Information System Security Manager
CurrentResponsibilities Include:a. Developing, maintaining, and overseeing the system security program and policies for theirassigned area of responsibility.b. Ensuring compliance with current cyber security policies, concepts, and measures whendesigning, procuring, adopting, and developing a new system.c. Ensuring the fulfillment of IO data requirements (e.g., storage, processing, Assured File Transfer(AFT), incident response, collection, dissemination, and disposal).d. Developing and implementing an effective system security education, training, and awarenessprogram.e. Maintaining a working knowledge of system functions, security policies, technical securitysafeguards, and operational security measures.f. Possessing sufficient experience, commanding adequate resources, and being organizationallyaligned to ensure prompt support and successful execution of a robust system security program.g. Completing training identified in ISSM Required Training Table within 6 months of appointment.h. Monitoring all available resources that provide warnings of system vulnerabilities or ongoingattacks and reporting them as necessary.i. Developing, documenting, and monitoring compliance with and reporting of the clearedcontractor facility’s system security program in accordance with Cognizant Security Activity (CSA)guidelines for management, operational, and technical controls.j. Performing risk assessments and documenting results in a RAR and keeping the risk assessmentcurrent throughout the acquisition/development portion of the system life cycle.k. Developing, maintaining, and updating, in coordination with all system stakeholders, POA&Ms inorder to identify system weaknesses, mitigating actions, resources, and timelines for correctiveactions. Entries in the POA&M will be based on vulnerabilities and recommendations identifiedduring assessments.