Information Systems Security Manager (ISSM)
Kratos Defense and Security Solutions · Glen Burnie, MD · 1 wk ago
Information TechnologyFull-time
About the role
We are seeking an experienced and highly motivated Information Systems Security Manager (ISSM) to lead the security management and compliance activities for information systems supporting our organization. The ISSM will be responsible for ensuring systems are securely designed, implemented, operated, and maintained in accordance with organizational security policies, regulatory requirements, and applicable cybersecurity frameworks.
Responsibilities
- Implement the risk management framework for classified systems, typically following the Defense Counterintelligence Security Agency (DCSA), DAAG, or JSIG process and supporting communications with cognizant security authorities.
- Serve as the primary point of contact for classified systems.
- Produce and maintain Body of Evidence (BoE) documentation to include risk assessments, System Security Plans (SSPs), and Plans of Action and Milestones (POA&Ms).
- Maintain the day-to-day security posture and continuous monitoring for all systems, including patching and updates.
- Assist Information Security team in unclassified security operations, including continuous monitoring, incident response, and vulnerability management.
- Assist Information Technology team in unclassified services functions.
- Ensure all users have the requisite security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the information systems.
- Ensure adherence to information system security policies and procedures.
- Coordinate vulnerability management, security assessments, penetration testing, and remediation activities.
- Perform oversight and provide guidance for media sanitization and destruction.
- Confirm domain/local policies are configured to meet regulatory requirements.
- Assess changes to the system/operational needs that could affect its accreditation.
- Serve as a voting/veto member of the Configuration Control Board (CCB) for all systems.
- Assist with coordination between Kratos and Defense and Government authorities regarding system security posture requirements.
- Participate in information system security inspections, tests, and reviews.
- Maintain a working knowledge of system functions, security policies, technical security safeguards, and operational security measures.
- Schedule periodic testing to evaluate the security posture of information systems.
- Develop an effective information system security education, training, and awareness program.
- Interface with internal and external customers and auditors, program managers, IT, security staff, etc.
- Support security incident response, investigations, and corrective actions.
- Serve as a member of the Configuration Control Board as necessary.
- Coordinate Information System Security Officers (ISSOs) and System Administrators (SysAdmins).
- Perform other duties as assigned.
Requirements
- U.S. Citizenship required.
- Thorough understanding of US Government (specifically DoD) IS security policies.
- Strong communication skills, critical thinking, and problem-solving skills; self-motivated with the ability to effectively prioritize multiple projects; ability to work in a team environment and deal effectively with changing project priorities.
- Ability to manage time, make sound decisions, take independent action, analyze problems, and provide focused solutions.
- High degree of attention to detail.
- Must have an active in-scope TOP SECRET clearance and be able to obtain and maintain access to Sensitive Compartmented Information (SCI) and/or any necessary Special Access Programs (SAP).
- DoD 8140/DoD 8570 approved (IAM Level 2-3) certification required within 6 months of hire.
Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent experience may be considered.
- 5+ years of experience in Information Technology (IT) in a classified environment, or 3+ years of experience as an ISSM/ISSO in government/industrial security or an intelligence career field.
- Strong understanding of identity and access management, endpoint security, network security, logging/monitoring, and incident response.
- Experience administering Windows and Linux operating systems, experience with large-scale server systems, thin client architecture, system virtualization, and other related peripherals.
- Strong understanding of cybersecurity frameworks such as NIST CSF, NIST SP 800-53, RMF, ISO 27001, CIS Controls, or equivalent.
Work Environment / Physical Requirements
This position involves work in an office and laboratory environment and could require the use of personal protective equipment (PPE) including:
- Safety glasses
- Hearing protection (varied based on tasks)
- Shoe covers
Physical Demands:
- Perform work using a computer for extended periods of time.
- Sit or stand for extended periods of time without leaving the work area.
- Climb ladders and stairs.
- Walk for considerable distances.
- Lift objects up to 50 pounds.
- Reach for objects above head or below waist.
- Stoop or crouch by bending at the waist or by bending legs.
- Withstand exposure to low and high temperature levels that result in possible body discomfort.
Benefits
- Medical, Dental & Vision Insurance Coverage
- Life/ADD & Short/Long Term Disability Insurance
- 401(k) Savings Plan
- Employee Stock Purchase Plan (ESPP)
- Paid Time-Off (PTO)
- Holidays
- Education Reimbursement