Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM) Location: Ramstein AB, Germany Security Clearance Level: Secret Duties/Responsibilities: The Contractor shall maintain regulatory requirements of cyber security and give guidance/assistance/ solutions regarding overall cyber readiness. Also, the Contractor shall provide all personnel, knowledge, skills, abilities, staff support and other related resources necessary to perform the RMF services.In supporting the Government in maintaining Assessments & Authorization (A&A) packages, ISSMs shall, at a minimum: Serve as the primary cyber security point of contact for systems, ensuring compliance with security policies, procedures, and regulations, and providing timely dissemination of threats, risk, and authorization status to stakeholders.
Perform all necessary procedures to ensure the safety of information systems assets, including overseeing the accreditation and certification ofsystems in accordance with DoW, Intelligence Community, and agency-specific requirements.
Prepare all required documentation associated with the submission of A&A packages IAW all Federal, DoW, AF, and local RMF policies, regulations, and standards.
Prepare and submit System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and risk assessment documents, and collaborate with Authorizing Officials (AOs) to achieve and maintain Authorization to Operate (ATO) status.
Develop and recommend policies and procedures to ensure information systems reliability, accessibility, and security, and conduct systems security evaluations, audits, and reviews to identify vulnerabilities and risks.
Recommend and implement programs to educate systems, network, and data users on systems security policies and procedures, and participate in network and systems design to ensure implementation of appropriate security policies.
Support, monitor, test, and troubleshoot hardware and software cyber problems pertaining to the enclave.
Develop system-wide information security requirements based upon the analysis of user, policy, regulatory, and resource demands for complex network and enclave systems.
Ensure the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services. Perform ISSM duties as outlined in AFMAN 17-01 and DoWI 8510.01 for assigned systems/applications.
Maintain familiarity with relevant DOW/NIST RMF publications, including NIST 800-53, 800-60, 800-37, DOWI 8540.01 CDS Policy, and DOW Directive 5144.02.
Minimum/General Experience: This position requires a minimum of 10 years experience, of which at least eight years must be specialized experience in defining computer security requirements for high level applications, evaluation of approved security product capabilities and resolution of computer security problems. Extensive knowledge and proficiency with the Security Technical Implementation Guide (STIG) implementation and automation tools such as SCAP, STIG Viewer, eMASSter which are often leveraged for automation.
Minimum Education: A Bachelors degree in computer science/systems, information systems/technology, engineering/engineering technology, software engineering/programming, management, natural sciences, social sciences, mathematics or business/finance. Education and experience requirements may be substituted with: A Masters Degree (in subjects described above) and eight years general experience of which at least six years must be specialized experience. No degree and thirteen years of general experience of which at least eleven years must be specialized experience. Certifications: DoW 8570.01M Information Assurance Manager (IAM) Level III Certification Additional Requirements: Candidate must meet TESA requirements as follows: #DefenseOCONUS
|