Information Systems Security Manager
Information Systems Security Manager
Location: Lexington Park, MD
Work Location: onsite
- You have 3–5 years of experience in cybersecurity operations, information security, or IT-related fields.
- You have knowledge of the Department of Navy and Naval Air Systems Command (NAVAIR), including digital infrastructure/environments and cybersecurity practices.
- You have experience in vulnerability management, incident response, and cybersecurity engineering.
- You have strong technical expertise in identifying and mitigating cybersecurity risks and vulnerabilities.
- You have working knowledge of Windows and Linux operating systems.
- You have a strong understanding of networking principles, including TCP/IP, WANs, LANs, and Internet protocols (e.g., SMTP, HTTP, FTP, POP, LDAP).
- You have familiarity with cybersecurity tools and technologies, including Splunk, ArcSight, Microsoft Sentinel, FortiSIEM, SwimLane, QRadar, and LogPoint.
- You have excellent written and verbal communication skills, with the ability to convey complex technical concepts to diverse audiences.
- You have the ability to work independently and collaboratively in a fast-paced, dynamic environment.
- You are willing to travel up to 20% as required.
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, Software Engineering, or a related technical discipline. Relevant certifications may be accepted in lieu of a degree.
- Active Secret clearance required, with the ability to obtain Top Secret/SCI eligibility.
- Working knowledge of Windows and Linux operating systems.
- IAM Level 2: CompTIA Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), CompTIA Network+, CompTIA Cybersecurity Analyst (CySA+), Certified Authorization Professional (CAP).
- Proficiency in using security tools such as Splunk, ArcSight, Microsoft Sentinel, FortiSIEM, SwimLane, QRadar, and LogPoint for monitoring, assessing, and reporting system security vulnerabilities.
- Hands-on experience with security monitoring, log analysis, threat intelligence, and digital forensics to identify and respond to system anomalies.
- Experience with defending against known attack vectors.
- In-depth knowledge of security frameworks, standards, and guides (e.g., RMF, NIST, CIS, STIGs, FIPS, etc.).