The Information Systems Security Manager will lead and implement the Assessment and Authorization process under Risk Management Framework for new and existing information systems, and manage ATO packages in eMASS. They will also review assessment reports and assist projects in identifying security risks and developing mitigation strategies.
Requirements
- 5+ years of experience leading and implementing the Assessment and Authorization process under Risk Management Framework for new and existing information systems
- 3+ years of experience reviewing assessment reports and assisting projects in identifying security risks, including technical and non-technical, and developing effective mitigation strategies
- 3+ years of experience managing ATO packages in eMASS
- Experience applying abstract security requirements, including NIST 800-53 controls to information systems
- Experience in an advisory environment and communicating technical subjects to clients
- Knowledge of supporting the development or modification of System Security Plans, security requirements, and supporting documentation for the Assessment and Authorization process
- Ability to ensure all products and administrative documentation is completed and maintained, including for continuity and historical reference, and design, develop, and implement network security measures that provide confidentiality, integrity, availability, authentication, and non-repudiation
- TS/SCI clearance
- HS diploma or GED
- DoD 8570 IAM III Certification
Benefits
- Health, life, disability, financial, and retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Dependent care
- Recognition awards program