Jobs · Information Technology · Maryland

Information Systems Security Manager (ISSM)

Astrion · Columbia, MD · 1 mo ago
Information Technology$137k–$205k/yrFull-time

Astrion has an exciting opportunity for an experienced Information Systems Security Manager to assist in establishing, implementing, and maintaining the security program for classified information systems in Columbia, MD. This is a full-time role requiring the ability to obtain TS/SCI clearance and a CAP, CISSM, or CISSP certification. Travel is less than 5%.

Responsibilities

  • Develop, implement, and oversee the organization's classified Information System Security Program (ISSP) in compliance with NISPOM, DAAG, RMF, and CSA guidance.
  • Establish policies, procedures, and technical standards for classified information systems.
  • Coordinate preparation of System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action & Milestones (POA&Ms), and Continuous Monitoring Strategy.
  • Support Authorization to Operate (ATO) and reauthorization activities; maintain authorization packages in eMASS.
  • Verify management, operational, and technical controls remain effective and monitor security control compliance throughout the system lifecycle.
  • Establish and manage a Continuous Monitoring (ConMon) program, including review of vulnerability scans, audit logs, security alerts, patch compliance, and configuration management.
  • Ensure deficiencies are documented and corrected; conduct self-inspections per 32 CFR 117.18.
  • Ensure incidents are investigated and reported to DCSA and appropriate government agencies; coordinate incident response activities and maintain incident documentation.
  • Approve and monitor configuration changes; ensure security impact analyses are completed and secure baseline configurations are verified.
  • Maintain system inventories and approve user access procedures; enforce least privilege and review privileged accounts.
  • Ensure user accounts are disabled when no longer required.
  • Partner with the IT team to coordinate POA&M remediation, review and approve configuration changes, evaluate requested new software, and drive collaboration between ISS and IT teams.
  • Ensure users receive initial and annual cybersecurity training; promote insider threat awareness within the IS security program.
  • Coordinate with the Insider Threat Program and Facility Security Officer (FSO).
  • Interface with Defense Counterintelligence and Security Agency (DCSA) and other government agencies.

Requirements

  • Bachelor’s degree with 10-12 years of experience.
  • Minimum of 5 years of experience in a leading or managerial role.
  • Experience supporting U.S. Government clients.
  • Ability to apply knowledge of IA policy, procedures, and workforce structure to develop, implement, and maintain a secure network environment.
  • CAP, CISM, or CISSP certification required.
  • U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility.

Preferred Qualifications

  • Proficiency with Secure Internet Protocol Network establishment and maintenance.
  • Proficiency with compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
  • Strong background in certification and accreditation process of information systems; ability to write, review, and coordinate systems security plans.

Pay

$137K - $205K

Similar jobs