Company

Lawelawe Technology ServicesSee more

addressAddressWashington, DC
type Form of workFull Time
salary Salary$151k-186k (estimate)
CategoryInformation Technology

Job description


Lawelawe Technology Services is Hiring an Information Systems Security Manager Near Washington, DC

The Information Systems Security Manager (ISSM) will be responsible for leading a team to execute risk management efforts against the CAO’s inventory of on premise, vendor, and cloud-based systems.
Key Responsibilities:
  • Manage Information System Security Officers (ISSO) to support information technology (IT) security goals and objectives and reduce overall organizational risk.
  • Assist in the execution and management of the Risk Management Framework (RMF) and advise ISSOs on proper application of cybersecurity policies and requirements.
  • Assist senior management in the development and interpretation of information assurance guidelines, policies, regulations etc.
  • Advise senior management (e.g., Chief Information Security Officer [CISO]) on risk levels and security posture.
  • Advise appropriate senior leadership or Authorizing Official of changes affecting the organization's cybersecurity posture.
  • Conduct independent or coordinated studies to identify, evaluate or recommend solutions to significant systems management problems that are likely to be complex and sensitive in nature.
  • Ensure that security improvement actions are evaluated, validated, and implemented as required.
  • Identify alternative information security strategies to address organizational security objectives.
  • Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
  • Participate in information security risk assessments during the Security Assessment and Authorization process.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
  • Provide quality assurance reviews of cybersecurity deliverables to ensure consistency, accuracy, and relevancy.
  • Provide technical and procedural information system advice to risk management team.
  • Perform quality reviews of security artifacts collected by ISSOs under their purview to ensure quality assessment and authorization (A&A) deliverables are provided.
  • Assume ISSO responsibilities in the absence of ISSO.
  • Ensure a record is maintained of all vulnerabilities for existing authorization boundaries.
  • Advise ISSOs on all matters, technical and otherwise, involving the security of assigned IT systems.
  • Maintain a working knowledge of system technology, security policies, and security safeguards.
  • Ensure continuous monitoring of authorization boundaries and implemented security controls is followed.
  • Provide guidance to ISSOs on mitigation actions for security control deficiencies and scan vulnerabilities for assigned IT systems.
  • Provide role-based training for assigned ISSOs specific to their roles and responsibilities.
  • Brief senior management on the status of ISSOs and their assigned projects.
  • Work with senior leadership to mature risk management processes.
  • Develop and formalize risk management training for varied stakeholder groups.
  • Conduct assigned technical reviews and risk analyses and develop cybersecurity risk mitigation recommendations and strategies based on threats.
  • Research and recommend innovative, secure, and (where possible) automated solutions to improve risk management processes and activities.
  • Participate in the technical security evaluation and assessment of new technologies.
  • Provide audit support to cybersecurity for audit activities and recommendations.
Qualifications:
  • 8 years of demonstrated work experience in cybersecurity risk management.
  • Bachelor’s degree in computer science, information technology, cybersecurity, or a related technical discipline required.
  • Current certification in one or more of the following IT Security disciplines: Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) or equivalent certification required.
  • Demonstrated experience managing Systems Security assessments, reviewing system security documentation for successful security authorization of such systems.
  • Strong knowledge and expertise with NIST publications.
  • Demonstrated experience providing quality A&A deliverables.
  • Proven technical acumen and understanding of common operating systems and network technologies, risk management frameworks, and common security tools and scanners.
  • Demonstrated understanding of cloud service models, hybrid applications, and mobile security technologies and tools.
  • Understanding of management, operational and technical cybersecurity principles.
  • Excellent written and oral communication skills.
  • Must possess an active Secret Clearance.
Preferred Qualifications:
  • Experience with privacy principles and frameworks is preferred.

Disclaimer:

The above job description is intended to describe the general nature and level of work being performed by individuals assigned to this position. It is not intended to be an exhaustive list of all responsibilities, duties, and skills required. Candidates possessing the necessary qualifications for the position will be considered.

Lawelawe is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status, and will not be discriminated against on the basis of disability.

Notice to all Applicants:

Offers of employment are contingent upon satisfactory completion of a comprehensive background verification, inclusive of a criminal record check. Employment may be subject to other background checks, as required by the position.

Job Summary

JOB TYPE

Full Time

SALARY

$151k-186k (estimate)

POST DATE

04/26/2024

EXPIRATION DATE

07/16/2024

Refer code: 9139077. Lawelawe Technology Services - The previous day - 2024-04-26 13:48

Lawelawe Technology Services

Washington, DC
Jobs feed

Pricing Integrity Agent

Retail Data, Llc

Minnesota, United States

Crew Member

Mod Pizza

Texas, United States

$12.50 per hour

Office Assistant

Nesco Resource

Versailles, KY

$15.00 •

Automotive Technician - PM Shift

Nesco Resource

Allen Park, MI

Up to $20.21 •

Material Handler

Nesco Resource

Williamsport, PA

$12.00 •

Work from Home Mental Health Therapist - Telehealth - Now Hiring

Lyra Health Inc

Texas, United States

$62,000 - $84,000 per year

Machine Operator

Nesco Resource

Mars, PA

$18.00 to $25.00 •

Public Defender 2 - Cedar Rapids

State Of Iowa

Cedar Rapids, IA

Dietary Aide - Server - FT - 10:30 AM - 7 PM

Pivotal Health Care

Marion, IA

Guest Experience Lead | Mayfaire Town Center Pop Up

Lululemon Athletica

North Carolina, United States

Share jobs with friends

Information Systems Security Manager

Palantir Technologies

Washington, DC

4 weeks ago - seen

Security Systems Infrastructure Project Manager

Sentrillion

$100,000 - $125,000 a year

Washington, DC

2 months ago - seen

ISSM (Information Systems Security Manager) [365]

eTRANSERVICES

Washington, DC

5 months ago - seen