Information Systems Security Manager (ISSM) I Bedford, MA
Watermark Risk Management International, LLC
Information Technology (IT)
The ISSM’s primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
*Telework/telecommuting is temporarily available for this position, on a rotating basis due to COVID*
Performance shall include:
Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures
Perform analysis of network security, based upon the RMF or JAFAN authorization process; advise customer on IT assessment and authorization issues
Perform risk assessments and make recommendations to customers
Advise government program managers on security testing methodologies and processes
Evaluate assessment documentation and provide written recommendations for authorization to government PM’s
Periodically review system security to accommodate changes to policy or technology
Develop and maintain a formal Information Systems Security Program
Ensure that all IAOs, network administrators, and other AIS personnel receive the necessary technical and security training to carry out their duties
Develop, review, endorse, and recommend action by the AO or DAO of system assessment documentation
Ensure approved procedures are in place for clearing, purging, declassifying, and releasing system memory, media, and output
Conduct assessment tests that include verification that the features and assurances required for each protection level are functional
Maintain a repository for all system authorization documentation and modifications
Coordinate AIS security inspections, tests, and reviews
Develop policies and procedures for responding to security incidents, and for investigating and reporting security violations and incidents
Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered within a system
Ensure that data ownership and responsibilities are established for each AIS, to include accountability, access rights, and special handling requirements
Ensure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local AIS security training.
Ensure that security assessments are completed and documented
Evaluate threats and vulnerabilities to ascertain whether additional safeguards are needed
Assess changes in the system, its environment, and operational needs that could affect the authorization
Ensure that authorization is accomplished on each AIS
Review AIS assessment plans
Conduct periodic assessments of the security posture of the AIS
Ensure configuration management (CM) for security-relevant AIS software, hardware, and firmware are properly documented.
Ensure that system recovery processes are monitored to ensure that security features and procedures are properly restored
ensure all AIS authorization documentation is current and accessible to properly authorized individuals
Ensure that system security requirements are addressed during all phases of the system life cycle
Participate in self-inspections; identify security discrepancies and report security incidents
Coordinate all technical security issues outside of area of expertise or responsibility with SSE
Provide expert research and analysis in support of expanding programs and area of responsibility
Perform file transfers between local systems to storage devices
5 - 7 years related experience
Bachelor’s degree in a related area or equivalent experience (4 years)
Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level 3 or Information Assurance Manager Level 3 within 6 months of the date of hire (CASP+ CE, CCNP Security, CISA, CISSP (or associate), GCED, GCIH, CISM, CISSP (or associate), GSLC, CCISO)
Current Top Secret Clearance with SCI Eligibility
Eligibility for access to Special Access Program Information
Willingness to submit to a Counterintelligence polygraph
Must be familiar with current security policy/manuals
Must have the ability to work in a dynamic environment and effectively interact with numerous DOD, military/civilian personnel and industry partner
Working knowledge of Microsoft Office (Word, PowerPoint, and Excel)
Possess a high degree of originality, creativity, initiative requiring minimal supervision
Willingness to travel within the organizational geographic Area of Responsibility (AOR) (note - could be extensive, and will include both air and ground transportation)
Must be able to lift up to 50 lbs
CLICK ON LINK BELOW TO BE DIRECTED TO OUR WEBSITE FOR YOUR APPLICATION PROCESS:
KEYWORDS: RMF, Risk Management Framework, ICD, Information Assurance, IA, IAO, IAT, IAM, A&A, A+, Network+, Security+, Non-classified Internet Protocol Router Network (NIPRNet), Secret Internet Protocol Router Network (SIPRNet), DISA Security Technical Implementation Guides (STIGs), CISSP, CASP
Watermark Risk Management International, LLC is an Equal Opportunity and Affirmative Action Employer and does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factors.
IT Project Management
Top Secret/Sensitive Compartmentalized Information (TS/SCI) With Polygraph
We hire service-disabled veterans whenever possible. Currently over 50% of our associates are disabled vets. You can take pride in knowing you are assisting men and women who have made very real sacrifices for their country.
Watermark Risk Management International is more than a company. We are a team. We will give you the opportunity to make your mark—to grow, stretch and flourish. We are keenly aware that our employees are our most important asset. We hire innovators, as well as thoughtful, creative and motivated workers who enjoy showing up for work in a purposeful, passionate and fully present way…every single day.
Watermark is a dynamic company, providing clients with the highest levels of service and support. We work hard and play hard, and try to keep our priorities in the following order: faith, family, health, and work.
We are firmly committed to diversity and discussion. We celebrate and welcome differences and diverse backgrounds, perspectives and work styles. Every employee has an important and relevant voice; opinions are absolutely required; and a willingness to speak up and contribute is a must. We believe our diversity will lead to the most beneficial and innovative customer solutions. As a result, we ensure no potential solution is overlooked. Watermark is an EEO employer and strongly supports the hiring of military veterans.