Information Systems Security Manager jobs in United States
cer-icon
Apply on Employer Site
company-logo

MIT Lincoln Laboratory · 1 week ago

Information Systems Security Manager

MIT Lincoln Laboratory is a Federally Funded Research and Development Center focused on research in support of National Security. The role of Information Systems Security Manager involves managing cybersecurity support for various laboratory programs, leading a team of Information Systems Security Officers, and ensuring compliance with security policies and procedures.

BiotechnologyInformation TechnologyNational SecuritySecurity
check
Growth Opportunities
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Lead and provide direct supervision to assigned Information Systems Security Officers (ISSO)
Ensures work is prioritized consistently with work group and organization goals and objectives
Develop and maintain multiple System Security Plans (SSP) based on the Joint SAP implementation Guide (JSIG); ensuring systems are operated, maintained, and disposed of according to the approved SSP
Conduct security compliance audits and perform security vulnerability assessments on Laboratory information systems
Establish and maintain configuration management policies and procedures
Ensure users and ISSOs are subject to an effective information security education, training, and awareness program
Implement and test IT security policies/procedures as part of a fully integrated IT security program
Coordinate and participate in the investigation and mitigation of information system incidents
Assume ISSO responsibilities in the absence of the ISSO and respond to off-hour emergencies as needed
Recommend and manage budget and other resource allocations required to securely operate and maintain an organization's cybersecurity requirements
Provide technical documents, incident reports, findings from computer examinations, summaries, and other situational awareness information to key stake holders
Recognize a possible security violation and take appropriate action to report the incident, as required
Assist the Program Managers in the development and maintenance of System Security Plans (SSP) and associated artifacts such as the Plan of Action & Milestones (POA&M), Risk Assessment Report, and Continuous Monitoring Strategy
Lead and align information technology (IT) security priorities with the security strategy
Prepare for and participate in periodic organization compliance assessments
Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program
Achieve a passing score on all government inspections

Qualification

DoD cybersecurity experienceDoD 8570.01-M IAM III certificationNIST 800-53Risk Management FrameworkJoint SAP Implementation GuideVulnerability managementWindows ServerRed Hat Enterprise LinuxCommunication

Required

Active Top-Secret clearance with SCI eligibility
Must be a U.S. Citizen
Education: BS degree in Computer Science, Information Technology, Computer Information Systems, or related field
Experience: Minimum of six (6) years' experience within DoD cybersecurity, Special Access Programs (SAP), and Sensitive Compartmented Information (SCI) Programs
Leadership: Demonstrated capability in leading cross-functional teams and presenting ideas both in writing and orally within a collaborative team environment
Certification: Possess a DoD 8570.01-M IAM III baseline certification (e.g., CompTIA Security+) or ability to obtain within 6 months of hire
Security Frameworks: Demonstrated understanding of: NIST 800-53, Risk Management Framework (RMF), Joint SAP Implementation Guide (JSIG), Intelligence Community Directive (ICD) 503, National Industrial Security Program Operating Manual (NISPOM) Chapter 8, DoD Manual 5205.07 Volumes 1–4
Technical Knowledge: Experienced in auditing, configuration, and vulnerability management
Operating Systems: Experience with multiple OS environments such as Windows Server (2012, 2016, 2019, 2022), Windows 10/11, Red Hat Enterprise Linux, Ubuntu, and MacOS
Vulnerability Tools: Demonstrated experience with vulnerability scanning and auditing tools and processes
Communication: Excellent written and verbal communication skills

Preferred

Technical experience, coursework toward an undergraduate degree, or industry IT certifications may be considered in lieu of formal education or DoD security experience requirements
Experience with virtualization and cloud technologies
Ability to integrate information security requirements into the acquisition process, including baseline security controls, robust software quality processes, and multiple delivery routes for critical system elements
Technical experience securing networks and systems utilizing DISA STIGs and/or SRGs (highly desired)

Benefits

Comprehensive health, dental, and vision plans
MIT-funded pension
Matching 401K
Paid leave (including vacation, sick, parental, military, etc.)
Tuition reimbursement and continuing education programs
Mentorship programs
A range of work-life balance options
... and much more!

Company

MIT Lincoln Laboratory

company-logo
MIT Lincoln Laboratory is a federally funded research and development center chartered to apply advanced technology to problems of national security.

Funding

Current Stage
Late Stage
Total Funding
$0.25M
Key Investors
Patrick J. McGovern Foundation
2023-12-20Grant· $0.25M

Leadership Team

leader-logo
Israel Soibelman
Chief Strategy Officer
linkedin
Company data provided by crunchbase