Position Summary: Plan, implement and manage security measures to safeguard computer systems, networks and data. Serve as facility ISSM by maintaining system security plans for Department of Defense (DoD) programs Provide business and technical knowledge to analyze and implement security policies and procedures for CMMC compliance.
Position Responsibilities:
- Perform oversight of the development, implementation and evaluation of information systems security program for assigned programs in compliance with NISPOM, DAAPM, DCID 6/3, JAFAN 6/3, ICD 503, and JSIG RMF.
- Prepare and maintain security Assessment and Authorization documentation (e.g., IA SOP, SSP, RAR, and SCTM) including participation in system categorization.
- Ensure the development, documentation, and presentation of IS security education, awareness, and training activities for users and others, as appropriate.
- Apply cyber security standards, directives, guidance and policies to special programs classified computing environments.
- Perform tasks related to compliance of Continuous Monitoring (ConMon) Plans (e.g., audit log review, security patching, software and hardware configuration management).
- Investigate security incidents to include data spills, data integrity incidents, and malicious code incidents.
- Ensure system security measures comply with applicable government policies, provide configuration management and accurately assess the impact of modifications and vulnerabilities for each system.
- Conduct reviews and technical inspections to identify and mitigate potential security weaknesses, and ensure that all security features applied to a system are implemented and functional.
- Manages Risk Management Framework (RMF) processes, product development and product maintenance for assigned systems.
- Knowledge and ability to implement and maintain a Risk Management Framework as mandated by NIST 800-37, NIST 800-53, and supporting policy.
- Experience administering the system functions including security policies and account management of Microsoft Windows and Server as well as Linux/Unix-based systems.
- Generate and maintain required IS security documentation including Systems Security Plans (SSP), Continuous Monitoring Plans, Security Control Traceability Matrices, Risk Assessments, Plan of Action &Milestones (POA&M), equipment specifications, practices and procedures.
- Perform CMMC application and accreditation duties, develop and implement continuous monitoring strategies, and enhance company best practices related to the IT Security posture.
- Maintains and builds business and technical knowledge to analyze and implement security strategies in accordance with best practices and industry requirements.
- Performs other duties as assigned support company objectives.
Essential Skills:
- Excellent customer service skills, clear communication, a passion for technology and a positive attitude.
- Detail-oriented individual with the ability to read and follow policy and procedure.
- Ability to work in a highly visible role with daily interactions with multiple roles.
- Strong analytical skills.
- Familiarity with NIST Special Publications and applying controls to a corporate environment strongly desired.
- Strong self-management skills and ability to adjust as needed to meet shifting priorities.
Qualifications:
- Bachelor's degree (preferred) in Computer Science or related field
- 5 + years' experience in security risk and systems auditing
- Experience supporting enterprise infrastructure including, Windows OS, networks, firewalls, VPN, messaging gateways, servers and applications
- Experience implementing technology with security requirements and specific contracts including documenting and writing procedures
- Enterprise Resource Planning database knowledge required; IFS knowledge preferable
- Proven project management skills with ability to bring projects to resolution
- Demonstrated ability to work with multiple groups to accomplish a goal
- US Secret Security clearance or ability to obtain a government security clearance within 90 days required.
Work Environment:
- Office environment and Manufacturing floor
- 9/80 Schedule - Hours: 7:00 am - 4:30 pm, Monday through Thursday, 7:00 am - 3:30 pm every other Friday, with additional hours as needed
|