The Information Assurance Manager maintains compliance of US government classified information systems, IAW NISPOM standards, Joint Special Access Program Implementation Guidance (JSIG), Risk Management Framework (RMF), and Information Assurance at Bell Helicopter.
Position Responsibilities:
1. Serve as Information Assurance Manager for classified computers in DoD and Intelligence Community computing environments.
2. Maintain day-to-day security posture and continuous monitoring of IS including security event log review and analysis.
3. Ensure system security measures comply with applicable government policies. Provide configuration management and accurately assess the impact of modifications and vulnerabilities for each system.
4. Maintain thorough understanding of NIST 800-53 controls, and determine which controls are applicable to the application, as well as document implementation in Security Controls Tractability Matrix (SCTM).
5. Provide support to the Information Systems Security Manager (ISSM) for maintaining appropriate operation information assurance (IA) posture for programs.
6. Conduct reviews and technical inspections (as prescribed by the ISSM) to identify and mitigate potential security weaknesses, and ensure that all security features applied to a system are implemented and functional.
7. Assist the ISSM in monitoring and resolving Plan of Action and Milestones (POA&M) to mitigate system vulnerabilities on assigned Information Systems.
8. Draft and/or prepare and maintain security Assessment and Authorization documentation (e.g., IA SOP, SSP, MSSP, RAR, SCTM).
9. Assist with the operational, sustainment, evaluation, and modernization of existing Security Management Systems (i.e. access control, digital imaging, and surveillance), as required.
Education Requirements:
Bachelor’s Degree is required. Preferred areas of study are: Information Technology, Information Assurance, Computer Information Systems, or Criminal Justice.
Position Requirements:
Experience as an IAM/ISSM implementing NISPOM Chapter 8, JAFAN 6/3, DCID 6/3, ICD 503, and/or JSIG IS requirements.
Must have a current CISSP certification per DoD Directive 8570.1.
Have an active TOP SECRET security clearance and ability to SAP/SAR access.
Experience with both Windows and Linux operating environments.
Experience in a research and development environment.
Experience in developing external customer relationships and communications (e.g.DSS, Army, Navy, AF, NRO, DIA, and DARPA)
Must be able to maintain awareness of upcoming customer / government driven changes and challenges and suggests approaches to meet those challenges
Must be customer/mission focused
Excellent time management skills are required.
Must meet DoD 8570.01M requirement for an IAMl II
Preferred:
Familiarity with conducting vulnerability scans
Familiarity with the ODAA Baseline Standard requirements, Joint Special Access Program (SAP) Implementation Guide (JSIG) and Risk Management Framework (RMF)