Tyto Athene, LLC
Information Systems Security Manager (ISSM) - SME
Tyto Athene, LLC, Arlington, Virginia, United States, 22201
Job Description
Tyto Athene is searching for an
Information System Security Manager (ISSM) - SME
to support a customer in Arlington, VA. The ISSM shall perform daily tasks involving system compliance validation, vulnerability management response coordination, data transfer (Low to High and High to Low), and ongoing audit review and correlation, as well as general support to ongoing continuous monitoring activities. The ISSM's primary function will be to provide oversight for a team of information system security officers for the organization’s overall cybersecurity strategy. The ISSM supports the implementation of robust cybersecurity measures that proactively identify and mitigate cyber threats. This exciting role requires an appetite for learning, superior attention to detail, the ability to meet tight deadlines, great organizational skills, and the ability to work in a highly collaborative environment.
Responsibilities:
Ensure that information system security requirements are addressed during all phases of an information system security lifecycle. Assist with the creation of operational Operations and Maintenance (O M) checklists to maintain the service (daily, weekly, monthly, and yearly O M checklists); build Tactics, Techniques, and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists. Develop and continuously update all Security Authorization documentation as required by the customer and applicable Risk Management Framework (RMF) packages using the current approved templates, forms, regulations, and methods. These documents include, but are not limited to SSP, SAR, Contingency Plan, IR Plan, CM Plan, SOPs, POAMs Remediation Plans. Assist ISSM/ISSO/ISSE with the Integration/Development of new techniques to improve Confidentiality, Integrity, and Availability for networks/systems operating at various classification levels. Ensure that security improvement actions are evaluated, validated, and implemented as required. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Identify information technology (IT) security program implications of new technologies or technology upgrades. Participate in an information security risk assessment during the Security Assessment and Authorization process. Participate in the development or modification of the computer environment cybersecurity program plans and requirements. Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations. Recognize a possible security violation and take appropriate action to report the incident, as required. Track audit findings and recommendations to ensure that appropriate mitigation actions are taken. Support the development of policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies. Able to perform self-sustaining and work with little to no oversight. Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes. Required:
Bachelor’s degree in Computer Science, Information Technology, or related field 8 years of relevant experience Experience with Authority to Operate (ATO) process, continuous monitoring, POA Ms, Security Authorizations (SA), NIST 800-37, NIST 800-53 Rev4/ Rev5, NSM 8 and working with System Owners (SO) Familiarity with information system security principles of NIST 800-171 In-depth knowledge of NIST special publications, CNSS policies and instructions Ability to review, analyze, and interpret technical procedures against customer security requirements Strong communication skills, both written and verbal Desired:
Understanding experience with eMASS or Xacta is a PLUS FedRAMP process Cloud environments (Azure, AWS) experience preferred Certified Information Security Manager (CISM) (optional but highly recommended)
Clearance:
Active TS/SCI clearance required
Certification: DoD 8570 IAM/IAT Level II certification.DoD Directive 8570.01-M for Information Assurance Technician Level III within 6 months of the date of hire This will change to a DoD 8140 equivalent once a DISA 8140 policy is released.
Location: This is an on-site role with expectations of being on the client site in Arlington, VA five days a week.
Additional Information
After several strategic acquisitions in 2021, Tyto Athene has experienced enormous opportunity and growth. Aside from being the leading provider of mission-focused IT and Cyber services and solutions to critical U.S. government agencies, Tyto is well-positioned to meet the growing demand for network modernization requirements across the federal enterprise.
Our employees are the key to the innovation that has made Tyto a success. We provide an environment that is geared to reward potential, innovation, and teamwork. If you would like to unleash your creativity and your career -- it's time to join Team Tyto!
Tyto Athene is searching for an
Information System Security Manager (ISSM) - SME
to support a customer in Arlington, VA. The ISSM shall perform daily tasks involving system compliance validation, vulnerability management response coordination, data transfer (Low to High and High to Low), and ongoing audit review and correlation, as well as general support to ongoing continuous monitoring activities. The ISSM's primary function will be to provide oversight for a team of information system security officers for the organization’s overall cybersecurity strategy. The ISSM supports the implementation of robust cybersecurity measures that proactively identify and mitigate cyber threats. This exciting role requires an appetite for learning, superior attention to detail, the ability to meet tight deadlines, great organizational skills, and the ability to work in a highly collaborative environment.
Responsibilities:
Ensure that information system security requirements are addressed during all phases of an information system security lifecycle. Assist with the creation of operational Operations and Maintenance (O M) checklists to maintain the service (daily, weekly, monthly, and yearly O M checklists); build Tactics, Techniques, and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists. Develop and continuously update all Security Authorization documentation as required by the customer and applicable Risk Management Framework (RMF) packages using the current approved templates, forms, regulations, and methods. These documents include, but are not limited to SSP, SAR, Contingency Plan, IR Plan, CM Plan, SOPs, POAMs Remediation Plans. Assist ISSM/ISSO/ISSE with the Integration/Development of new techniques to improve Confidentiality, Integrity, and Availability for networks/systems operating at various classification levels. Ensure that security improvement actions are evaluated, validated, and implemented as required. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Identify information technology (IT) security program implications of new technologies or technology upgrades. Participate in an information security risk assessment during the Security Assessment and Authorization process. Participate in the development or modification of the computer environment cybersecurity program plans and requirements. Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations. Recognize a possible security violation and take appropriate action to report the incident, as required. Track audit findings and recommendations to ensure that appropriate mitigation actions are taken. Support the development of policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies. Able to perform self-sustaining and work with little to no oversight. Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes. Required:
Bachelor’s degree in Computer Science, Information Technology, or related field 8 years of relevant experience Experience with Authority to Operate (ATO) process, continuous monitoring, POA Ms, Security Authorizations (SA), NIST 800-37, NIST 800-53 Rev4/ Rev5, NSM 8 and working with System Owners (SO) Familiarity with information system security principles of NIST 800-171 In-depth knowledge of NIST special publications, CNSS policies and instructions Ability to review, analyze, and interpret technical procedures against customer security requirements Strong communication skills, both written and verbal Desired:
Understanding experience with eMASS or Xacta is a PLUS FedRAMP process Cloud environments (Azure, AWS) experience preferred Certified Information Security Manager (CISM) (optional but highly recommended)
Clearance:
Active TS/SCI clearance required
Certification: DoD 8570 IAM/IAT Level II certification.DoD Directive 8570.01-M for Information Assurance Technician Level III within 6 months of the date of hire This will change to a DoD 8140 equivalent once a DISA 8140 policy is released.
Location: This is an on-site role with expectations of being on the client site in Arlington, VA five days a week.
Additional Information
After several strategic acquisitions in 2021, Tyto Athene has experienced enormous opportunity and growth. Aside from being the leading provider of mission-focused IT and Cyber services and solutions to critical U.S. government agencies, Tyto is well-positioned to meet the growing demand for network modernization requirements across the federal enterprise.
Our employees are the key to the innovation that has made Tyto a success. We provide an environment that is geared to reward potential, innovation, and teamwork. If you would like to unleash your creativity and your career -- it's time to join Team Tyto!