Cyber Security Information System Security Manager (ISSM) - Onsite
About the role
Join BAE Systems and work on the world’s most advanced electronics—from detecting threats for F-35 pilots to illuminating the night for soldiers. Spanning air, land, sea, and space, we develop the technology of tomorrow, delivered today. As part of our team, you’ll have the opportunity to create and develop advanced technology capabilities in areas such as advanced electronics, autonomy, cyber, electronic warfare, and sensors and processing.
In this Cybersecurity, ISSM role, you will support and protect information systems critical to national security. You’ll collaborate with seasoned professionals in a fast-paced, team-based environment with a training and development plan designed to grow your skills. This role is full-time and onsite at a BAE Systems facility due to the need for consistent, in-person collaboration.
Responsibilities
- Support adherence to a rigorous Risk Management Framework (RMF) compliance program as stipulated by NISPOM/DAAPM, JSIG, ICD 503, STIGs, and associated NIST publications.
- Obtain and maintain Authority to Operate (ATO) approvals for various systems by adhering to the RMF process.
- Support cybersecurity efforts throughout the RMF process, including development and management of System Security documentation, Plans of Action and Milestones (POA&Ms), assessing and auditing systems security controls, and continuous monitoring of controls.
- Provide oversight for all classified systems compliance and ensure execution of a strong self-inspection program.
- Ensure all security certification and accreditation documents for classified systems are up-to-date.
- Ensure continuous monitoring (e.g., weekly, monthly) in accordance with cognizant security authority requirements.
- Coordinate security-related activities with information security architects, senior information security officers, information system owners, common control providers, and information system security officers.
- Develop core documentation including System Security Plans, Standard Operating Procedures, Plan of Actions and Milestones, Remediation Plans, and Configuration Management Plans.
- Review and create mitigation reports from compliance and vulnerability scanning tools (Nessus, SCAP, ACAS, SCC).
- Audit and certify compliance of various systems (Windows, Linux, Network Devices, and peripherals).
- Develop and deliver IA-related briefings and training material.
Requirements
- Active Top Secret Clearance and IAM Level II certification commensurate with DoD 8570.1M requirements.
- ISSM or relevant cybersecurity experience.
- High level of personal motivation and initiative to learn and adapt in an ever-changing security environment.
- Customer-focused with excellent communication skills and ability to work with limited supervision.
- Strong organizational skills and ability to interface with IA team members, other security disciplines, program personnel, and government security representatives.
- Experience with compliance and vulnerability scanning tools (Nessus, SCAP, ACAS, SCC).
- Experience with auditing and certifying compliance of various systems (Windows, Linux, Network Devices, and peripherals).
Preferred Qualifications
- Experience running and maintaining an entire information assurance program for complex efforts or areas.
- Working knowledge of system functions, security policies, technical security safeguards, and operational security measures.
- Ability to translate operational requirements into technical requirements and architectures to meet program objectives.
- Experience conducting all aspects of a self-inspection.
- Experience with periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system, and integrity scans to determine compliance.
- Prepared incident reports of analysis methodology and results.
- Knowledge of new and emerging information technology (IT) and cybersecurity technologies.
- Employ best practices when implementing security controls within an information system, including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques.
- Ability to function as an integral part of the development team, including designing and developing organizational information systems or upgrading legacy systems.
Pay
Full-Time Salary Range: $118,095 - $200,762. Individual salaries are determined by a variety of factors including business considerations, local market conditions, and internal equity, as well as candidate qualifications such as skills, education, and experience.
Benefits
- Health, dental, and vision insurance.
- Health savings accounts.
- 401(k) savings plan.
- Disability coverage and life and accident insurance.
- Employee assistance program and legal plan.
- Perks including discounts on home, auto, and pet insurance.
- Paid time off, paid holidays, and other types of leave, including paid parental, military, bereavement, and applicable federal and state sick leave.
- Company recognition program with monetary or non-monetary awards.
- Other incentives based on position level and job specifics.
Schedule
This role is full-time and onsite at a BAE Systems facility 100% of the time due to the need for consistent, in-person collaboration.