Information Systems Security Manager (ISSM)
U.S. Citizenship Required. Ability to qualify for a TOP SECRET US Department of Defense security clearance required. Candidate must ultimately be SAP and SCI program eligible.
This position is in-person.
Toyon is seeking an experienced Information Systems Security Manager (ISSM) for our fast-paced Department of Defense environment. The ideal applicant would have recognized success working on classified computing systems under the NISPOM Rule 32 CFR Part 117, the DCSA Assessment and Authorization Guide (DAAG), Joint Special Access Program Implementation Guide (JSIG), and ICD Standards.
At Toyon, we pride ourselves on functioning as a cooperative and professional security team based on trust. The successful candidate will continually work to develop positive and productive relationships as they support our security program. Excellent interpersonal skills are required. Team members must have the ability to react quickly and provide authoritative security guidance to employees.
Responsibilities:
- Primary technical support of classified system hardware and software MUSAs, ISOLANs, and WANs
- Apply diagnostic techniques to identify problems, investigate causes, and recommend solutions
- Coordinate requirements for new computer systems, acting as a liaison between technical staff and IT
- Harden and perform certifications on new classified systems
- Provide Security configuration advice to various Program Leadership
- All aspects of audits and vulnerability scanning, ensuring systems are being operated securely and computer security policies and procedures are implemented
- Maintain and audit SIPRnet and various classified Customer networks
- Perform self-inspections and developing procedures
- Create and maintain Risk Management Framework (RMF) materials
- Assist with DCSA and Special Access Program Inspections as needed
- Obtain and maintain Authorizations to Operate (ATOs)
- Clearly articulate technical information to both technical and nontechnical audiences
- Contribute to Cybersecurity Maturity Model Certification (CMMC) monitoring