Posted 1 month ago
Top Secret
Unspecified
Polygraph
IT - Security
Springfield, VA (On-Site/Office)
Title
Information Systems Security Manager - Intermediate
Full-Time/Part-Time Full-Time Description
RiVidium Inc. is seeking a dedicated and experienced Information Systems Security Manager (ISSM) to lead our security program. In this critical role, you will be responsible for the overall security posture of our information systems, ensuring the secure and reliable transfer of time-sensitive data across multiple classified networks. You will play a key part in our mission-critical cross-domain operations by developing, implementing, and maintaining a comprehensive information security program.
Key Responsibilities
This position is currently accepting applications.
Information Systems Security Manager - Intermediate
Full-Time/Part-Time Full-Time Description
RiVidium Inc. is seeking a dedicated and experienced Information Systems Security Manager (ISSM) to lead our security program. In this critical role, you will be responsible for the overall security posture of our information systems, ensuring the secure and reliable transfer of time-sensitive data across multiple classified networks. You will play a key part in our mission-critical cross-domain operations by developing, implementing, and maintaining a comprehensive information security program.
Key Responsibilities
- Security Program Management: Design, implement, and maintain a comprehensive cybersecurity program, including security architecture, policies, and procedures, to protect information systems and data.
- Risk Management: Conduct regular risk and vulnerability assessments to identify, analyze, and mitigate potential security threats. Develop and implement remediation plans to address identified vulnerabilities and security incidents.
- Compliance and Authorization: Ensure all information systems comply with government and Department of Defense (DoD) cybersecurity regulations, including the Risk Management Framework (RMF). Lead and manage the Assessment and Authorization (A&A) process to obtain and maintain Authority to Operate (ATO) approvals.
- Continuous Monitoring: Oversee continuous monitoring activities to ensure ongoing compliance with cybersecurity policies, detect security events, and respond to threats in a timely manner.
- Leadership and Collaboration: Serve as the primary cybersecurity technical advisor to senior leadership and system owners. Collaborate with security teams and key stakeholders to integrate security requirements across all operational and system lifecycle phases.
- Incident Response: Develop, lead, and coordinate incident response activities, including investigation, reporting, and system-level responses to security incidents and unauthorized disclosures of information.
- Security Awareness and Training: Develop and implement security awareness and training programs to ensure personnel understand and adhere to cybersecurity policies, procedures, and best practices.
- Security Clearance: Active Top Secret clearance.
- Security Certification: DoD Information Assurance Technical (IAT) Level III (DoD 8140) certification (CISSP or CISM preferred).
- Polygraph: Ability to successfully obtain and maintain a government polygraph (post-hire requirement).
- Risk Management Framework (RMF): Extensive experience with RMF processes, including the development and management of accreditation packages for Assessment and Authorization (A&A).
- Compliance Knowledge: Strong working knowledge of NIST, DoD, and other applicable compliance frameworks governing data security and classified data transfer.
- Cross-Domain Solutions (CDS): Hands-on experience with cross-domain solutions and a solid understanding of CDS concepts and environments.
- Cloud Certifications: CompTIA Cloud+, CASP+, AWS Certified Cloud Practitioner, or similar cloud-focused certifications.
- Cloud Architecture Experience: Experience designing and supporting cloud architectures and large-scale deployments (5+ years preferred).
- Technical Documentation: Experience authoring technical point papers related to cross-domain solutions.
- Security Design & Engineering: Experience in the security design and engineering of cross-domain solutions.
- Training & Mentorship: Experience training cross-domain engineers on new technologies and security practices.
This position is currently accepting applications.
group id: RTX15cf25