?.Do you like collabo...Show more
    Last updated: 30+ days ago • Promoted
    Manager, Network Security, Tech & Data Risk Management

    Manager, Network Security, Tech & Data Risk Management

    Capital One • Falmouth, VA, US
    Full-time +1
    Manager, Network Security, Tech & Data Risk Management Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers.We are serious about tech...Show more
    Last updated: 1 day ago • Promoted
    Digital Network Exploitation Analyst (DNEA), Advisor

    Digital Network Exploitation Analyst (DNEA), Advisor

    Peraton • Fort Meade, MD, United States
    Full-time
    Digital Network Exploitation Analyst (DNEA), Advisor.US-MD-Fort Meade | US-TX-San Antonio | US-HI.Peraton's Cyber Mission in Annapolis Junction, MD supplies the Intel community with mission essenti...Show more
    Last updated: 19 hours ago • Promoted • New!
    Digital Network Exploitation Analyst (DNEA), Senior Associate

    Digital Network Exploitation Analyst (DNEA), Senior Associate

    Peraton • Fort Meade, MD, United States
    Full-time
    Digital Network Exploitation Analyst (DNEA), Senior Associate.Peraton's Cyber Mission in Annapolis Junction, MD supplies the Intel community with mission essential Next Generation SIGINT Analysts a...Show more
    Last updated: 19 hours ago • Promoted • New!
    Digital Network Exploitation Analyst (DNEA), Lead Associate

    Digital Network Exploitation Analyst (DNEA), Lead Associate

    Peraton • Fort Meade, MD, United States
    Full-time
    Digital Network Exploitation Analyst (DNEA), Lead Associate.Peraton's Cyber Mission in Annapolis Junction, MD supplies the Intel community with mission essential Next Generation SIGINT Analysts and...Show more
    Last updated: 19 hours ago • Promoted • New!
    IT Information Security Manager

    IT Information Security Manager

    SmartCommerce • Washington, DC, United States
    Full-time
    IT Information Security Manager.We are better together!!! And we hope that includes you!!! We’re a community of problem solvers passionate about helping clients take their sales to the next level.W...Show more
    Last updated: 6 days ago • Promoted
    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

    Capital One • Mc Lean, VA, US
    Remote
    Full-time +1
    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote).Ever since our first credit card customer in 1994, Capital One has recognized that technology and data...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cyber Risk & Security Manager

    Senior Cyber Risk & Security Manager

    BTI • Washington, DC, United States
    Full-time
    A leading company in cybersecurity is seeking an Information Systems Security Manager to oversee risk management processes. The successful candidate will lead a team focused on IT security goals and...Show more
    Last updated: 2 days ago • Promoted
    Information Assurance Engineer / Security Manager

    Information Assurance Engineer / Security Manager

    C2 Labs, Inc. • Washington, DC, United States
    Full-time
    Information Assurance Engineer / Security Manager.C2 Labs partners with clients on their IT transformation journey via our industry-leading capabilities in full stack development, hyper-automation / ...Show more
    Last updated: 29 days ago • Promoted
    Cyber Security Manager

    Cyber Security Manager

    CARFAX • Centreville, VA, United States
    Full-time
    Isn't it time you bragged about where you work? At CARFAX, we do, every day.We pride ourselves on being mission-focused on helping to grow a brand built on accuracy and integrity.We care deeply abo...Show more
    Last updated: 4 days ago • Promoted
    Security Transformation Manager

    Security Transformation Manager

    Accenture • Arlington, VA, United States
    Full-time
    Security Transformation Manager.Accenture LLP; Arlington, VA) : Accenture LLP has multiple openings for the position of Security Transformation Manager in Arlington, VA, and the job duties are as fo...Show more
    Last updated: 1 day ago • Promoted