What are the responsibilities and job description for the Information Systems Security Manager position at North Wind?
Summary : This position is responsible to ensure all systems comply with NIST 800-171, CMMC, and various security related system controls while meeting program demands and operating in an accredited state. Establish compliance framework, work collaboratively with team and vendors in all aspects of SSP development, maintenance, accreditation / re-accreditation, and oversight, including conducting periodic reviews to ensure compliance.
Responsibilities :
- Work with Vendor to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources. Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level. Document and escalate incidents (including event’s history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment.
- Perform cyber defense trend analysis and reporting. Perform event correlation using information gathered from a variety of sources within the company to gain situational awareness and determine the effectiveness of an observed attack. Work with vendor to perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
- Use cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity. Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings). Assess adequate access controls based on principles of least privilege and need-to-know.Work with stakeholders to resolve computer security incidents and vulnerability compliance.
- Lead Disaster Recovery and Business Continuity Plans. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
- Perform security reviews, develop a security risk management plan. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
- Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Verify that application software / network / system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
Preferred Education / Experience :
Preferred Knowledge / Ability :
North Wind is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. North Wind supports safe and drug free workplace through pre-employment background checks and drug testing.