Jobs · Information Technology · South Carolina

Information System Security Manager (ISSM)

KBR Careers · Charleston, SC · Today
Information TechnologyFull-time

Responsibilities

  • Deliver documentation to include: Executive level briefings, Assessments, Self-Assessments, RMF packages, and supporting RMF documentation
  • Review Cybersecurity tool reports, ACAS, HBSS, for the purposes of reporting and compliance
  • Software Certification package development
  • Work directly with the TRMC SISO on all TRMC RMF packages and ATO Status updates
  • Support security engineering projects and solution delivery
  • Lead security audit and compliance activities for each system responsible for
  • Responsible for auditing all artifacts provided in each RMF package to determine system readiness for ATO packet submissions
  • Provide recommendations to the SISO, PM, and AO regarding remediation and mitigation of identified vulnerabilities on test reports and plan of action and milestones (POA&Ms)
  • Monitor system status updates and report to senior leadership
  • Includes monthly executive reports, vulnerability reports, JFHQ DODIN reporting and briefing
  • Monthly executive briefing to SISO, PM on security metrics
  • Interface with PMs and SISO on issues needing input/concurrence
  • Draft and present RMF deliverables to senior leadership
  • Attending Executive Program Reviews as the ISSM
  • Work with outside agencies on Memorandums of Understanding / Interconnection Service Agreements, and other senior level agreements etc.
  • Work directly with a distributed team to reduce travel

Requirements

  • TS/SCI required
  • A minimum of 2 years of Information Technology Information Assurance, or Cyber Security engineering experience
  • A minimum of 2 years of experience in conducting security assessments by reviewing security controls with the ISSO/ISSM and guide programs through RMF process
  • Bachelor’s Degree in Engineering, Computer Science, or 8 years IT field experience in lieu of degree; Master’s Degree preferred
  • Proven expertise with assessing security controls in accordance with NIST Special Publications (i.e.: NIST 800 Series)
  • Proven in-depth knowledge of Cybersecurity principles technologies, and processes
  • Experience with NIST 800-53, Security Development
  • Familiarity with performing assessments for Unclassified and Classified environments
  • Ability to adapt to process changes
  • Ability to interface with senior leadership
  • Ability to support high visibility or high priority projects
  • Possession of excellent oral and written communication skills

Qualifications

  • Proven expertise with assessing security controls in accordance with NIST Special Publications (i.e.: NIST 800 Series)
  • Proven in-depth knowledge of Cybersecurity principles technologies, and processes
  • Experience with NIST 800-53, Security Development
  • Familiarity with performing assessments for Unclassified and Classified environments
  • Ability to adapt to process changes
  • Ability to interface with senior leadership
  • Ability to support high visibility or high priority projects
  • Possession of excellent oral and written communication skills

Similar jobs