Information Systems Security Manager - 3695315
TCGAbout the role
You've stumbled upon the rare B Corp government contractor! At TCG, we aim to prove that businesses can be good to their employees and responsible to their community while being profitable. We're an award-winning IT solutions provider to the Federal government seeking an Information Systems Security Manager to join our team.
US Citizenship is required for this role. In addition, the selected applicant must submit to a government background investigation and be favorably adjudicated before their first day.
This position is primarily remote but may require occasional in-person meetings for critical needs with advanced notice. The selected applicant must live within commuting distance of Washington, D.C.
The Information Systems Security Manager may lead and participate in the performance of security risk assessments, system threat assessments, vulnerability assessments, and penetration analyses of facilities, and computer networks; development and preparation of security plans, vulnerability assessments, and other plans; evaluation of information system and network access control, data integrity, and system virus and worm countermeasures associated with data processing, LAN, and WAN systems; use of state-of-the-art security evaluation and assessment technology, techniques, and tools.
RESPONSIBILITIES:
- Oversee the implementation and maintenance of security controls in alignment with NIST 800-53, ensuring the protection of organizational information systems.
- Conducts risk assessments and develops security plans based on NIST RMF and related publications.
- Maintain a strong understanding of current and emerging security threats and vulnerabilities, and how they relate to NIST guidelines
- Researches, develops, coordinates, maintains, and ensures compliance with end-user and technical security policies, standards, and procedures, including the System Security Plan (SSP), Incident Response Plan, and Disaster Recovery/COOP/Contingency Plan.
- Coordinates with the security and policy committee members to ensure that developed security policies and standards are technically sound and aligned with business needs.
- Serves as an authority for responding to policy issues and providing correct interpretation that maintains the security and integrity of the organization's security environment while meeting business objectives.
- Examines and reports on policy and standard compliance for computing platforms, operating systems, and networks.
- Specifies technical security requirements for new application developments; assesses the security impact of proposed system changes; coordinates with systems developers and engineers to configure, test, and deploy implemented system security solutions.
- Performs or oversees the performance of day-to-day security operations including, but not limited to, monitoring of audit logs and Intrusion Detection/Prevention devices, and ensuring effective tracking and reporting mechanisms are in place.
- Assists with network vulnerability "controlled penetration testing" assessments.
- Assist with activities associated with responding to a security-related incident or disaster recovery/business continuity.
- Prepares action plan and monitors corrective measures to maintain an adequate level of security to meet audit and regulatory requirements. Ensures that IA or IA-enabled software and hardware comply with appropriate security configuration guidelines. Ensures proper virus, malware, etc, protections are properly applied and maintained.
- Supports and maintains organization-wide information security training and awareness programs.
- Researches and coordinates with other agencies to be current with computer viruses, hoaxes, and system vulnerabilities affecting the agency.
- Analyzes and defines security requirements to meet government-mandated security policies.
- Identifies, implements, and assesses common security controls.
- Gathers, organizes, and documents technical information about an organization's mission, goals, and needs; existing security products; and ongoing programs in the multi-level security arena.
- Performs risk analyses, including risk assessments.
REQUIRED EXPERIENCE & SKILLS:
- A minimum of 8 years of experience related to Information Assurance with 3 years of experience conducting security control assessments and authorizations, ensuring compliance wit
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s