Jobs and Careers
AC

Information System Security Manager (ISSM)

Accenture Federal Services
United Statesfull_timeVerifiedPosted 16 Dec 2024
💰 $243,100/yr($126,300/yr$243,100/yr)

About the role

At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations.   Join Accenture Federal Services to do the work you love in an inclusive, collaborative, and caring community, where you can be empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more.   Join us to drive positive, lasting change that moves missions and the government forward!  

Job Description:

Accenture Federal Services is seeking an Information System Security Manger (ISSM) to serve as the Subject Matter Expert (SME) responsible for the management and technical administration of secure cloud environments. The ISSM will oversee day-to-day information system security operations, resolve complex problems, and develop innovative solutions to meet unique security requirements. The ISSM will lead a team of cybersecurity professionals to ensure adherence to all aspects of a rigorous Risk Management Framework (RMF) compliance program as stipulated by NISPOM/DAAPM, JSIG, ICD 503, STIGs and associated NIST publications. The ISSM will also be responsible for maintaining multiple Authorization to Operate (ATO) approvals for several environments by adhering to the Risk Management Framework (RMF). This position supports cybersecurity efforts throughout the RMF process, to include the development and management of System Security documentation, Plans of Action and Milestones (POA&Ms), assessing and auditing systems security controls, and continuous monitoring of controls.

Responsibilities:

Responsibilities will include the following: 

  • Demonstrate leadership and decision-making skills to develop and manage a team to implement the strategy for enterprise security within assigned systems. 
  • Develop and maintain information system security implementation policy and guidelines of network security using the Risk Management Framework (RMF) and other relevant industry and governmental standards, such as the Joint Special Access Program Implementation Guide (JSIG). 
  • Prepare and review Authorization to Operate (ATO) documentation to include System Security Plans (SSPs), the Plan of Action and Milestones (POA&M), Risk Assessment Reports, Assessment and Authorization (A&A) packages, and security control implementations. 
  • Ability to successfully interface with other teams, other security disciplines (industrial security, physical security, special programs security, etc.), program personnel, and government security representatives. 
  • Review and create mitigation reports from compliance and vulnerability scanning tools (Nessus, SCAP, ACAS, SCC, etc.). 
  •  Coordinate with Security Control Assessor (SCA) and Authorizing Official (AO) on approval of external information systems (e.g. interconnected system with another organization).
  • Ensure approved procedures are used for sanitizing and releasing system components and media. 
  • Maintain a repository of all security authorizations for program systems. 
  • Ensure proper measures are taken when an IS incident or vulnerability is discovered. 
  • Ensure CM policies and procedures for authorizing the use of hardware/software are followed. 
  • Serve as a voting member of the Change Control Board (CCB).

Basic Qualifications:

  • Minimum 10 years related experience in Information Systems, Computer Science, or related field. Additional relevant experience, training, and/or certification/s may be considered in lieu of degree. 
  • Experience in SAP and Collateral Information Systems (IS) Security. 
  • Experience in Cloud-based Information Systems (IS) Security. 
  • Meet DoD 8570/8140 Certification Requirements for IAM Level II 
  • Detailed understanding of the Risk Management Framework (RMF), NIST, ICD, DoD and CNSS standards. 
  • Hands on experience with DISA Security Technical Implementation Guide (STIG) implementation and management. 
  • Experience with eMASS. 
  • Understanding of Sensitive Compartmented Information Facility (SCIF) standards. 
  • Knowledge of secure coding practices and vulnerability/quality scanning tools (e.g., Fortify, SonarQube). 
  • Must be able to work well within a team environment and able to adapt quickly to change. 
  • Good writing and verbal presentation skills. Customer focused, excellent communicator.

Bonus Points If You Have: 

  • Security hardening scripting/automation experience.
  • Familiarity with network technologies (LAN & WAN) and best pra

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Accenture Federal Services

View company profile →