Cybersecurity Systems Engineer / ISSM
1 мес. назад
USASeniorOnsite
information security managementrisk managementcompliance management
Lead the organization's information security, governance, risk, and compliance programs, ensuring confidentiality, integrity, and availability of corporate and customer information systems.
О компании
- Be Challenged and Make a Difference In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At , we provide unmatched value to our customers and employees through innovative solutions and an engaging culture. The Cybersecurity Systems Engineer / Information Systems Security Manager (ISSM) provides leadership for the organization's information security, governance, risk, and compliance program. The role is responsible for protecting the confidentiality, integrity, and availability of corporate and customer information systems while aligning cybersecurity practices with business objectives, contractual obligations, and regulatory requirements. This position serves as the organization's primary
Требования
- Bachelor’s degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent combination of education and experience).
- 7+ years of progressive cybersecurity or information assurance experience.
- Experience serving as an ISSM, ISSO, IA Manager, or similar role.
- Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, DFARS 252.204-7012, CMMC, and DoD cybersecurity requirements.
- Experience developing SSPs, POA&Ms, security policies, standards, and procedures.
- Experience supporting security audits and assessments.
- Excellent written, verbal, and presentation skills.
- Ability to effectively communicate cybersecurity concepts to both technical and non-technical audiences.
- Ability to work at a computer for extended periods.
- Occasionally lift up to 25 pounds.
- Ability to obtain and maintain a U.S. Government security clearance.
- Active Secret clearance required; Top Secret and SCI eligibility is desirable.
Будет плюсом
- CISSP certification (or ability to obtain within an agreed timeframe).
- Certifications such as CISM, Security+, CASP+, CCSP, CGRC (formerly CAP), CEH.
- Experience with Microsoft 365 Government, Microsoft Defender, Microsoft Entra ID (Azure AD), Intune, and Microsoft Purview.
- Experience with SIEM, EDR, vulnerability scanning, and cloud security platforms.
- Experience supporting CMMC Level 2 or 3, ISO 27001, and/or ISO 20000 compliance programs.
- Experience with developing policies and procedures and passing DCSA audits.
- Experience supporting Defense Industrial Base (DIB) contractors.
- Experience supporting classified and unclassified information systems.