Information Systems Security Manager , Amazon Leo Government

AmazonArlington, VirginiaOn-siteFull-timeStaff, 8–12 yearsListed 5 hours ago

Apply now

About this role

Description

Are you passionate about helping customers solve complex security and compliance challenges? Do you thrive in environments where you can build scalable mechanisms and drive operational excellence? Amazon Leo Government (ALG) is seeking an Information Systems Security Manager (ISSM) to join our team.

In this role, you will help develop, design, and implement strategies to scale and manage the ALG security program in compliance with the National Industrial Security Program (NISP). We are looking for a builder with deep customer obsession who can earn trust with multiple stakeholders and deliver results in a fast-paced, high-security environment.
As an ISSM, you will own the day-to-day execution and continuous improvement of Information System Security policies, standards, and directives that support the assessment, authorization, and continued operation of information systems processing classified information. You will develop and implement security policies, conduct risk assessments, manage system accreditations through the Risk Management Framework (RMF), and drive continuous monitoring efforts.

This is an individual contributor role with significant scope for ownership. You will be expected to dive deep into technical details, invent and simplify processes, and deliver results that directly impact ALG's ability to serve our government customers.

Key job responsibilities
• Own and enforce security policies, procedures, and regulatory requirements to ensure compliance with customer and NISP requirements; ensure users follow proper security procedures and all classified information systems are properly secured.
• Develop, implement, and maintain security policies, procedures, and documentation in compliance with DoD security standards and regulations (e.g., NIST, RMF, FISMA), raising the bar on quality and consistency.
• Create and maintain media sanitization (clearing, purging, or destroying) and reuse procedures, ensuring repeatable and auditable processes.
• Develop and document processes, procedures, and guidelines for protection requirements (e.g., e-mail labels, media labels), control procedures (e.g., discretionary access control, need-to-know sharing), incident management reporting, remote access requirements, system management, and use of encryption.
• Configure, update, and monitor classified network infrastructure devices including routers, firewalls, intrusion detection/prevention components, and switches; proactively identify and remediate vulnerabilities.
• Leverage customer-authorized tools to test and secure systems, including vulnerability scanners and antivirus solutions; document findings and drive remediation.
• Perform system administration functions for modern operating systems and applications, including installing and configuring operating systems, applying patches and updates, tuning security controls to meet federal requirements, monitoring operations, and managing system backups.
• Identify opportunities to automate, simplify, or improve security processes and mechanisms; document and share best practices across the team.

This position requires the candidate to be a U.S. Citizen and must currently possess and maintain an active TS/SCI security clearance.

This position is based in Arlington VA, some travel will be required.

Basic Qualifications

- Bachelor's degree or equivalent in Computer Science, Engineering, Information Systems Management, Information Security or other related fields
- 5+ years of experience with cybersecurity policies and implementation of Risk Management Framework (RMF), including DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series
- Current certification in good standing to satisfy IAM Level III (CISSP, GSLC, or CISM)

Preferred Qualifications

- 5+ years of experience as an Information System Security Officer (ISSO) or Information System Security Manager (ISSM) supporting classified programs
- Experience working in Special Access Programs (SAP)
- Working knowledge of Intelligence Community Directives (ICDs), including ICD 704, 705, and 503
- KMI Certification
- Demonstrated ability to build scalable security processes and mechanisms in a growing or dynamic environment
- Experience writing technical documentation, standard operating procedures, or runbooks
- Track record of identifying and driving process improvements in a security or compliance domain

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .

USA, VA, Arlington - 102,000.00 - 178,400.00 USD annually