Jobs and Careers
NO

Information Systems Security Manager (ISSM)

Noblis
Philadelphia, United Statesfull_timeVerifiedPosted 17 Feb 2025
💰 $145,550/yr($93,200/yr$145,550/yr)

About the role

Responsibilities

Noblis MSD’s mission is to support the Naval Sea Systems Command (NAVSEA) and, Naval Surface Warfare Center (NSWCPD) and their missions’ to enable research, development, test and evaluation, acquisition, engineering, systems integration, in-service and fleet engineering with cybersecurity, comprehensive logistics, and life-cycle savings.

 

Noblis MSD is seeking a well-rounded Information Systems Security Management (ISSM) individual to oversee RMF packages and the Information Systems Security Engineer (ISSE) with NSWCPD ashore and afloat systems network server duties. The ISSM position supports a national security focused customer providing system security engineering services and/or product to ensure secure reliable and uninterrupted availability of customer developed and deployed systems and networks. The ISSM will support the Government to ensure core security engineering principles are implemented into assigned programs information systems architecture.

 

PRINCIPAL DUTIES/RESPONSIBILITIES:

 

Lifecycle cybersecurity support of US Navy systems, which includes, but is not limited to:

  • Oversee analysis and evaluation to design, implement, test and field secure systems, networks, and architectures
  • Assessing system compliance against NIST, DoD, and Navy security requirements to include the NIST 800-53 controls and results of DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)
  • Develop, implement, and enforce information systems security policies ensuring system security requirements are addressed during all phases of the acquisition and Information System (IS) lifecycle.
  • Oversee certification and testing in accordance with the Risk Management Framework (RMF) and National Institute of Standards and Technology (NIST) policy; identify deficiencies and providing recommendations of risk mitigation to customer.
  • Support the Government to resolve conflicting system security engineering requirements.
  • Develop program technical publications such as Systems Engineering Plans (SEP), Technical Plans, Analyses and Reports, Risk Assessments, Security Concepts of Operations (SECONOP), Program Protection Plan, Anti-Tamper Plan, Cybersecurity Strategy, Technology Development Strategies, Test Plans, procedures and reports, System Security Plans
  • Coordinating with other system SMEs to facilitate identificaton and development of authorization boundary diagrams, architecture diagrams, and hardware and software inventories
  • Working with system administrators, engineers, and developers to update system/site policies, procedures, and process guides
  • Producing evidence as necessary to support compliance status of NIST, DoD, and Navy security requirements
  • Maintaining awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes
  • Attending and participating in regular A&A status meetings to facilitate progress and address potential issues of RMF system efforts
  • Actively participating in working group meetings to identify, plan, and execute strategies in response to emerging cybersecurity/RMF policies

Required Qualifications

  • Bachelor of Science degree in Computer and Network Security from a nationally accredited college or university with 5 years’ experience 
  • Experience as an ISSM on programs and contracts of similar scope is strongly preferred
  • Must have a current Security+ certification
  • US CItizen with an active DoD secret clearance or the ability to obtain a DoD secret 

Desired Qualifications

  • Knowledge of the fundamental concepts, practices, and procedures associated with industrial control systems
  • Experience with testing methods, automated tools, plans, and procedures for verification of compliance and vulnerability requirements.
  • Experience with vulnerability assessment tools, including but not limited to Assured Compliance Assessment Solution (ACAS) and Host Based Security System (HBSS) and DISA SCAP/STIGs
  • Experience with the Enterprise Mission Assurance Support Service (eMASS)
  • Experience with modern networks, operating systems, databases, and virtual computing
  • Ability to develop and interpret security architectures, data flow diagrams, engineering electrical/pinout drawings, and publications that depict the system(s) architecture
  • Ability to be able to identify risk areas of non-compliance and propose solutions to design to fulfill operational requirements and meet cybersecurity requirements simultaneously.
  • Exceptional verbal and written communication skills, with the ability to collaborate across teams and organizations, including senior level management
  • Proven

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Noblis

View company profile →