The Information System Security Manager (ISSM) position is responsible for the implementation of Risk Management Framework (RMF) activities required to support Information System (IS) assessment and authorization activities. This position reports directly to the Chief of Security, Special Projects.
The successful candidate must possess sufficient understanding, knowledge, and experience to implement, enforce, and ensure compliance with RMF policies and procedures. This position will work closely with NAVSEA, Government vendors, EB departments, and sub-contractor counterparts.
This position requires a balance of technical knowledge and experience, with strong analytical, documentation, and reporting skills. Responsibilities include:
- Supporting the development and maintenance of organization-wide Cybersecurity policies, procedures, templates, and associated education, awareness, and training products; organization-wide Risk Management Strategy, to include the Risk Assessment Report; and the organization-wide Continuous Monitoring (ConMon) Strategy
- Developing and/or assessing system specific policies, procedures, templates, training, and other documentation to ensure alignment with the requirements of organization-wide policies and procedures
- Coordinating, conducting, and documenting system specific ConMon activities; identifying, managing, and tracking system specific risks, to include vulnerabilities and other areas of non-compliance; and providing guidance on risk mitigation and remediation considerations and strategies
- Processing POA&M Forms, Configuration Management Plans(CM), and Security Impact Assessments
- Verifying Operating System (OS) and network device configurations, and ensure compliance with configuration standards and other technical requirements
- Overseeing and supporting RMF activities performed by ISSOs
- Leading assessment and authorization efforts for systems; developing and maintaining packages to include POA&Ms
- Interfacing with various internal and external EB stakeholders
- Providing guidance and support on security requirements and implementation
- Supporting internal and external inspections and assessments
- Other responsibilities as necessary to support RMF activities