Cybersecurity Manager/ISSO
Job Description
Lead and oversee cybersecurity operations, RMF authorization, and risk management for a large DoD/USAF mission-support program (US BICES-X) at General Dynamics Information Technology, onsite at Andrews AFB, MD.
Responsibilities
- Articulate the value of information security to stakeholders at all levels.
- Provide guidance to senior leadership on changes affecting cybersecurity posture, risk, and compliance.
- Coordinate security inspections, testing, and reviews with a geographically dispersed team.
- Develop, issue, and maintain security plans, instructions, SOPs, and guidance for the operating environment.
- Report security and compliance matters to government leaders, operations, and ISSO personnel.
- Brief senior government and GDIT leadership on cybersecurity metrics, risk indicators, and trends.
- Oversee policy standards and ensure implementation approaches align with requirements.
- Guarantee deployment of security requirements, policies, and procedures per approved baselines.
- Provide remediation guidance to staff and ensure regulatory, contractual, and policy compliance.
- Support policy updates using NIST 800-53, best practices, and evolving compliance needs.
- Align IT security priorities with the broader cybersecurity strategy and evaluate new technologies.
- Support acquisition activities in accordance with DoW/USAF supply chain risk practices.
- Assist in managing cybersecurity budgets, staffing, and contractual objectives.
- Lead cybersecurity activities for a large program and support policy dissemination and audits.
- Assist government ISSMs in preparing ATO, ATC, IATT, POA&M, and RMF/ISSO documentation as required.
- Assist in developing and executing required ST&V plans.
- Produce ISSO materials, including project briefs and RMF action status for DoW IT packages.
- Analyze system architecture, conduct security impact assessments, and propose risk mitigation strategies.
- Provide security design oversight for build processes of servers, services, and endpoints.
- Ensure hosting facility ATO compliance for dependent systems.
- Implement and enforce robust cybersecurity and vulnerability management practices.
- Conduct compliance and vulnerability audits using STIG Viewer, DISA SCAP, eMASSter, ACAS, and ESS Policy Auditor across Linux, Windows, Cisco, Juniper, VMware, and related technologies.
- Execute Continuous Monitoring activities, including creation, tracking, and closure of POA&Ms and risk acceptances.
- Share threat information with government leadership and cybersecurity teams to support risk decisions.
- DoW RMF execution in accordance with DoW 8510, including control validation and test coordination.
- Coordinate with AFRL, USAF, and other agencies for audits, inspections, CVAs, ST&Vs, and CCRI events as required.
- Assess change requests across firewall, systems, and networks to determine organizational risk.
- Maintain information system integrity by enforcing security policies and vulnerability monitoring.
- Provide leadership and mentorship to junior technical staff.
- Maintain current knowledge of relevant security technologies.
- Process support tickets using approved ITSM systems.
- Perform other cybersecurity tasks as outlined in AFI 17-101 sections 3.12 through 3.14 or as directed by the Cybersecurity Lead.
Requirements
- More than 10 years of relevant cybersecurity experience.
- Bachelor's degree; equivalent experience may substitute.
- Active TS/SCI clearance.
- IAM Level III certification (CISSP, CISM, or GSLC).
- Strong background in RMF and eMASS is required.
- Solid understanding of cybersecurity principles, methodologies, and practices.
- Extensive knowledge of NIST, DoW, and AF cybersecurity orders/directives.
- Team-oriented and capable of collaborative work in a structured environment.
- Excellent multitasking abilities in fast-paced settings.
- Highly organized, self-directed, and detail-oriented.
- Outstanding written and verbal communication skills.
- High integrity, adaptability, resilience, and initiative.
Technologies
- STIG Viewer, DISA SCAP, eMASSter, ACAS, ESS Policy Auditor
- Linux, Windows, Cisco, Juniper, VMware
- RMF, NIST 800-53, DoW 8510, AFI 17-101
Work Requirements
- Experience level: 10+ years in related cybersecurity fields.
- Travel: 10 - 25 percent.
- Citizenship: U.S. Citizenship Required.
Compensation
- Salary range: USD 124,093 - 165,600 per year. Final compensation based on experience, location, and contractual requirements.
- Benefits and total rewards information available.
Preferred Qualifications
- Experience managing personnel (up to 10 staff).
- Ability to prioritize multiple tasks in dynamic, fast-paced environments.
- Strong communication skills across individual, team, and leadership levels.
- Additional role-specific certifications as required.
- ITIL Foundations certification.