Leidos is seeking an Information System Security Manager (ISSM) for our Bridgewater, VA office. The Information System Security Manger is the primary Information Assurance (IA) decision maker and responsible for the management and technical administration of Information Systems (IS) in accordance with internal and external security requirements. The ISSM will oversee day-to-day security operations including hardware and software implementations along with assisting users as needed in a classified computing environment. Ability to work independently as well as with a team of analysts trained in operations research, mathematics, and other skills is required. The ideal candidate will be adaptable to diverse office situations, procedures and demands.
- Certification and accreditation of SIPR through the RMF process.
- Continuous upkeep, monitoring, analysis, and response to Information System, network and security events.
- Documents compliance actions within the approved automated compliance tracking system.
- Develops and maintains a Plan of Actions and Milestones (POA&M) to address non-compliance and corrective actions.
- Develop procedures and documentation to ensure compliance with Configuration Management (CM) for security-relevant IS software, hardware, and firmware.
- Author all required information system security-related documentation as required by cognizant security authority and IAW published standards.
- Ensures systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the System Security Plan (SSP), Standard Operating Procedures (SOP), and customer directives.
- Ensures records are maintained for workstations, servers, software, routers, firewalls, network switches, crypto, and other relevant hardware/equipment throughout the information system's life cycle.
- Evaluates proposed changes or additions to the information system, and advises senior site leadership of the security relevance.
- Lead / conduct security IS education and training.
- Participates in internal/external security audits/inspections; performs risk assessments and Continuous Monitoring.
- Lead investigations of computer security violations and incidents, reporting as necessary to both the Facility Security and Senior Program Managers.
- Ensure proper protection and / or corrective measures are taken when an incident or vulnerability has been discovered
- Working with the Facility Security Officer (FSO) develop, implements and manage a formal Information Security / Information Systems Security Program.
- Develop, implement and enforce Information Security Policies and Procedures.
- Author, review and update IS Authorization documentation (Body of Evidence) to support IS Assessment and Authorization (Certification/Accreditation) activities.
- Bachelor's degree or equivalent and 8+ year's related experience. Additional years of relevant experience will be considered in lieu of a degree.
- Current DoD 8570 baseline certification for IAM II
- Active SECRET clearance with ability to upgrade to TS if needed
- Understanding of the Risk Management Framework (RMF), NIST, ICD, and CNSS standards.
- Familiarity with network technologies (LAN & WAN) and best practices within a classified environment to including encryption and key management
- Expert with Microsoft Window in a secure network environment. Active directory. Group policy.
- Must be able to work in a constantly changing regulatory environment.
- Must be able to work well within a team environment and able to adapt quickly to change.
- Good writing and verbal presentation skills.
- Willingness to continue training to enhance job performance
- Past or current ISSM/ISSO experience
- DoD IS knowledge and experience
- Security hardening scripting/automation experience
- Microsoft OS Certification (MCSE Win 7 or other)
- Linux experience
External Referral Bonus:
Potential for Telework:
Clearance Level Required:
Scheduled Weekly Hours: