CybersecurityJobs.io
← Back to all jobs

Job Description

Bravura Information Technology Systems is seeking a Cybersecurity Lead / Information Systems Security Manager (ISSM) to support program and system cybersecurity activities at Redstone Arsenal, AL. In this onsite role, you will lead RMF Assess and Authorize support and help execute authorization activities, vulnerability management, and CS/IS systems engineering compliance aligned to NIST 800-series controls and DoD/Army cybersecurity requirements.

Role overview

You will be responsible for the cybersecurity of a program, organization, system, or enclave. The position includes acting as a primary point of contact for CS and IS Systems Engineering (ISSE) issues, guiding CS execution across system security architecture, and coordinating efforts tied to ATO/ATC/IATT processes and incident coordination.

Responsibilities

  • Lead cybersecurity/ISSM execution, including RMF Assess and Authorize support and security documentation such as SSP, PPSM, and POA&M.
  • Own vulnerability management, including security artifact support for authorization, and coordinate incident-related activities in alignment with program expectations.
  • Maintain network security and authorization for mission network operations by controlling connections, user accounts, and access privileges, and by collaborating with the security team to identify, resolve, and report vulnerabilities and incidents.
  • Support systems engineering and program execution by maintaining adequate security expertise for input to systems engineering, software design and integration, testing, and training, while complying with applicable regulations, policies, and guidance.
  • Ensure CS design, engineering, and implementation comply with required NIST 800 Series CS controls, including identification and implementation of CS and CS-enabled IT products IAW NIST 800 Series.
  • Design, engineer, and implement technical and non-technical security configuration throughout the system security architecture, including development of Threat Assessment, Vulnerability Assessment, and Risks Assessment documentation.
  • Ensure exceptions involving CS policy/requirement limitations, configuration changes, alternative engineering solutions, or discrepancies are approved by the Government Change Control Board (CCB) prior to implementation.
  • Submit Contractor’s Risk Management to support use of third-party, public domain, and Free and Open Source Software (FOSS) products, including SBOM where feasible, for Government CCB approval.
  • Obtain Government CS ISSM email approval at Engineering or CS TIM or CCB prior to use of Mobile Code IAW NIST SP 800-53.
  • Implement a software assurance program for software applications created on behalf of the Customer, applying best practices such as static code analysis, DISA APP DEV STIG implementation, OWASP Top 10 implementation, and NETCOM Software Assurance TTP while supporting RMF application development requirements.
  • Produce and maintain a Hardware Baseline Inventory IAW authoritative cybersecurity repository requirements using NIST SP 800-53 and NIST SP 800-160.
  • Develop and document a Vulnerability Management Plan (VMP) including control summary, IAVM process overview, IAVA implementation, and vulnerability monitoring.
  • Review and evaluate security patches and update system software for operating system and resident applications.
  • Prepare an IAVM Test Report specifying information assurance and security test and scans, patch assessment details, and IAVA distribution, including CS scans using DISA approved CS scanning tools.
  • Produce, maintain, and deliver cybersecurity artifacts/documentation to support RMF A&A, including SSP, PPSM, and POA&M.
  • Identify and prioritize remediation for vulnerabilities and weaknesses discovered through CS testing, focusing on High and Moderate risks (formerly CAT I and CAT II) as the highest priority and proposing remediation for Low risk (formerly CAT III) items.

Requirements

  • Must fulfill at least one: Masters or Doctorate in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering, or Masters in Strategic Information & Cyberspace Studies (NDU CIC); OR completion of military training including 4C-FA26A (Network Systems Engineer), A-531-0009 (ISSM), ISSM (Advanced) Credential / Playlist, M09CHN1 (Communications Chief Course), M09D3H1 (ISSM), or M09DRX1 (MAGTF Communications Planner); OR Active certification as 8+ years.
  • 8+ years of experience.
  • Secret minimum; TS/SCI and SAP access as required by assigned systems/workspaces; CAC/NACI required.
  • DCWF 8140.

Key technologies

  • NIST 800 Series, NIST SP 800-53, NIST SP 800-160, RMF
  • SSP, PPSM, POA&M, ATO, ATC, IATT
  • DISA APP DEV STIG, OWASP Top 10, NETCOM Software Assurance TTP
  • SBOM, FOSS, Mobile Code
  • IAVM, IAVA, DISA approved CS scanning tools
  • Hardware Baseline Inventory, Vulnerability Management Plan (VMP), IAVM Test Report
  • static code analysis, CCB

Job category: Cybersecurity Engineer ISSM
Job type: Full Time
Location: Redstone Arsenal, AL (onsite)
Clearance level: Minimum Secret (active) Up to TS/SCI
Education/Certifications: DCWF 8140
Years of experience: 8+
Source selection: PFITSS

Similar Jobs