Jobs · Information Technology · Colorado

Information Systems Security Manager

SAIC · Colorado Springs, CO · 3 wk ago
Information Technology$120k–$160k/yrFull-time

SAIC's Horizon 2 contract is seeking an energized and professional Cyber GRC Analyst Principal / Information Systems Security Manager (ISSM) to support secure operating facilities in Colorado Springs, CO. The role supports the US Space Force Space Systems Command's Program Executive Offices overseeing Space Domain Awareness, Combat Power, and Battle Management Command, Control, and Communications portfolios.

About the role

You will manage all facets of SAIC’s Information Protection Program at the Colorado Springs location, responsible for accreditation, compliance, continuous monitoring, and operational security of classified information systems across applicable classification levels. You will provide oversight, guidance, and technical support on IT and information system security issues affecting the mission, implementing common information system security practices, policies, and standards. This role offers mentorship opportunities and may require sporadic off-hours support in a dynamic, customer-centric environment.

Responsibilities

  • Lead activities required to obtain and maintain Authority to Operate (ATO) approvals for classified information systems.
  • Ensure compliance with applicable Department of Defense (DoD) and Risk Management Framework (RMF) requirements, including CNSSI guidance, NIST security controls directives, and other cybersecurity policies.
  • Perform vulnerability/risk assessments to support authorization and accreditation of classified systems.
  • Develop, maintain, and update RMF documentation, including System Security Plans (SSP), System Assessment Plans (SAP), Risk Assessment Reports (RAR), Security Control Traceability Matrices (SCTM), Plans of Action and Milestones (POA&M), and Continuous Monitoring Plans (ConMon).
  • Coordinate with program security officers and/or cognizant security officials on approval of External Information Systems (e.g., guest systems, interconnected systems).
  • Conduct periodic reviews and evaluations of required IS policies, standards, and procedures.
  • Coordinate Information System Security Assessments, tests, and reviews.
  • Conduct due diligence and process hardware and software requests.
  • Provide configuration management for information system security software, hardware, and firmware.
  • Coordinate Incident Response (IR) activities, security event reporting, and corrective actions associated with cybersecurity incidents affecting authorized systems.

Requirements

  • Bachelor’s degree (preferably in Information Security or related field); 9+ years of experience in cybersecurity, information assurance, system administration, or equivalent (7 years may be substituted with a Master’s degree).
  • Experience with the Risk Management Framework, National Institute of Standards and Technology, Committee on National Security Systems cybersecurity requirements, and risk management methodologies.
  • Program Security responsibilities, including OPSEC, Program Protection, Personnel Security clearances, Security Training and Education, and Classification management.
  • Experience working in a SAP and/or SCI environment.
  • Ability to control, label, virus scan, and appropriately transfer data between information systems at varying classification levels.
  • In-scope security background investigation (T5 or SSBI), adjudicated for SCI eligibility, and enrolled in the Continuous Evaluation program (if applicable).
  • Willingness to be nominated for access to Sensitive Compartment Information and Special Access Programs and consent to a Polygraph examination.
  • Certification(s) meeting or exceeding DoD 8140 IAT Level II requirements (e.g., CompTIA Security+, CISSP).

Skills

  • Master’s degree in cybersecurity, Information Security, or related security studies (preferred).
  • Knowledge and experience using DoD tools for vulnerability assessments and compliance reporting (eMASS, XACTA, ACAS, STIGs, Nessus, SCAP, Splunk, etc.).
  • Familiarity with JSIG, ICD 503, NIST RMF, NIST SP 800-53/53A, CNSSI 1253, and the Assessment & Authorization (A&A) process.
  • Experience with Incident Response and Disaster Recovery Procedures.
  • Experience creating/updating plans, processes, and procedures for system and data security requirements, including certification artifacts.
  • Familiarity with virtualized hosting, such as VMware.
  • Experience conducting security audits/system assessments of information systems.
  • Extensive training or experience with Windows-based Information Systems and working knowledge of Linux operating systems.
  • Understanding of Contractor Program Security Officer (CPSO) functions, responsibilities, and disciplines (e.g., PERSEC, PHYSEC, facility alarm operations, Security Training and Education, visitor access requests).
  • Understanding of DD254s to support government contracts.

Pay

Target salary range: $120,001 - $160,000. The estimate represents the typical salary range based on experience and other factors.

Schedule

  • Full-Time
  • Day Shift
  • Travel: Yes - 10% of the time

Clearance Level: Must be able to obtain TS/SCI with Polygraph. Minimum clearance required: TS/SCI.

Similar jobs