Information System Security Officer (CMMC Compliance)
AvantorAbout the role
The Opportunity:
Under general supervision, develop and execute security controls, defenses and countermeasures to intercept and prevent internal or external attacks or attempts to infiltrate company email, data, e-commerce and web-based systems. Maintain hardware, software and network firewalls and encryption protocols. Administer cybersecurity policies to control physical and virtual access to systems. Perform network security audits and testing and evaluates system security configurations to ensure efficacy and compliance with policies and procedures. Conduct penetration testing and vulnerability assessments of applications, operating systems and/or networks. Provide information to management regarding impact on the business caused by theft, destruction, alteration or denial of access to information and systems.THE OPPORTUNITY:
NuSil is seeking an Information System Security Officer to develop & administer a CMMC compliant information systems security program in support of our high-performance silicones business serving the Aerospace & Defense industries.
WHAT WE'RE LOOKING FOR (EDUCATION): Bachelor's degree with three years of Information Security or related experience. In lieu of a degree, an additional four years of applicable work experience may be substituted.
CERTIFICATIONS: CCP, CCA, CISSP, CISM or CISA preferred
EXPERIENCE: Must have detailed knowledge of Cybersecurity Maturity Model Certification (CMMC) and/or NIST SP 800-171 with demonstrated experience in compliance assessment and risk management. Working knowledge of the National Industrial Security Program Operating Manual (NISPOM) and Defense Federal Acquisition Regulation Supplement (DFARS) preferred.
THOSE NECESSARY TO PERFORM THE JOB COMPETENTLY:
Must be a US Citizen
Must have and be able to maintain an Active U.S. Government security clearance.
Bachelor's degree (Information Security, Computer Science, or related field) with three years of Information Systems Security, Cybersecurity or related experience.
Demonstrated understanding of secure information system design, implementation and maintenance is required and strong knowledge of continuous monitoring and risk management/assessment practices.
Excellent verbal and written communication. Strong interpersonal skills as required to effectively collaborate with customers, cybersecurity professionals and fellow associates.
PREFERRED QUALIFICATIONS:
Bachelor’s degree in information security, computer science, or a related field.
Minimum of three years of experience in information security, with a focus on compliance and risk management.
Extensive experience with NIST SP 800-171 and CMMC requirements.
Strong knowledge of continuous monitoring and risk management/assessment practices.
Experience with System Security Plan (SSP) and Plan of Action & Milestones (POA&M) management.
Experience with Controlled Unclassified Information (CUI) data protection requirements.
Relevant certifications such as CCP, CCA, CISSP, CISM, or CISA are preferred.
Candidate must have and be able to maintain an Active U.S. Government security clearance at the Secret level with a background investigation date within the last 6 years.
Ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business needs.
Possess understanding and working knowledge of the National Industrial Security Program Operating Manual (NISPOM) and Defense Federal Acquisition Regulation Supplement (DFARS)
Excellent analytical, problem-solving, and communication skills.
Ability to work independently and as part of a team.
Must be able to adapt to a fast-paced and challenging work environment and must demonstrate exceptional interpersonal and leadership skills.
Demonstrated positive working relationships with internal and external customers.
Ability to work independently and follow projects through to completion.
Ability to maintain flexibility to deal with changing priorities and deadlines.
HOW YOU WILL THRIVE AND CREATE AN IMPACT (MAJOR JOB DUTIES & RESPONSIBILTIES):
The Information System Security Officer (CMMC Compliance) is responsible for tracking, managing, and overseeing compliance with Cybersecurity Maturity Model Certification (CMMC) requirements. This role includes managing the System Security Plan (SSP), Plan of Action and Milestones (POA&M), conducting cybersecurity risk asse
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Information Security Architecture & Engineering Lead
Gainwell Technologies
$135,800/yr
Intern, Information Technology
Biogen
Document Management Specialist I - Health Information Services/Information Solutions
Medical University of South Carolina