Information Systems Security Manager - NAVSUP OIS/Clearance Required

GDIT
Yorktown, VA, USA
$127.5K-$172.5K a year
Temporary
Full-time

Job Description :

Information Systems Security Manager NAVSUP OIS - Secre Clearance Required

Overview / Job Responsibilities

GDIT is looking for an experienced Information Systems Security Manager (ISSM) who can prepare, submit, and monitor accreditation packages through the Risk Management Framework (RMF) process ensuring receipt of Interim Authority to Test (IATT) or Authority to Operation (ATO) in support of the Naval Supply Systems Command (NAVSUP) Ordnance Information System (OIS) program.

The ISSM will not only maintain current operating cybersecurity environment (data center) but will also support the program’s transition to AWS GovCloud operating environment.

The ISSM will apply their knowledge of Cybersecurity engineering best practices used to secure technical solutions, including applications, systems, architectures, and infrastructures that are operationally viable and efficient on-site in either Mechanicsburg, PA, or Yorktown, VA.

This critical role will also be responsible for :

Develop and maintain a formal IS security program and policies for their assigned area of responsibility.

Provide technical and procedural Information System (IS) Security advice to government and industrial teams.

Develop and oversee operational information systems security implementation policy and guidelines.

Coordinate with PSO or cognizant security official on approval of External Information Systems (e.g. guest systems, interconnected system with another organization).

Oversee ISSOs under their purview to ensure they follow established IS policies and procedures.

Assume ISSO responsibilities in the absence of the ISSO; maintain required IA certifications.

Ensure System Administrators (SA) monitor all available resources that provide warnings of system vulnerabilities or ongoing attacks.

Ensure approved procedures are used for sanitizing and releasing system components and media.

Maintain a repository of all security authorizations for IS under their purview.

Coordinate IS security inspections, tests, and reviews.

Ensure proper measures are taken when an IS incident or vulnerability is discovered.

Ensure data ownership and responsibilities are established for each IS, and specific requirements (to include accountability, access and special handling requirements) are enforced.

Ensure development and implementation of an effective IS security education, training, and awareness program.

Ensure CM policies and procedures for authorizing the use of hardware / software on an IS are followed. Any additions, changes or modifications to hardware, software, or firmware must be coordinated with the appropriate AO prior to the addition, change or modification.

Serve as a voting member of the Configuration Control Board (CCB) and / or the Risk Executive Board, if applicable. The ISSM shall have authority to veto any proposed change they feel is detrimental to security.

Appeals on an ISSM / ISSO veto may be taken to the AO. The ISSM may elect to delegate this responsibility to the ISSO.

Maintain a working knowledge of system functions, security policies, technical security safeguards, and operational security measures.

Manage, maintain, and execute the information security continuous monitoring plan.

Ensure a record is maintained of all security-related vulnerabilities and ensure serious or unresolved violations are reported to the AO / DAO;

and Assess changes to the system, its environment, and operational needs that could affect the security authorization.

Primary Responsibilities :

Meeting and maintaining CYBER certification and accreditation requirements, including researching, testing and providing technical information for obtaining CYBER accreditation.

Developing Security Requirements Traceability Matrix (STRM), aligning security requirements with the individual components of a system.

Performing checks of systems and applications for IA vulnerabilities using approved automated IA tools (ACAS, SCAP-compliant scanners, DISA STIG Viewer, etc.

custom scripts and manual processes (i.e., Security Technical Implementation Guides STIGS ).

Monitoring OIS security posture, documenting raw findings in a quick look report, for customer notification. Create and maintain system Plan of Action and Milestones (POA&Ms) of open vulnerabilities and applied mitigations utilizing Department of Defense Enterprise Mission Assurance Support Service (eMASS) tool.

Supporting the development and documentation of risk assessment results and recommendations using identified threats, applicable vulnerabilities, and likelihood of occurrence within context of risk tolerances

Monitor all database and application software used in OIS for version change control and nearing / exceeding last date allowed in the Department of Navy Application Database Management System (DADMS).

Coordinating / interfacing with OIS Technical Team, Defense Information Systems Agency (DISA), IA Staff, and Fleet Cyber Command to document, review, revise, and submit changes related to Ports, Protocols, and Services (PPS), Access Control Lists (ACLs), and Whitelists.

This support includes preparing and submitting the registration forms for new requirements.

Supporting DOD Portfolio Repository DON (DITPR-DON) to support the annual review.

Providing recommendations for corrective actions and mitigation strategies.

Producing security risk assessment briefs and reports for delivery to stakeholders and senior management.

Support the DevSecOps team in implementing Cyber Security requirements to achieve and maintain IATT and ATO

Interpret OS, web server, and database scans to facilitate resolving security findings with the DevSecOps team and external teams

Ensure systems are scanned, patched, and compliant with DoD policy

Troubleshoot Windows and RHEL security policies

Support with configurations including CloudWatch logs, registering systems, reporting and manage findings

Assess systems to determine applicable IA controls based on design, architecture, and data

Attend risk management and system meetings to provide status updates and take action items

Minimum Qualifications :

Must have DOD Secret level clearance to start

Certification Requirement : Directive 8570.1 / 8140 IAM-III : Certified Information Systems Security Professional (CISSP)

Bachelor’s degree with a minimum of 10 years of relevant experience

Experience performing risk assessments and audits

Experience using DoD approved tools (ACAS, SCAP-compliant scanners, eMASS, etc.).

Knowledge of the overall Risk Management Framework and NIST compliance as a security professional

Experience presenting to clients or management to present technical and non-technical information to allow key personnel to make informed decisions

Experience successfully advising stakeholders through the ATO process

Familiarity with information security documents, government orders, notices, and guidelines

Experience documenting and maintaining systems running in AWS GovCloud (DoD preferred)

Ability to work independently to create and update Security Plans, Contingency Plans, and other security documents

Solid understanding in DoD Cyber Security policies and requirements

Preferred Qualifications :

Bachelor’s degree in Engineering, IT, Computer Science, or related field or equivalent

5 years’ experience in ISSM capacity

Experience supporting DoD (Navy preferred) enterprise application transition to the AWS GovCloud (up to IL 6) in a security capacity

AWS Certified Security certification

The likely salary range for this position is $127,500 - $172,500. This is not, however, a guarantee of compensation or salary.

Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours :

Travel Required : None

None

T elecommuting Options :

Onsite

Work Location : USA PA Mechanicsburg

USA PA Mechanicsburg

20 days ago
Related jobs
Promoted
SAIC
Work, Virginia

Demonstrated expertise providing innovative solutions in the engineering, integration, production, and modernization of Air Force hardware systems/sub-systems. Are you a strategic visionary in the realm of technology, eager to lead the charge in crafting cutting-edge solutions that exceed expectatio...

Promoted
ManTech
Newport News, Virginia

The individual will assist in coordinating the development of the AUX & CREW work package with the SUPSHIP Newport News RCOH Maintenance Planning Manager (MPM); this will include integration of all modernization, repairs and services work; areas of concern include CVN Engineering systems, Auxiliary ...

Promoted
Amentum
Newport News, Virginia

Note: US Citizenship is required to maintain an Active Secret Clearance. Install, monitor, and maintain sophisticated equipment and systems at both company and client locations. Conduct comprehensive tests, evaluations, and certifications for AN/BVY-1 systems, ensuring operational excellence. Valida...

Promoted
Chenega MIOS SBU
Newport News, Virginia

Chenega Analytic Business Solutions (CABS) provides federal agencies and commercial customers with trusted insights into Records and Information Management, Administrative Solutions, Information Technology, Engineering, and Training. The EMC is the one-stop shop for visual information services throu...

Promoted
Amentum
Newport News, Virginia

Note: US Citizenship is required to maintain an Active Secret Clearance. Installing, monitoring, and servicing equipment and systems at Company and client sites. Performing validations/verifications of BLQ-10 operational electronic systems. Developing technical/engineering data for Planned Maintenan...

Promoted
ManTech
Newport News, Virginia

Must have an active Secret Security Clearance and U. The applicant will be required to answer certain questions for export control purposes, and that information will be reviewed by compliance personnel to ensure compliance with federal law. At ManTech International, you’ll help protect our national...

Promoted
Northrop Grumman
Hampton, Virginia

Possess an active DoD Top Secret security clearance. Citizenship is required for all positions with a government clearance and certain other restricted positions. At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the w...

TASC Technical Services
Newport News, Virginia

The candidate must be able to obtain a Position of Public Trust Clearance - US Citizen or Permanent Resident (Green Card Holder), and must not have traveled outside the US for a combined total of 6 months or more in last 5 years. Adhere to USPS OIG policies by identifying and mitigating safety and s...

Parsons Corporation
Spring,VA,US

Define system security requirements in coordination with security stakeholders including system engineers, program managers, security control assessors, and authorizing officials. ISC)2 Certified Information System Security Professional (CISSP) or Certified Cloud Security Professional (CCSP) certifi...

Bravura Information Technology Systems, Inc.
Newport News, Virginia

Plans and supervises multiple projects involving complex information systems. Responsible for ensuring that technical solutions and schedules are implemented in a timely manner, performs enterprise-wide horizontal integration planning and interfaces to other functional systems. ...