Company

Institute for Defense AnalysesSee more

addressAddressPrinceton, NJ
type Form of workFull-Time
CategoryInformation Technology

Job description

Overview:
The Institute of Defense Analyses (IDA) has an immediate career opening for an Information Systems Security Manager (ISSM) located at our Center for Communications Research located in Princeton, New Jersey (CCRP). Our primary sponsor is the Department of Defense and the classified work that is done at IDA must be kept secure. Our IT Department plays a major role against leaks of classified information. This is a great opportunity to make a difference in the national defense community.
Summary Statement:
Serves as Information Systems Security Manager (ISSM) and within assigned IT Portfolio, mentors the ISSO and Cybersecurity Analyst; oversees accreditations and daily operations of all Information Systems. Works closely with the IT Manager to implement organizational common controls across the IT Portfolio. Represents IDA with cognizant US Government accrediting agencies and either approves system accreditations or signs off on all accreditation paperwork. Ensures appropriate operational security posture is maintained for local area networks (LAN), wide area networks (WAN) and stand-alone systems. The ISSM monitors these systems and their operational environment and must have the technical knowledge and expertise required to manage the security aspects of these systems.
Must understand requirements for physical and environmental protection of the computer systems, personnel security rules that pertain to systems, incident handling (such as classified spills or malware), and security training and awareness. The ISSM plays an active role in monitoring a system and its environment of operation to include developing and updating the system security plan (SSP), managing and controlling changes to the system, and assessing the security impact of those changes
  • Serves as the Information Systems Security Manager (ISSM) for IDA/CCR-P classified and unclassified systems under the IT Manager.
    • Serves as a mentor to the ISSO and Cybersecurity Analyst.
    • Manages and coordinates information security monitoring, inspections and incident response.
    • Develops, implements and manages a formal information security / Information Systems Security program.
    • Develops, reviews, signs, maintains and oversees Information Systems Security plans (SSPs) and Assessment and Authorization (A&A) in accordance with DoD mandated polices.
    • Performs audit reviews of systems comprised of multiple operating system using security information and event management (SIEM) products to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc. Reports any findings to the Director of the Computing Lab.
    • Performs recurring self-assessments on all systems under their purview to ensure compliance with documented security requirements and to detect any system level vulnerabilities. Prepares a detailed report of the findings and ensures proper protection and / or corrective measures are taken immediately, or develops a Plan of Action and Milestones (POA&M) to document planned actions.
    • Interacts directly with US Government Security Control Assessors (SCAs) during on-site assessments to demonstrate compliance with technical configuration requirements and implementation and enforcement of written security policy.
    • Continuously updates all required system documentation, including the SSP, POA&M, Risk Assessment Report, and system component inventories.
    • Develops procedures for responding to security incidents and investigating and reporting security violations and incidents as appropriate.
  • Develops, implements and enforces information security policies and procedures
    • Performs the steps involved in the execution of the Risk Management Framework (RMF), including generation of documentation, controls compliance testing, and continuous monitoring activities for systems.
    • Develops and periodically reviews training materials and standard operating policies covering all technical and administrative aspects of system operations.
    • Works with IT to perform an initial system assessment to ensure that required security controls are implemented and operating correctly before a systems is authorized for production.
    • Works with IT to develop automated processes to assist in maintaining system compliance and documentation updates.
    • Collaborates with IT to oversee an effective change management policy and procedures for authorizing use of hardware/software on an information system. Evaluates proposed changes against Government security requirements and recommends approval or denial based on a security impact analysis.
    • Reviews and ensures implementation of bulletins and advisories that impact the security posture of Information Systems covered by SSP's.
    • Reviews systems for compliance to Government requirements, and provide recommendations for improvements.
  • Develops an Information Systems Security, education, training and awareness program
    • Clearly communicates to all users including security personnel, IT staff, and managers the proper procedures for protecting classified information and the systems that process that information. Training prior to initial system access and periodically after includes proper system usage, physical security, data transfers, media protection, etc.
  • Performs other duties as assigned.

Qualifications:
  • Bachelor's degree in an Information Assurance/Cybersecurity of similar relevant field or equivalent experience.
  • Minimum six years' experience in a similar Systems Security Manager or officer role.
  • Must have the following Information Assurance certifications or security training or obtain the certificates within 6 months of hire:
    • DSS MISPOM Risk Management Framework Courses
    • DOD 8570.01-M certification at IAM level 3, such as CISSP or CISM
    • Cedrtified Authorization Professional (CAP) through (ISC)
  • Must understand the technical configurations of Linux Operating Systems and Windows in physical and virtual environments as appropriate to the site, both and other operating systems preferred.
  • Must have knowledge of NIST security publications.
  • Must have the ability to read and understand event logs from Linux and Windows.
  • Knowledge of tools to parse logs, scan operating systems for vulnerabilities and compliance checking preferred, and required within 6 months of hire.
  • Customer service skills, including good interpersonal skills and the ability to communicate effectively with all levels of employees.
  • Ability to obtain and maintain Top Secret security clearance with SCI Eligibility.

#ITatIDA
Refer code: 7615028. Institute for Defense Analyses - The previous day - 2024-01-03 16:43

Institute for Defense Analyses

Princeton, NJ
Popular System Security Manager jobs in top cities
Jobs feed

Court Services Specialist

Mexico Courts

Las Cruces, NM

$18.28 an hour

OR Central Scheduler - FT

Mountainview Regional Medical Center

Las Cruces, NM

$29.8K - $37.8K a year

Desktop Support in White Sands, New Mexico

Virtual Service Operations

New Mexico, United States

$17 - $25 an hour

Leasing Agent

Pro Residential

Lawton, OK

$1,800 - $2,400 a month

Electric Meter Technician

Texas Meter & Device

Las Cruces, NM

$120 - $200 a day

HRIS Senior Analyst- SuccessFactors

Sitel

United States

Shift Manager Pokemoto/MuscleMakerGrill

Muscle Maker Grill

Fort Sill, OK

$13 - $15 an hour

Engine Tester

Aventure Staffing

Norfolk, NE

$ 17.50/hr DOE

Medical Assistant I

Epiphany Dermatology

Las Cruces, NM

$31.8K - $40.2K a year

Preschool 1:1 and Teacher Aides

York State Department Of Labor

New York, NY

Share jobs with friends

Related jobs

Information Systems Security Manager (ISSM)

Lead Information System Security Manager- TS/SCI

Peraton

Red Bank, NJ

6 months ago - seen