Information Systems Security Manager (ISSM)
General Dynamics Mission Systems engineers a diverse portfolio of high technology solutions, products, and services that enable customers to successfully execute missions across all domains of operation.
Basic Qualifications
- Bachelor's degree in Engineering, or a related Science or Mathematics field, plus a minimum of 5 years of relevant experience; or Master's degree plus a minimum of 3 years of relevant experience.
- Department of Defense TS/SCI with Polygraph clearance is required at time of hire.
- Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information.
- U.S. citizenship is required.
Responsibilities
As an Information Systems Security Manager (ISSM) supporting Information Assurance at General Dynamics Mission Systems, you will:
- Lead the cybersecurity, assessment and authorization (A&A), and compliance activities for classified information systems.
- Serve as the primary security representative for the program, providing security leadership across the system life cycle and coordinating directly with program leadership, system stakeholders, internal security organizations, and government customers.
- Oversee the implementation, operation, maintenance, and continuous monitoring of system security controls; manage security documentation; assess and mitigate cybersecurity risks; and ensure systems remain compliant with applicable government, customer, and company requirements.
- Lead security audits, incident-response activities, security training, and customer engagements while working closely with cross-functional engineering, IT, configuration management, and program teams.
- Serve as the ISSM responsible for oversight of information-system security activities for the Program.
- Lead and support A&A activities, including the development, maintenance, review, and submission of required security documentation, such as System Security Plans (SSPs), Security Assessment Reports (SARs), Security Controls Traceability Matrices (SCTMs), and Plans of Action and Milestones (POA&Ms).
- Act as a primary security interface with government customers, program leadership, engineers, system administrators, and internal security stakeholders.
- Ensure security controls are implemented, assessed, documented, and maintained in accordance with applicable customer, government, and internal security requirements.
- Perform and document weekly system audit reviews, media reviews, and hardware/software configuration-management reviews.
- Execute or oversee security testing and evaluation activities to verify the effective implementation of required security controls.
- Support the identification, assessment, tracking, and mitigation of vulnerabilities and risks throughout the system life cycle.
- Manage POA&M development and status, ensuring corrective actions are documented, prioritized, tracked, and communicated to appropriate stakeholders.
- Conduct and coordinate information assurance and security education training for system users, emphasizing appropriate risk-mitigation practices and user responsibilities.
- Lead or support incident-response, reporting, containment, cleanup, and recovery actions in accordance with company and customer direction.
- Ensure systems are operated, maintained, modified, and disposed of in accordance with approved SSPs and internal security policies and procedures.
- Support customer assessments, inspections, technical exchanges, and recurring security-status discussions.
- Provide timely security-status reporting to program leadership and customers, including risks, vulnerabilities, compliance posture, and corrective-action progress.
Requirements
- Experience developing and maintaining System Security Plans (SSPs) and supporting Assessment and Authorization (A&A) documentation, including Security Assessment Reports (SARs), Security Controls Traceability Matrices (SCTMs), and Plans of Action and Milestones (POA&Ms).
- Experience with system security assessment and hardening tools, including SCAP Compliance Checker, STIG Viewer, ACAS/Nessus, and similar tools.
- Experience conducting security control assessments, vulnerability reviews, security audits, and compliance monitoring.
- Training and proficiency in Assured File Transfer (AFT) procedures.
- Ability to work independently, prioritize competing requirements, and lead security activities with minimal supervision.
- DoD 8570/8140 certification meeting IAM Level II requirements, such as CISSP, CGRC, or equivalent.
- Comprehensive knowledge of the NISPOM, NIST SP 800-53, and NIST SP 800-171 requirements.
- Experience serving as an ISSM or leading information-system security activities for classified programs.
- Outstanding written, verbal, and customer-facing communication skills.
- Demonstrated ability to lead and collaborate with cross-functional teams throughout the system life cycle.
- Ability to effectively engage government customers, communicate system security posture, and support customer reviews, assessments, and authorization decisions.
What You’ll Experience
- Technologies that are not just top-notch—they are often top-secret.
- A team of bold thinkers committed to exploring what is next.
- Opportunities to gain new knowledge as it is discovered.
- A highly visible security leadership role supporting a critical SAP/SCI program and customer mission.
Benefits
We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded.
Pay
Target salary range: USD $118,519.00/Yr. - USD $131,482.00/Yr. This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary.