RiVidium
Posted 4d ago

Information Systems Security Manager - Intermediate (VA, Springfield)

RiVidium
Springfield, Virginia, United States
OnsiteFull Time
Responsibilities
  • managing resources
  • advising management
  • overseeing cybersecurity
Requirements
  • Associate degree or higher required
  • Preferably in a technology
  • Mathematics, or engineering field
  • IAT/IAM Level 3 certification required. AWS
  • Log auditing
  • Help desk, and ITIL V4 familiarity preferred
Technical tools mentioned
AWSITIL V4Computer Network DefenseSecurity Assessment and Authorization

Job description

RiVidium Inc. is seeking an individual to be responsible for the cybersecurity of a program, organization, system, or enclave. Responsibilites and abilities for this position shall include, but not limited to:




  • Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support information technology (IT) security goals and objectives and reduce overall organizational risk.

  • Acquire necessary resources, including financial resources, to conduct an effective enterprise continuity of operations program.

  • Advise senior management (e.g., Chief Information Officer [CIO]) on risk levels and security posture.

  • Advise senior management (e.g., CIO) on cost/benefit analysis of information security programs, policies, processes, systems, and elements.

  • Advise appropriate senior leadership or Authorizing Official of changes affecting the organization's cybersecurity posture.

  • Collect and maintain data needed to meet system cybersecurity reporting.

  • Communicate the value of information technology (IT) security throughout all levels of the organization stakeholders.

  • Collaborate with stakeholders to establish the enterprise continuity of operations program, strategy, and mission assurance.

  • Ensure that security improvement actions are evaluated, validated, and implemented as required.

  • Ensure that cybersecurity inspections, tests, and reviews are coordinated for the network environment.

  • Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s).

  • Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture.

  • Establish overall enterprise information security architecture (EISA) with the organization's overall security strategy.

  • Evaluate and approve development efforts to ensure that baseline security safeguards are appropriately installed.

  • Evaluate cost/benefit, economic, and risk analysis in decision-making process.

  • Identify alternative information security strategies to address organizational security objectives.

  • Identify information technology (IT) security program implications of new technologies or technology upgrades.

  • Interface with external organizations (e.g., public affairs, law enforcement, Command or Component Inspector General) to ensure appropriate and accurate dissemination of incident and other Computer Network Defense information.

  • Interpret and/or approve security requirements relative to the capabilities of new information technologies.

  • Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.

  • Lead and align information technology (IT) security priorities with the security strategy.

  • Lead and oversee information security budget, staffing, and contracting.

  • Manage the monitoring of information security data sources to maintain organizational situational awareness.

  • Manage the publishing of Computer Network Defense guidance (e.g., TCNOs, Concept of Operations, Net Analyst Reports, NTSM, MTOs) for the enterprise constituency.

  • Manage threat or target analysis of cyber defense information and production of threat information within the enterprise.

  • Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards to ensure that they provide the intended level of protection.

  • Oversee the information security training and awareness program.

  • Participate in an information security risk assessment during the Security Assessment and Authorization process.

  • Participate in the development or modification of the computer environment cybersecurity program plans and requirements.

  • Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations.

  • Provide enterprise cybersecurity and supply chain risk management guidance for development of the Continuity of Operations Plans.

  • Provide leadership and direction to information technology (IT) personnel by ensuring that cybersecurity awareness, basics, literacy, and training are provided to operations personnel commensurate with their responsibilities.

  • Ability to apply techniques for detecting host and network-based intrusions using intrusion detection technologies.

  • Ability to integrate information security requirements into the acquisition process; using applicable baseline security controls as one of the sources for security requirements; ensuring a robust software quality control process; and establishing multiple sources (e.g., delivery routes, for critical system elements).

  • Ability to identify critical infrastructure systems with information communication technology that were designed without system security considerations.



Preferred Qualifications to include:




  • Experience in log auditing and audit logging.

  • Understanding of AWS

  • Help Desk Experience

  • ITIL V4 Foundation: A familiarity with at least one ITIL V4 component is desirable.



Requirements for this position shall include:





  • Associate’s degree or higher from an accredited college or university (Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree, or a degree in a Mathematics or Engineering field.)




  • Certs- IAT/ IAM level 3




About RiVidium

Provides cybersecurity software and IT services to federal agencies.

Similar jobs

Information Systems Security Manager roles near Springfield, Virginia
1d
Save
Mark Applied
Hide
Senior Information Systems Security Manager (ISSM)
Washington or North Carolina
$159k-$200k/yr RemoteFull Time
KBR
KBRNYSE: KBR: Provides engineering, technology, and professional services for global markets.
5+ YOEBachelor's degree and 5+ years in federal or DoD cybersecurity, active DoD Secret clearance, ATO experience, cloud and DevSecOps expertise, and cybersecurity leadership skills.
eMASS, XACTA, GitLab, Docker, AWS GovCloud, Azure Government, IaaS, PaaS, SaaS, Agile Scrum, DevSecOps, NIST SP 800-53, Risk Management Framework (RMF)
1d
Save
Mark Applied
Hide
Information Systems Security Manager
Fort Belvoir, Virginia, United States
$140k-$180k/yr OnsiteFull Time
Modern Technology Solutions
Modern Technology Solutions: A defense consulting organization providing technology and information assurance support to government programs.
5+ YOEBachelor’s degree, 5+ years DoD IT/IA experience, 3+ years A&A, RMF, and eMASS experience, vulnerability scanning experience, DoD 8140 intermediate certification, and current Top Secret eligibility required.
Enterprise Mission Assurance Support Service (eMASS), Retina, ACAS, Nessus, NIST SP 800-53 Rev5, NIST SP 800-171, NIST SP 800-37, Microsoft DISA eMASS
1d
Save
Mark Applied
Hide
Information Systems Security Manager
Fort Belvoir, Virginia, United States
$140k-$180k/yr OnsiteFull Time
Modern Technology Solutions, Inc.
Modern Technology Solutions, Inc.: Provides engineering, technology, and cybersecurity services for national security.
5+ YOEBachelor's degree, 5+ years of DoD IT/IA experience, RMF and A&A package expertise, eMASS experience, vulnerability scanning experience, DoDI 8140 intermediate certification, and current Top Secret eligibility.
Enterprise Mission Assurance Support Service (eMASS), Retina, ACAS, Nessus, NIST SP 800-53 Rev5, NIST SP 800-171, NIST SP 800-37, DISA eMASS, RMF, IT, IA
1d
Save
Mark Applied
Hide
Information Systems Security Manager
Chantilly, Virginia, United States
$150k-$210k/yr OnsiteFull Time
VTG
VTG: Provides engineering and digital modernization solutions for national security.
Master's or PhD in a related technology field, or bachelor's with advanced security certification; active Top Secret/SCI clearance with CI Poly; and one listed cybersecurity certification.
RMF, NIST
3d
Save
Mark Applied
Hide
Information Systems Security Manager - TS/SCI with Polygraph
Bethesda, Maryland, United States
$162k-$219k/yr OnsiteFull Time
General Dynamics Information TechnologyNYSE: GD: Provides mission-critical IT services to government and defense organizations.
8+ YOEBachelor’s degree in a related technology field, 8+ years of experience, active TS/SCI clearance with polygraph, U.S. citizenship, and experience with RMF, NIST controls, STIGs, documentation, and security tools.
Amazon Web Services (AWS), Plan of Action and Milestones (POA&M), RMF, Xacta, NIST 800-53, ICD 503, CNSSI 1253, NIST SP 800-53/53A, STIGs, ServiceNow, Continuum, SCAP, CISSP, CompTIA Security+, CISA, CISM, CompTIA Advanced Security Practitioner (CASP+), AWS Solutions Architect
3d
Save
Mark Applied
Hide
Information Systems Security Manager - TS/SCI with Polygraph
Bethesda, Maryland, United States
$162k-$219k/yr OnsiteFull Time
GDIT
GDITNYSE: GD: Delivers IT and mission services to government agencies.
Bachelor's degree in a related technology field, 8+ years of experience, U.S. citizenship, and active TS/SCI clearance with polygraph. Requires RMF, cybersecurity standards, documentation, audit, and security tool experience.
Amazon Web Services (AWS), Plan of Action and Milestones (POA&M), RMF, Xacta, NIST 800-53, ServiceNow, Continuum, SCAP, ICD 503, CNSSI 1253, NIST SP 800-53/53A, STIGs
1w
Save
Mark Applied
Hide
Information Systems Security Manager (ISSM)
Washington or Arlington
$121k-$185k/yr OnsiteFull Time
RAND
RAND: Provides research and analysis for public policy and security.
5+ YOEFive years of classified systems security experience with an associate degree, or ten years without a degree; TS/SCI eligibility and DoD 8140 IAM Level 2 certification required.
NISPOM, DAAG, ICD, JSIG, NIST 800 Series, RMF, SIEM, Microsoft Office, Cybersecurity tools
1w
Save
Mark Applied
Hide
Information Systems Security Manager ISSM
Alexandria, Virginia, United States
$130k-$160k/yr HybridFull Time
KMS Solutions
KMS Solutions: Technical engineering and management services for defense programs.
5+ YOEBachelor’s degree and 5+ years of DoD cybersecurity or RMF experience. Requires Security+ or equivalent IAT/IAM certification, Windows or Linux certification, eMASS experience, Secret clearance eligibility, and U.S. work authorization.
Risk Management Framework (RMF), NIST SP 800-53, NIST SP 800-53A, CNSSI 1253, ACAS, SCAP, Nmap, eMASS, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Microsoft Outlook, Windows, Linux, DIACAP