Information Systems Security Manager (ISSM) - Hybrid | Chantilly, VA
Optiv + ClearSharkAbout the role
This position will be hybrid and can be hired in the Washington, DC metropolitan area.
The Information Systems Security Manager (ISSM) will perform duties for the Optiv+ClearShark information systems environments, both unclassified and classified, will own and manage the information system security program for Optiv + ClearShark and will report directly to the Senior Corporate Counsel. The ISSM is responsible for leading projects and operational tasks that apply new and existing technologies and solutions to solve business needs in the cybersecurity space. The ISSM works with other engineers, various groups, and operational support staff both within IT and other business units to provide and maintain solutions that meet business and technical requirements. The ISSM will assist in the development of procedures and runbooks; act as the subject matter expert in a variety of cybersecurity domains such as Identity and Access Management, Vulnerability Management, Endpoint Protection, Incident Response activities, etc.; and will provide tier two production support for responsible solutions.
How you’ll make an impact
- Develop, administer, and sustain a CMMC Program and Certification.
- Ensure NIST 800-171 compliance for all applicable corporate information systems.
- Lead the development and implementation of security solutions and process improvements.
- Lead the enhancement of key security solutions in the GRC, Security Operations, and IAM space.
- Ability to manage security vendors to resolve issues and maximize configurations.
- Lead the deployment, monitoring, troubleshooting, and changing of security solutions.
- Partner with IT and business colleagues to ensure proper security controls are included in new solutions.
- Research and evaluate the impact of new vulnerabilities, security alerts and threat intelligence bulletins.
- Participate in threat hunting and incident response events.
- Lead third-party risk management tasks such as conducting risk assessments for vendors and services.
- Build and maintain relationships with key customer's technical staff members and with internal stakeholders from IT, customer service and field operations.
- Share experience, knowledge, and ideas with management and co-workers to maintain a kind and respectful team-based environment.
- Promote a corporate culture that is committed to information security best practices.
- Participate in after-hours support, as needed, to respond to critical security incidents.
- Function with a high degree of integrity with an ability to keep information confidential.
- Develop, administer, and sustain RMF packages for classified systems IAW NIST 800-53, NISPOM, and ICD requirements.
- Perform audit log reviews and initiate incident response actions for any anomalous activity.
- Lead the vulnerability management program; perform vulnerability scans and prioritize and coordinate remediation actions.
- Assess systems and create baselines utilizing the DISA STIGs.
- Develop a Plan of Action and Milestones (POA&M) and work items to remediation.
- Participate in change control board meetings.
- Work in partnership with the Facility Security Officer (FSO) to meet NISPOM and NISP requirements.
What we’re looking for
- Bachelor’s degree in computer science and/or any related fields, Master’s Degree a plus.
- Minimum of 7+ years of relevant work experience related to cyber security.
- Must be a US Citizen and be able to obtain and maintain a Top Secret Security Clearance. Holding a current Top Secret clearance with SCI eligibility is a plus.
- Must have experience with several of the following: Microsoft, O365, Active Directory, Splunk, ServiceNow, SailPoint, Qualys, CASB, Prisma Access, Tenable, XSIAM, or other cybersecurity tools.
- Proficient across multiple operating systems such as Microsoft Windows, ESXi, Apple MacOS, and RedHat Linux.
- Familiarity with security best practices for cloud architectures (SaaS, IaaS, PaaS).
- Knowledge of securing cloud environments particularly Azure and AWS.
- Fundamental understanding of network protocols and network security.
- Knowledge of industry and Government frameworks such as NIST, CMMC, and RMF.
- Have experience with developing and sustaining Government accreditation packages within different Government frameworks, such as NISPOM, CMMC, JSIG, and ICD.
- Have experience reviewing audit logs and performing cybersecurity incident investigations.
- Experience with the DISA STIGs and performing STIG validations of different technologies.
- Detail-oriented with strong conceptual, analytical, problem solving, decision making and planning skills.
- Knowledge of modern software development lifecycles, includin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s