Search for More Jobs
Get alerts for jobs like this Get jobs like this tweeted to you
Company: SPA
Location: San Diego, CA
Career Level: Mid-Senior Level
Industries: Manufacturing, Engineering, Aerospace

Description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.  

 

The Cybersecurity Pillar under SPA's CIO establishes and maintains a robust cybersecurity posture and policy architecture across SPA's information systems. The team manages cyber policy, develops control implementations and system security plans, continuously monitors SPA systems, and performs routine cyber operations including patching, auditing, and incident response. Cybersecurity is critical to SPA's mission; therefore we strive to offer secure solutions that ensure data is protected while meeting the needs of the business.

 

In this role, you will serve as the Information Systems Security Manager (ISSM) for multiple systems operating under SPA's Operations Research and Cyber Analysis (C5ISR/ORCA) Group. This requires the individual to operate with autonomy while interfacing directly with SPA clients and leaders overseeing the business unit's operation.  

 

This position will develop information system solutions following Risk Management Framework (RMF) with implementations following the DAAG/DAAPM and CMMC.  The ISSM will be responsible for attaining and maintaining system assessments and authorizations through government authorizing agencies from requirements through operational deployment. ISSM will implement requirements to establish classified communication links including internet, phone, video teleconferencing and other vital communications channels. The successful candidate will coordinate requirements with DoD agencies to ensure mission accomplishment and the protection of sensitive information.


Responsibilities

Responsibilities:

  • Develop and maintain enterprise-wide RMF information security policies, standards, guidelines, procedures, and artifacts following the RMF framework.
  • Oversees the development and deployment of the information security program for multiple classified systems to meet business and enterprise requirements, policies, standards, guidelines, and procedures Prepares, reviews, and presents technical reports and briefings.
  • Create and Maintain the System Security Plans (SSP) and associated documentation.
  • Create a book of business for Cybersecurity Team.
  • Maintain compliance of accredited information systems based on federal and DoD security standards.
  • Manages and performs security compliance via continuous monitoring.
  • Identifies root causes, prioritizes threats and recommends and/or implements corrective actions.
  • Research and address information security issues as required as an authority on the subject.
  • Ensure systems are operated, maintained, and disposed of in accordance with internal and DCSA security policies and practices.
  • Participate in internal and external security audits and inspections; performs risk assessments.
  • Evaluate proposed changes or additions to the information system and assess their security relevance.
  • Ensure configuration management (CM) for security relevant IS software, hardware, and firmware is maintained and documented.
  • Conduct investigations of computer security violations and incidents, reporting as necessary.
  • Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered.
  • Communicate, implement and manage a formal Information Security / Information Systems Security Program together with CISO, CIO, and ISO.
  • Receive and respond to incoming calls and/or e-mails regarding end-user or system problems.
  • Interface with third-party support and equipment vendors as needed.

 

Some travel may be required.

 

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent.  Elements of the compensation package include competitive base pay and variable compensation opportunities.  

 

SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and several programs that provide for both paid and unpaid time away from work.  

 

The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc.

 

Please note that the salary information shown below is a general guideline only.  Salaries are commensurate with experience and qualifications, as well as market and business considerations.  California Pay Transparency Range: $125,000-$175,000


Qualifications

Qualifications:

 

  • Bachelor's degree in information security, Information Technology, or related discipline, or equivalent experience/combined education, with 5+ years of professional experience.
  • Must have and maintain a DoD 8570.01-M (Information Assurance Workforce) IAM Level II certification (e.g. CAP, CISM, or CISSP).
  • A minimum of 3 years of direct experience with RMF artifacts, obtaining and maintaining system ATOs, and implementing new and complex technologies at multiple classification levels within large enterprise environments.
  • A minimum of 3 years of direct experience performing a continuous monitoring and the cybersecurity hygiene of windows domains and network enclaves.
  • A minimum of 5 years of direct experience working with federal/government agencies in sensitive and classified environments.
  • A minimum of 3 years of direct experience with Risk Management Framework (RMF), NIST 800-53, DAAG/DAAPM, and other legal and regulatory guidance.
  • Active Secret security clearance.

 

Desired Skills:

  • At least 3 years' experience in the deployment, configuration, and troubleshooting of information technology equipment.
  • Ability to understand information systems equipment configurations (switches, routers, IDS, firewalls, servers, storage, etc.).

 



Qualifications

Qualifications:

 

  • Bachelor's degree in information security, Information Technology, or related discipline, or equivalent experience/combined education, with 5+ years of professional experience.
  • Must have and maintain a DoD 8570.01-M (Information Assurance Workforce) IAM Level II certification (e.g. CAP, CISM, or CISSP).
  • A minimum of 3 years of direct experience with RMF artifacts, obtaining and maintaining system ATOs, and implementing new and complex technologies at multiple classification levels within large enterprise environments.
  • A minimum of 3 years of direct experience performing a continuous monitoring and the cybersecurity hygiene of windows domains and network enclaves.
  • A minimum of 5 years of direct experience working with federal/government agencies in sensitive and classified environments.
  • A minimum of 3 years of direct experience with Risk Management Framework (RMF), NIST 800-53, DAAG/DAAPM, and other legal and regulatory guidance.
  • Active Secret security clearance.

 

Desired Skills:

  • At least 3 years' experience in the deployment, configuration, and troubleshooting of information technology equipment.
  • Ability to understand information systems equipment configurations (switches, routers, IDS, firewalls, servers, storage, etc.).

 



Responsibilities

Responsibilities:

  • Develop and maintain enterprise-wide RMF information security policies, standards, guidelines, procedures, and artifacts following the RMF framework.
  • Oversees the development and deployment of the information security program for multiple classified systems to meet business and enterprise requirements, policies, standards, guidelines, and procedures Prepares, reviews, and presents technical reports and briefings.
  • Create and Maintain the System Security Plans (SSP) and associated documentation.
  • Create a book of business for Cybersecurity Team.
  • Maintain compliance of accredited information systems based on federal and DoD security standards.
  • Manages and performs security compliance via continuous monitoring.
  • Identifies root causes, prioritizes threats and recommends and/or implements corrective actions.
  • Research and address information security issues as required as an authority on the subject.
  • Ensure systems are operated, maintained, and disposed of in accordance with internal and DCSA security policies and practices.
  • Participate in internal and external security audits and inspections; performs risk assessments.
  • Evaluate proposed changes or additions to the information system and assess their security relevance.
  • Ensure configuration management (CM) for security relevant IS software, hardware, and firmware is maintained and documented.
  • Conduct investigations of computer security violations and incidents, reporting as necessary.
  • Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered.
  • Communicate, implement and manage a formal Information Security / Information Systems Security Program together with CISO, CIO, and ISO.
  • Receive and respond to incoming calls and/or e-mails regarding end-user or system problems.
  • Interface with third-party support and equipment vendors as needed.

 

Some travel may be required.

 

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent.  Elements of the compensation package include competitive base pay and variable compensation opportunities.  

 

SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and several programs that provide for both paid and unpaid time away from work.  

 

The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc.

 

Please note that the salary information shown below is a general guideline only.  Salaries are commensurate with experience and qualifications, as well as market and business considerations.  California Pay Transparency Range: $125,000-$175,000


 Apply on company website