Information Systems Security Manager
CurrentPerform security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standardsLead and implement the Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF) for new and existing information systemsFacilitate development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acknowledgement Letters (RAL) and support Continuous Monitoring (CONMON)Supervise configuration management of assigned systems; auditing systems to ensure security posture integrityLead staff with assessments and test/analysis data to document state of compliance with security requirementsConduct risk assessments and investigations, implement appropriate risk mitigations, and coordinate incident response activitiesConduct periodic hardware/software inventory assessmentsCollaborate with the appropriate government customers, suppliers, and company personnel to implement protective mechanisms and to ensure understanding of and compliance with cybersecurity requirementsSupervise the development and deployment of program information security for all program systems to meet the program and enterprise requirements, policies, standards, guidelines and proceduresHandle assigned team to facilitate effective execution of Risk Management Framework (RMF)Lead and perform security compliance continuous monitoringCoordinate and participate in security assessments and auditsPrepare, review, and present technical reports and briefingsIdentify root causes, prioritize threats and recommend and/or implement corrective actionExplore the enterprise and industry for evolving state of industry knowledge and methods regarding information security best practices