Information System Security Manager (Issm) Nf5
- Location:
- Virginia, Quantico
- Requires Relocation:
- No
- Start Date:
- 26/12/2024
- End Date:
- 20/01/2025
- Offering Type:
- Permanent
- Hiring Paths:
- The public
- Service Type:
- Competitive
- Travel Percentage:
- 25% or less
About U.S. Marine Corps
The Navy and Marine Corps team offers innovative, exciting and meaningful work linking military and civilian talents to achieve our mission and safeguard our freedoms. Department of the Navy provides competitive salaries, comprehensive benefits, and extensive professional development and training. From pipefitters to accountants, scientists to engineers, doctors to nurses-the careers and opportunities to make a difference are endless. Civilian careers-where purpose and patriotism unite! This announcement uses the Certain Personnel of the DoD direct hire authority to recruit and appoint qualified candidates to positions in the competitive service.
Job summary
Marine Corps Community Services (MCCS) is looking for the best and brightest to join our Team! MCCS is a comprehensive program that supports and enhances the quality of life for Marines, their families, and others in the Marine Corps Community. We offer a team oriented environment comprised of military personnel, civilian employees, contractors and volunteers who keep the organization functioning smoothly and effectively.
Major duties
This position serves as the Enterprise Information System Security Manager (ISSM) for the Information Technology Directorate (MRI), NAF Business and Support Services Division (MR), Manpower and Reserve Affairs Department, Headquarters Marine Corps. The incumbent will provide guidance and direction to Information System Security Managers at the installation and project/program level to provide system security manager services to Marine Corps installations worldwide. Serve as an advocate for all disciplines within the security program including the development and subsequent enforcement of the organization¿s security awareness programs, business continuity and disaster recovery plans, and all industry and governmental compliance issues. Promotes IT security awareness to the user community by validating the user community is completing annual security training. Oversees and maintains regulatory requirements and completes periodic reviews for security implications and security applications. Works closely with and receives reports from Information Systems Security Manager(s), Information Systems Security Officers (ISSO)s, and Information System Security Engineer(s). Performs security compliance efforts IAW the Payment Card Industry (PCI), Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology Special Publication (NIST SP) 800 series, Federal Information Processing Standards (FIPS) series, and USMC related policies and procedures. Conducts assessments of threats and vulnerabilities, determine deviations from acceptable configurations and enterprise or local policies, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in all situations. Coordinates with all departments within the Marine Corps Community Services (MCCS) and higher Marine Corps to support cybersecurity awareness initiatives. Occasional travel to complete work assignments, conduct training or attend conferences and meetings may be required. Performs other related duties as assigned. This is a white-collar position where occasional lifting up to 20 lbs may be required. Performs other duties as assigned.
Requirements
EVALUATIONS:
Qualification
Bachelors' Degree in Information Technology or Business related field appropriate to the work of position AND seven years of experience performing specific tasks for Information System Security Manager (ISSM), security assessments, vulnerability management, or cybersecurity (CY): OR an appropriate combination of education and experience that demonstrates possession of knowledge and skill equivalent to that gained in the above, OR appropriate experience that demonstrates the applicant has acquired the knowledge, skills, and abilities equivalent to that gained in the above. Knowledge of risk management processes, secure configuration management techniques, Government laws and policies, cyber threats and vulnerabilities, encryption algorithms, host/network access control mechanisms, vulnerability information dissemination sources, Payment Card Industry (PCI) data security standards, Personally Identifiable Information (PII) data security standards, incident response and handling methodologies, intrusion detection methodologies and techniques for detecting host and network-based intrusions, and organization's risk tolerance and/or risk management approach. Skill in applying security controls, analyzing traffic to identify network devices, conducting application vulnerability assessments, assessing security systems designs, interpreting vulnerability scanner results to identify vulnerabilities, assessing cloud security measures and microservices, preparing Test & Evaluation reports, and running Security Content Automation Protocol (SCAP) content and Security Technical Implementation Guides (STIGS) based tools for benchmark, compliance checks, and security configuration reviews. Ability to identify systemic security issues based on the analysis of vulnerability and configuration data, apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation), conduct vulnerability scans and recognize vulnerabilities in security systems, and translate data and test results into evaluative conclusions. As an authorized and privileged user of Department of Defense Information Systems must fulfill the requirement to complete DoD Workforce Improvement Program certification (DoD 8140.01) as a condition of access within six months of employment. This position has been determined as an advanced proficiency level. This position had been determined as Moderate Risk. As a condition of employment, the incumbent must be able to obtain and maintain an Access National Agency Check and Inquiries (ANACI/ Tier 3) Secret Clearance to access classified information. Eligible for incremental telework as determined by MR/MF policy.
Evaluations
Your application/resume and supporting documentation will be used to determine whether you meet the job qualifications listed on this announcement. This vacancy will be filled by the best qualified applicant as determined by the selecting official.