Information Systems Security Manager (ISSM)
STRAbout the role
About the Team:
The Security team at STR is comprised of highly skilled professionals who are responsible for maintaining compliance IAW with Government protocol and directives.
The Classified Cybersecurity (CCS) team consists of a collaborative group of ISSM’s, ISSO’s, and ISSE’s who are passionate about national security that take great pride in maintaining confidentiality, integrity, and availability of our systems.
The Role:
STR has an exciting opportunity for an ISSM that will be responsible for classified programs Cybersecurity/Risk Management Framework (RMF) posture in accordance with government directives and program requirements.
In this dynamic position you will interface directly with the government cognizant security agency (CSA) and collaborate with other Cybersecurity professionals, Security professionals, System Administrators, engineering community, and other government customers on overall compliance and configuration change management.
Please note…this is not a remote and/or hybrid role and a requires you to be onsite.
What you will Do:
- Responsible for the Cybersecurity program as stipulated by various US Government requirements including (but not limited to): Joint Special Access Implementation Guide (JSIG), National Industrial Security Operating Manual (NISPOM), and the DCSA Assessment and Authorization Process Manual (DAAPM)
- Supervisor and Team Lead for assigned Cybersecurity staff supporting accredited networks
- Monitor cybersecurity compliance by performing periodic self-inspections, tests, and reviews of information systems to ensure that workstations/servers are operating as authorized/accredited
- Coordinate with program/project stakeholders, Cybersecurity staff (other ISSM’s, ISSO’s, ISSE’s), the Facility Security Officer (FSO), Contractor Program Security Officer (CPSO), and other Security and IT team members to define, implement and maintain an acceptable information systems security posture
- Maintain day-to-day security posture and continuous monitoring of IS including security event log review and analysis
- Performs Assessment and Authorization (A&A) activities such as information system certification testing of required configuration controls and preparing/maintaining various documentation including Standard Operating Procedures (SOP), System Security Plan (SSP), Risk Assessment Report (RAR), Security Controls Traceability Matrix (SCTM), etc.
- Manages and maintains Continuous Monitoring (ConMon)/Plan of Action and Milestones (POA&M) reports
- Responsible for security sustainment activities including (but not limited to): hardware change management, software change management, account management, media protection, user interface, file transfers, etc
- Assists the FSO, CPSO and Computer Incident Response Team (CIRT) in data spill incident response
- Maintain thorough understanding of NIST 800-53 controls, determines controls applicable to the application, and documents control implementation in the SCTM
- Perform other tasks as assigned by manager
Who you Are:
- This position requires an active Top Secret security clearance, with the ability to obtain an SAP and SCI access for which U.S. citizenship is needed by U.S. Government
- Two (2) to four (4) years’ experience as an ISSM implementing DAAPM, JSIG, and/or ICD503 IS requirements
- DoD 8570 IAM Level III certification (CISM, CISSP, etc.) or the ability to obtain within 6 months upon being hired
- Experience with configuration/certification and auditing/analysis of Windows/Linux operating systems in a Peer-to-peer, LAN & WAN network environment
- Familiarity/understanding using authorization/accreditation databases (eMASS, Xacta, etc.)
- Excellent communications skills
- Demonstrated strong critical thinking and problem-solving skills
- Detail oriented and self-motivated
- Ability to effectively prioritize multiple projects
- Ability to work with people in a team environment and deal effectively with changing project priorities
- Strong customer service skills
STR is a growing technology company with locations near Boston, MA, Arlington, VA, near Dayton, OH, Melbourne, FL, and Carlsbad, CA. We specialize in advanced research and development for defense, intelligence, and national security in: cyber; next generation sensors, radar, sonar, communications, and electronic warfare; and artificial intelligence algorithms and analytics to make sense of the complexity that is exploding around us.
STR is committed to creating a collaborative learning environment that supports deep technical understanding and recogniz
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s