Unknown Company

Cybersecurity – Information System Security Manager

az • Posted 4 days ago
Onsite Full Time Quality Management

Responsibilities

  • Lead implementation and sustainment of DFARS/NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC) controls for systems handling Controlled Unclassified Information (CUI)
  • Develop and maintain security documentation (including System Security Plans and POA&Ms)
  • Coordinate audits and remediation with program stakeholders and assessors
  • Drive ongoing monitoring to protect CUI in accordance with DFARS and CMMC requirements
  • Lead a team of ISSOs performing cybersecurity governance work on CUI, DFARS, and CMMC systems
  • Perform security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards
  • Oversee configuration management of assigned systems; auditing systems to ensure security posture integrity
  • Conduct risk assessments and investigations, execute appropriate risk mitigations, and oversee incident response activities
  • Conduct periodic hardware/software inventory assessments
  • Serve as organization spokesperson on advanced projects and programs
  • Act as advisor to management and customers on advanced technical research studies
  • Interface with the appropriate government customers, suppliers, and company personnel to implement protective mechanisms and ensure understanding of and compliance with cybersecurity requirements

Requirements

  • Currently hold certification in good standing to satisfy IAM Level III (CISSP, GSLC, or CISM)
  • 5+ years of experience with cyber security policies and implementation of Risk Management Framework (RMF)
  • 3+ years of experience implementing and sustaining Defense Federal Acquisition Regulation Supplement (DFARS) /National Institute of Standards and Technology (NIST) SP 800-171 controls and mapping to Cybersecurity Maturity Model Certification (CMMC) requirements
  • 5+ years of experience as an information system security officer (ISSO) or information system security manager (ISSM)
  • 5+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
  • 5+ years of experience assessing and documenting test or analysis data to show cyber security compliance

#J-18808-Ljbffr
Back to Job Search