Senior Specialist, Cyber Intelligence
L3Harris Technologies is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers’ mission and quest for professional growth. We provide an inclusive, engaging environment designed to empower employees and promote work-life success. Fundamental to our culture is an unwavering focus on values, dedication to our communities, and commitment to excellence in everything we do.
About the role
This Security position assumes the responsibilities associated with the role of Information Systems Security Manager (ISSM). The ISSM will oversee the development, implementation, evaluation, and the certification and accreditation of classified information systems. The role involves interfacing with management, maintaining liaison with US Government information assurance and oversight agencies, and interpreting government and company policy to ensure compliance with Cognizant Security Agency (CSA) requirements for classified information systems and/or networks.
The ISSM will provide information security guidance to program, engineering management, and end users, including recommendations on process tailoring. The position requires establishing and maintaining required training and information security compliance deliverables, publicizing and submitting government Risk Management Framework (RMF) compliant plans, procedures, and instructions, and sustaining compliance throughout system and program life cycles.
The ISSM will report directly to the site Facility Security Officer (FSO) and may assist security management with facility accreditation packages, site-specific security plans, physical security requirements, and other assignments as needed. The role may also involve maintaining and accounting for electronic communication equipment and additional document control.
Responsibilities
- Develop, maintain, and oversee the system security program and policies for assigned facility or area of responsibility.
- Ensure compliance with current government security policies, concepts, and measures when working with stakeholders to design and develop new systems.
- Develop and implement an effective information system security education, training, and awareness program.
- Manage system Control Change Board (CCB) meetings.
- Maintain a working knowledge of system functions, security policies, technical security safeguards, and operational security measures.
- Identify and mitigate system vulnerabilities based on risk and impact.
- Develop, maintain, and update Plans of Actions and Milestones (POA&M) to identify system weaknesses, mitigation, and timelines for corrective actions.
- Certify to government Authorizing Officials (AOs) that security plan requirements and procedures comply with contractually imposed regulations (NISPOM, NIST SP 800-53, DAAPM, JSIG, etc.).
- Ensure systems are operated and maintained in accordance with the Security Plan and government-issued Authorization to Operate (ATO).
- Ensure audit records are collected and analyzed.
- Obtain and maintain NISP Enterprise Mission Assurance Support Service (eMASS) and/or applicable government system access to manage security authorizations.
- Manage, maintain, and execute the continuous monitoring strategy.
- Conduct periodic assessments of systems and ensure corrective actions are taken for all vulnerabilities and findings.
Requirements
- Bachelor’s degree with 6 years of prior ISSM experience, or Graduate Degree with 4 years of prior ISSM experience, or in lieu of a degree, a minimum of 10 years of prior related ISSM experience.
- DOD 8570.1 Certified (Level II or higher); Security+ or Certified Information Systems Security Professional (CISSP) or other applicable 8570.1 certifications required.
Skills
- Experience with classified processing environments of varying complexity.
- Experience with government compliance, regulations, and standards (NISPOM, DAAPM, RMF, JSIG, NIST 800-53).
- Experience with security requirements, clearances, and procedures.
- Experience with applicable network, systems, hardware, and software programs.
- Experience with various communication protocols.
- Strong decision-making and analytical skills.
Schedule
4/10: Employees work 10-hour days, 4 days a week.