Unknown Company

Information System Security Manager

silver spring, md • Posted 4 days ago
Onsite Contract Quality Management

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face.

About The Role

Peraton is seeking an Information System Security Manager in support of Peraton Labs' information assurance and information technology operations. This is a full-time on-site position working out of the Silver Spring, Maryland office.

Responsibilities

  • Lead and manage information assurance efforts and systems across numerous environments in Silver Spring, MD.
  • Perform Information System Security Manager (ISSM) roles and responsibilities as prescribed by the DAAG, JSIG, ICD-503, and other applicable regulations.
  • Create, manage, and maintain RMF Package documentation, submissions, and associated artifacts including A&A packages, ASA packages, SCRs, and more.
  • Prepare, deliver, and update all required documentation using the current approved templates, forms, regulations, and methods.
  • Meet continuous monitoring requirements for accredited information systems, including weekly audits, backups, AV updates, OS patching, vulnerability scanning, and other prescribed tasks.
  • Manage security vulnerabilities, implement timely remediation, monitor security logs for violations and anomalous events, and report information security concerns and problems when necessary.
  • Generate Plan of Actions & Milestones (POA&Ms) for each non-compliant control, manage all applicable POA&Ms throughout the information system lifecycle. Proper documentation shall be filed and updated as required.
  • Oversee the management and maintenance of Linux and Microsoft classified information systems, with the ability to assist in technical efforts when needed, including building systems, installing software, and troubleshooting information systems and network devices.
  • Apply security controls based on the DoD Security Technical Implementation Guidance and other customer requirements.
  • Work closely with key stakeholders to identify additional controls applicable to the system(s) to maintain a favorable security posture.
  • Assist in incident response, annual self-inspection, and inventory efforts.
  • Track the deployment of all applicable software and hardware to classified environments.
  • Provide, track, and report security requirements throughout the system life cycle of all information systems within the accreditation boundary.
  • Provide timely and detailed responses to user and customer requests.
  • Continuously maintain a thorough understanding of all relevant corporate policies, security control plans, system configurations, architecture, installed software, accounts, data flows, ports, protocols, and other relevant data for each information system.
  • Maintain required certifications for this role.

Qualifications

  • Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD.
  • CISSP or equivalent certification (DoD 8570 IAM Level III).
  • Experience with SAP and/or DCSA assessments and authorizations.
  • 5+ years experience with Authority to Operate (ATO) process, continuous monitoring, POA&Ms, Security Authorizations (SA), NIST 800-37, NIST 800-53 Rev4/Rev5, working with Information System Owners (ISO) and Program Managers (PM).
  • Experience with SCAP, STIGs, and other compliance tools.
  • Proven written and verbal communication skills, and the ability to work well with team members.
  • Active TS clearance with ability to obtain SCI.

Desired Skills/Qualifications

  • Preferred degree in a technical discipline such as computer science, cybersecurity, or information technology.
  • Experience with Ongoing Authorizations.
  • Experience with eMASS.
  • Experience with ACAS, Nessus, and/or other vulnerability scanners.
  • 3+ years of solid Linux system administration experience with specific focus on Ubuntu and RedHat distributions.
  • Experience with Linux shell scripting, including writing new scripts and troubleshooting existing codes.
  • In-depth knowledge of TCP/IP and networking concepts and a solid understanding of the well-known services including DHCP, DNS, SSH, TLS, IPSec, etc.

Details

Target Salary Range: $112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at

EEO

Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

#J-18808-Ljbffr
Back to Job Search