Information Systems Security Manager / Information Assurance (IA) Team

Leidos Inc
Arlington, VA, United States
$122.2K-$220.9K a year
Full-time

Description

The Information System Security Manger (ISSM) / Information Assurance (IA) Team Manager is the primary IA decision maker and responsible for the management and technical administration of the Information System (IS) in accordance with internal and external security requirements.

The ISSM will oversee day-to-day information system security operations, resolve complex problems, and develop innovative solution to meet changing security requirements.

The ISSM / IA Tm Mgr. will serve as the Subject Matter Expert (SME) within the Information Assurance technical domain. Ability to work independently as well as with a team of analysts trained in operations research, mathematics, and other skills.

The ideal candidate will be adaptable to diverse office situations, procedures and demands.

Primary Responsibilities

  • Personnel management for their team.
  • Training / Mentoring, education, PTO planning / development / submittal, remote work requests, end of day report requirements, quarterly check-ins, yearly reviews, and timesheet verifications / approvals.
  • Continuous upkeep, monitoring, analysis, and response to Information System, network and security events.
  • Documents compliance activities in accordance with the governing authority approved authorization package.
  • Develop procedures and documentation to ensure compliance with Configuration Management (CM) for security relevant IS software, hardware, and firmware.
  • Ensures systems are operated, maintained, and disposed of in accordance the governing authority approved authorization package and customer directives.
  • Ensures records are maintained for workstations, servers, software, routers, firewalls, network switches, and other relevant hardware / equipment throughout the information system's life cycle.
  • Evaluates proposed changes or additions to the information system and advises senior site leadership of the security relevance.
  • Lead / conduct security IS education and training.
  • Mentor other engineers in the art of cybersecurity and secure software development practices.
  • Participates in internal / external security audits / inspections; performs risk assessments and Continuous Monitoring.
  • Lead investigations of computer security violations and incidents, reporting as necessary to both the Facility Security and Senior Program Managers.
  • Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered.
  • Working with the Facility Security Officer (FSO) develop, implements and manage a formal Information Security / Information Systems Security Program.
  • Develop, implement and enforce Information Security Policies and Procedures.
  • Author, review and update IS Authorization documentation (Body of Evidence) to support IS Assessment and Authorization activities.

Basic Qualifications

Bachelor's degree and 12 - 15 years related experience in Information Systems, Computer Science or related field or a Master's with 6 - 10 years of related experience.

Additional relevant experience, training, and / or certification may be considered in lieu of degree.

  • Detailed understanding of the Risk Management Framework (RMF), NIST, ICD, and CNSS standards.
  • Familiarity with network technologies (LAN & WAN) and best practices within a classified environment to include crypto and key management.
  • Working knowledge with Microsoft Windows operating systems (workstation & server), Linux, and system virtualization (multiple hypervisors) in a secure network environment.
  • Experience with compliance scanning tools (e.g. SCAP) and vulnerability scanning tools (e.g. ACAS).
  • Hands on experience with DISA Security Technical Implementation Guide (STIG) implementation and management.
  • Must be able to work in a constantly changing regulatory environment with short-, mid-, and long-term timelines for remediating any non-compliance.
  • Must be able to work well within a team environment and able to adapt quickly to change.
  • Good writing and verbal presentation skills.
  • Experience with eMass.
  • Active TS / SCI clearance.
  • CISSP Certification must be obtained within 6 months of hire.

Preferred Qualifications

  • Past or current ISSM / ISSO experience.
  • DoD IS knowledge and experience.
  • Detailed understanding of Risk Management Framework (RMF).
  • Security hardening scripting / automation experience.
  • Microsoft OS Certification (MCSE Win 7 or other).
  • Linux certification (RHCSA, CompTIA Linux, LCFS / LCFE, etc.).
  • Understanding of Sensitive Compartmented Information Facility (SCIF) standards.
  • Strong knowledge of secure coding practices and vulnerability / quality scanning tools (e.g., Fortify, SonarQube).
  • Knowledge of agile development processes and DevOps tools such as Jira, Bitbucket, Confluence.
  • Knowledge of continuous integration, delivery, and automated test tools such as Jenkins, SonarQube, JUnit, Cucumber, Selenium, JMeter.
  • Experience developing and delivering modern software, including micro services, containers, and hybrid cloud architectures.
  • Additional desired certifications include CCNA, CCSP, MCSE, and / or SANS GIAC.

Experience with Windows and Linux.

Original Posting Date :

2024-08-28

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range :

Pay Range $122,200.00 - $220,900.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

2 days ago
Related jobs
Promoted
iNovex Information Systems
McLean, Virginia

The Product Manager will research software systems, present ideas for system improvements, and conduct impact analysis for software changes to provide high-value features to our customer. This Product Manager will have applied experience working in a dynamic Agile/Scrum environment with shifting pri...

Promoted
Applied Research Associates (ARA)
Arlington, Virginia

What you’ll do as an Information Systems Security Manager (ISSM). You will conduct recurring Cybersecurity reviews on information systems in accordance with DoD Manuals, JSIG, NIST Special Publications, customer directives, and company policies as applicable. Information Systems Security Manager (IS...

Promoted
Tria Federal
Arlington, Virginia

Information Security Compliance Specialist who will conduct Security Assessment and Authorization (A&A) support for USSS IT systems. Information Security Compliance Specialist. Tria Federal (Tria) is the premier middle-market IT and Advisory services provider delivering digital transformation soluti...

Akima
Alexandria, Virginia

Cloud Lake Technology is looking for a Computer and Information system manager to work in Alexandria, Virginia. To join our team of outstanding professionals, apply today!. May provide consultation on complex projects and is considered to be the top-level contributor/specialist. Demonstrated experie...

Mantis Security Corporation
Reston, Virginia

DoD 8570 compliance with IASAE Level 3 is required • Three (3) years of experience in scripting languages, Linux/RedHat, and/or Networking Appliances Information Systems Security Engineering Professional (ISSEP) and CISSP Certifications are required • Active TS/SCI security clearance wit...

Systems Planning and Analysis
Arlington, Virginia

Identify and mitigate security incidents along with developing response measures for Government leadership, and serve as the Program Security Officer (PSO) and SME for special security and SAP support in a SCIF and/or SAP facility (SAPF). Monitor access to SCIF/SAPF and compliance with physical and ...

Hilton
McLean, Virginia

Experience with these Hospitality related applications and systems: Property Management Systems, PointOfSalesSystems(F&B,spa,parking,etc. Information Technology (IT) Manager- Hilton Los Angeles Airport(. Information Technology (IT) Manager. Information Technology issues, products and services in adh...

Intelligent Waves LLC
Fort Belvoir, Virginia

Security Clearance: This Information Assurance Analyst must have a DoD Top Secret SCI security clearance. Intelligent Waves has an immediate need for an Information Assurance Analyst to support our mission critical work in support of our government customer at Ft. Location: This Information Assuranc...

AttainIT Technologies
McLean, Virginia

AttainIT is seeking a motivated, career and customer-oriented Information System Security Engineer to join our team. You will perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established cybersecurity standards and ...

Conduent Business Services
VA, United States

The NIST Security Analyst is a member of the CISO Regulatory & Compliance Team and will assist in the performance of internal audits, ensuring they comply with applicable Conduent and NIST security standards, regulations, and policies. Knowledge and understanding of security controls across all secu...