About this role
Radiance Technologies is an employee-owned company with a generous benefits package that is unmatched among our peers. Employee ownership, generous 401K, full heath / dental / life / vision insurance benefits, challenging assignments, educational reimbursement, competitive salaries and work environment combine to make Radiance Technologies a great place to work and succeed.
Radiance is searching for an Information Systems Security Manager (ISSM) that will be responsible for a portfolio of programs, supporting information system life cycle activities. The qualified candidate will scope information systems for new programs, prepare Risk Management Framework packages, maintain compliance throughout the system authorization period, and participate in program close-out and de-certification activities. Additionally, the candidate must maintain the day-to-day security posture through the change management and continuous monitoring process of the information system, which may include security event log analysis and end user account audits. Work hours are normal business hours, however, occasional support during non-business hours may be required.
Responsibilities:
- Responsible for having a strong understanding of the NIST 800-53 controls and ensure system security measures comply with applicable government policies such as the DAAG, JSIG, NIST, etc.
- Oversee and implement a configuration management process that accurately assesses the impact of modifications to the information system.
- Conduct and participate in vulnerability assessments and continuous monitoring activities for the information systems under their purview.
- Responsible for performing incident response and business continuity activities.
- Obtaining and maintaining access to authorization platforms such as eMASS, Xacta, etc. to effectively manage authorizations packages for information systems under their purview.
- Prepare and maintain security authorization documentation (e.g. SOP, SSP, RAR, SCTM, POA&M)
- Responsible for tracking assessment findings and developing mitigation plans.
- Maintain the information assurance posture for programs the includes the periodic review of technical to ensure all applied security features are implemented and functioning as intended.
- Maintains awareness of changes driven by internal and external customers and develops a security compliant plan that meets corporate needs.
- Ability to manage information systems in a SCIF and SAPF environment and support remote location operations.
- Responsibilities also include those outlined in the DAAG and JSIG.
Required Skills:
- Experience in implementing security controls of the operating systems to include Active Directory, Group Policies, and SROs.
- Experience or strong working knowledge of standing up and maintaining customer networks such as SIPRNet, JWICS, etc.
- Experience with various information system security compliance tools, such as Splunk, ELK, Wireshark, Snort, SCAP, SCC Tool, STIG Viewer, ACAS, Nessus, etc.
- Working knowledge of information system environments to include MUSA, LAN, WAN, etc. and its information system components (i.e. switches, routers, operating systems, software, etc.)
- Possess a DoD 8570.1M compliant information system certification (e.g. Security+, CISSP, CISM, etc.)
Required Experience:
- 7+ years of experience in information systems security/information assurance implementing NISPOM Chapter 8, NIST, DAAG, ICD 503, and/or JSIG IS requirements
- Experience with Risk Management Framework (RMF), Interconnected Security Agreements (ISA), Network Security Plans, and Memorandums of Understanding/Agreement (MOU/A).
- Active TS/SCI clearance
Successful candidates will have the following behavioral competencies:
- Great attitude with high degree of customer focus.
- Flexible and adaptable to changing priorities.
- Solid problem solver.
- Reliable and committed to getting the job done (including after hours as required).
- Excellent coping skills and the ability to juggle multiple priorities.
- Self-managed; able to work independently or with a team as well as the leadership skills necessary to lead a group of technical team members as required.
- Able to be objective and receive input from specialized team members according to their areas of expertise.
Radiance Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.