Information System Security Manager (ISSM) - Contingent Upon Contract Award
Technology
Job Description
Job Description
Contingent Posting Notice:
JMA Resources is recruiting for this position in anticipation of a potential contract award. This position is contingent upon JMA Resources receiving the associated contract award and confirmation of final staffing requirements and funding.
Position Overview:
The Information System Security Manager (ISSM) supports the implementation and oversight of information security activities for our client’s systems and programs. This role helps manage cybersecurity risk, RMF activities, compliance, security improvements, and coordination across technical and program stakeholders.
Responsibilities:
- Cybersecurity Program & Risk Management
- Support information security goals and initiatives that reduce organizational cybersecurity risk.
- Coordinate cybersecurity activities and communicate security priorities across organizational levels and stakeholders.
- Support the evaluation, validation, and implementation of security improvements.
- Identify security requirements throughout the system lifecycle and support effective implementation of related policies and procedures.
- Evaluate patterns of noncompliance and assess their impact on risk and overall cybersecurity program effectiveness.
- Identify and recommend information security strategies to address organizational security objectives.
- RMF, Assessment & Compliance
- Support information security risk assessments throughout the Assessment and Authorization (A&A) process.
- Perform quality assurance reviews of RMF package submissions in accordance with applicable NSWCPD and NAVSEA requirements.
- Support cybersecurity inspections, testing, and reviews of network environments.
- Track audit findings, deficiencies, and recommendations through appropriate mitigation or corrective action.
- Develop findings reports and recommend corrective actions for identified deficiencies.
- Coordinate resolution of findings identified through internal and external reviews.
- Monitor authorization conditions, POA&M items, and System Level Continuous Monitoring (SLCM) activities.
- Reporting & Stakeholder Coordination
- Collect and analyze data needed to support cybersecurity reporting and management decisions.
- Report and maintain system compliance information in applicable Navy and DoD systems, including DADMS, DITPR-DON, and VRAM.
- Facilitate communication and coordination among RMF stakeholders throughout the authorization process.
- Support cybersecurity strategy, policy enforcement, security awareness, emergency planning, and other information security program activities.
- Carry out other related duties assigned to support evolving client, project, and company needs.
Clearance Level:
- Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required. Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines.
Required Qualifications:
- Experience:
- At least 8 years of professional experience overseeing or managing information security program implementation, including experience with:
- Coordinating cybersecurity activities across multiple levels of an organization.
- Managing cybersecurity strategy, personnel, infrastructure, policy enforcement, emergency planning, security awareness, and/or related resources.
- Supporting information security risk management, compliance, and security program activities.
- Education/Certification:
- Master’s degree in computer science, information technology, or an equivalent STEM field.
- One of the following certifications:
- Certified Authorization Professional (CAP)
- CompTIA Advanced Security Practitioner Continuing Education (CASP+ CE)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP) or Associate of ISC2
- GIAC Security Leadership Certification (GSLC)
- Certified Chief Information Security Officer (CCISO)
- HealthCare Information Security and Privacy Practitioner (HCISPP)
- Skills:
- Strong knowledge of RMF, A&A, cybersecurity risk management, and information security compliance.
- Ability to evaluate cybersecurity findings, risks, and corrective actions.
- Experience coordinating across technical, program, and leadership stakeholders.
- Strong analytical, organizational, and technical communication skills.
- Ability to manage multiple cybersecurity priorities, findings, and compliance activities.
- At least 8 years of professional experience overseeing or managing information security program implementation, including experience with:
Preferred Qualifications:
- Experience supporting Navy or Department of Defense cybersecurity and RMF programs.
- Experience with Navy and DoD compliance and vulnerability management systems such as DADMS, DITPR-DON, or VRAM.
Location & Commitments:
- Position: Full Time
- Work Arrangement: Hybrid – On-site at our client site in Philadelphia, Pennsylvania. The number of days on-site will be determined by client needs after hire.
- Travel Requirements: May be required
- Location Preference: Prefer candidates within a 50-mile radius of Philadelphia, Pennsylvania.
- Work Hours: A typical workday consists of eight hours, totaling a forty-hour workweek. We understand that there may be times when employees will need to adjust their work hours due to client needs or personal reasons. To help balance these demands, we offer some flexibility in work schedules.
