Job Requirements
San Diego, CA
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Job Description:
Position Overview ORBIS requires a highly skilled Information System Security Manager III (ISSM III) to provide senior technical leadership for the NSWC Corona CCAM contract. The ISSM III will act as the principal advisor on all matters, technical and otherwise, involving the security of assigned information systems. This key personnel position is critical to ensuring that ORBIS effectively manages and implements the RMF A&A processes for complex Navy systems, ensuring they achieve and maintain their Authority to Operate (ATO).
Core Responsibilities & Technical Execution:
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
ORBIS offers an excellent benefits package and a competitive salary in a professional atmosphere.
Position Overview ORBIS requires a highly skilled Information System Security Manager III (ISSM III) to provide senior technical leadership for the NSWC Corona CCAM contract. The ISSM III will act as the principal advisor on all matters, technical and otherwise, involving the security of assigned information systems. This key personnel position is critical to ensuring that ORBIS effectively manages and implements the RMF A&A processes for complex Navy systems, ensuring they achieve and maintain their Authority to Operate (ATO).
Core Responsibilities & Technical Execution:
- Take ownership of the cybersecurity posture for assigned NSWC Corona enclaves, networks, and Platform IT (PIT) systems.
- Lead the development, submission, and maintenance of complete RMF A&A packages in accordance with DoD Instruction 8510.01 and Navy RMF Process Guides.
- Oversee the work of assigned Information System Security Officers (ISSOs) and System Administrators to ensure the continuous implementation of security controls.
- Develop, review, and approve critical cybersecurity documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and Configuration Management Plans.
- Act as the primary technical liaison between system owners, the Navy Security Control Assessor (SCA), and the Authorizing Official (AO) for all package reviews and continuous monitoring activities.
- Manage the Enterprise Mission Assurance Support Service (eMASS) records for assigned systems, ensuring all artifacts, test results, and control implementations are accurate and current.
- Direct the formulation and management of complex Plan of Action and Milestones (POA&M) entries, working with engineering teams to identify mitigation strategies, resource requirements, and timeline estimates.
- Lead the response to cybersecurity incidents, directing forensic data collection, reporting to higher echelons, and implementing corrective actions to prevent recurrence.
- Conduct high-level reviews of Assured Compliance Assessment Solution (ACAS) scans, Security Technical Implementation Guide (STIG) checklists, and SCAP Compliance Checker (SCC) results.
- Enforce strict configuration management policies, reviewing and approving all proposed system changes, hardware additions, and software updates through the local Change Control Board (CCB).
- Develop and deliver cybersecurity awareness training and briefings for system users, privileged users, and leadership.
- Monitor Information Operations Conditions (INFOCONs), Cyber Tasking Orders (CTOs), and Information Assurance Vulnerability Alerts (IAVAs) to ensure rapid compliance and reporting.
- Clearance: Must possess an active, TS/SCI and be a United States citizen.
- Education: Master's degree in Computer Science, Information Technology, Cybersecurity, or an equivalent STEM discipline from an accredited university. (A Bachelor's degree with two additional years of highly specialized experience may be considered).
- Experience: A minimum of eight (8) years of dedicated cybersecurity experience coordinating with various organizational levels to manage and oversee information security program implementation.
- Leadership Experience: Proven experience managing cyber strategies, infrastructure, policy enforcement, emergency planning, and security awareness programs.
- Certifications: Must possess and maintain a current DoD 8140/8570 IAM Level III certification (e.g., CISSP, CISM, CISO, GSLC, or CASP+ CE).
- Comprehensive knowledge of NIST Special Publication 800-53 security controls, NIST 800-37 RMF guidelines, and Navy/NAVSEA specific cybersecurity business rules.
- Extensive hands-on experience utilizing eMASS for package submission and continuous monitoring.
- Experience working directly with Navy afloat platforms, hull, mechanical and electrical (HM&E) systems, or industrial control systems (ICS).
- Experience acting as an ISSM for a Navy command or echelon II/III organization.
- Familiarity with DevSecOps methodologies and integrating RMF into agile software development lifecycles.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
ORBIS offers an excellent benefits package and a competitive salary in a professional atmosphere.
group id: 90973602