ASRC Federal Holding Company logo

Senior Manager Information Security

ASRC Federal Holding Company
  • Aberdeen Proving Ground, MD
  • Autofill and Review
14 days ago

Job Description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work

ASRC Federal Technology Solutions LLC is looking for an experienced Information System Security Officer with a minimum of an active Top Secret security clearance to support their work with DEVCOM-CBC and the Transformation Decision Analysis Center (TDAC) organization, and who will serve as the Teams direct manager. This position supports the development, implementation, and maintenance of cybersecurity policies, standards, and procedures, ensuring compliance with applicable Department of Defense (DoD), Army, and DEVCOM CBC regulations.

In this role, you will provide cybersecurity support to the DEVCOM-CBC G-6 Cybersecurity Branch, focusing on all aspects of Risk Management Framework (RMF) activities, cybersecurity assessments, and incident response. This role requires a deep understanding of cybersecurity principles, a strong analytical ability, and excellent communication skills to effectively convey complex information to both technical and non-technical audiences, while maintaining a broad portfolio of compliance and accounts management responsibilities across unclassified, classified, and standalone systems.

KEY RESPONSIBILITIES

  • Maintain current Authority to Operate (ATO) status for DEVCOM systems and provide RMF guidance and support to other DEVCOM/TDAC locations with similar systems.
  • Develop, update, and/or modify the system-level artifacts (e.g., TTPs, plans, policies, procedures, hardware/software lists, data flow, system architecture diagrams, PIAs, Ports/Protocols/Services, MOA/MOU, etc...) and ensure they are associated with corresponding controls in eMASS.
  • Obtain, run, analyze, and import all applicable vulnerability scanners and compliance checkers as required, including STIGs, Nessus/ACAS Scans, etc...
  • Track and report IAVAs related to DEVCOM systems.
  • Create, modify, and/or maintain all aspects of the implementation plan and test results, as defined by DOD, Army, NETCOM, and DEVCOM requirements.
  • Manage Plans of Action and Milestones (POA&M), including development, status updates, milestone tracking, and closure.
  • Manage assigned network packages within eMASS and maintain accurate, current authorization documentation.
  • Create, modify, and/or maintain all aspects of CONMON.
  • Utilize existing or develop custom solutions to facilitate RMF requirements, reduce timelines and provide up-to-date status reporting of compliance
  • Update and track cybersecurity test results, implementation plans, and risk assessments.
  • Evaluate STIG checklists and document compliance status, deficiencies, and required remediation actions.
  • Perform first-response coordination for Negligent Disclosure of Classified Information incidents in accordance with organization SOPs for incident response
  • Conduct vulnerability management activities, including identifying, tracking, and coordinating corrective actions.
  • Oversee and manage small team with administrative and personnel duties
  • Serve as liaison between government and contractor organizations

REQUIRED QUALIFICATIONS

  • Active DoD Top Secret clearance or higher. Candidates without a minimum of a Top Secret clearance will not be considered.
  • Bachelor's degree (BA/BS) in Computer Science, Information Technology, Engineering, or a related field and 8 additional years of experience
  • OR Master's degree in Computer Science, Information Technology, Engineering, or a related field or 6 additional years of experience
  • OR a total of 12 years of work experience in the field in lieu of degree
  • 5 or more years of hands-on RMF EMASS Authorization duties
  • Working knowledge of DoD and Army cybersecurity regulations including Army Regulation 25-2, DoD 8140, and DoD RMF policy
  • Experience with Active Directory account management and STIG/SRG audit processes
  • Familiarity with the Army Account Validation System (AVS) or equivalent DoD workforce compliance tracking platforms

PREFERRED QUALIFICATIONS

  • Direct experience with eMASS, POA&M and RMF processes and responsibilities
  • CISSP or CISM certification
  • Experience supporting DEVCOM or Army G-6 cybersecurity programs
  • Personnel management experience
  • Experience serving as an Enhanced Trusted Agent for PKI hardware token issuance
  • Experience performing Software Assurance or Hardware Assurance reviews for DoD networks
  • Familiarity with NSA and Army data sanitization and destruction policy

CLEARANCE LEVEL

  • This position requires an active Top Secret clearance.

EDUCATION REQUIRMENTS

  • Bachelor's degree in Information Technology, Computer Science, or a related field or 10 years of experience in lieu of the degree
  • Master's degree in Information Technology, Computer Science, or a related field

CERTIFICATION

  • DoDI 8140.03 qualification for DCWF Work Role Information Systems Security Manager (722 Advance). Accepted foundational qualifications include certifications mapped to Work Role 722 Advance in the current DoD 8140 Qualification Matrix, such as CISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, and GSLC.

Preferred

  • CISM
  • CISSP
  • CISSP-ISSMP

WORK ENVIRONMENT AND PHYSICAL DEMANDS:

  • This position primarily operates in a professional office environment at Aberdeen Proving Ground, MD, working within or alongside the DEVCOM-CBC G-6 Cybersecurity Branch. The role involves extended use of computer equipment and may require the candidate to move between buildings on the installation to support users and coordinate with government staff. Some work may involve access to classified facilities and systems. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Numbers & Facts

LocationAberdeen Proving Ground, MD
IndustryAerospace and Defense
Company Size5,000 to 9,999 employees
Year Founded2003
Websitehttp://www.asrcfederal.com

Benefits

Military Leave, On Site Cafeteria, Parking, Prescription Drug Coverage, Professional Development, 401K, Employee Referral Program, Flexible Spending Accounts, Employee Events, Tuition Reimbursement, Work From Home, Life Insurance, Merchandise Discounts

About Company

ASRC Federal comprises a family of companies that provide mission-critical services to federal government agencies dedicated to defense, civil and intelligence support. Our customer-focused service delivery model and emphasis on operational excellence are foundational elements infused in all our companies. The reliability and quality of day-in, day-out service delivery from our family of companies ensure our customers that we keep our sights on their mission-critical priorities.

Skills

  • Administrative Skillsunmatched
  • Analysis Skillsunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Corrective Actionunmatched
  • DoD Directive 8140unmatched
  • DoD Directive 8570unmatched
  • Documentationunmatched
  • Federal Governmentunmatched
  • Governmentunmatched
  • Government Contractsunmatched
  • Government Organizationsunmatched
  • ISSMP - Information Systems Security Management Professionalunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Legalunmatched
  • Maintain Complianceunmatched
  • Microsoft Active Directoryunmatched
  • National Security Agency (NSA)unmatched
  • Nessusunmatched
  • Network Administration/Managementunmatched
  • People Managementunmatched
  • Public Healthunmatched
  • Public Key Infrastructure (PKI)unmatched
  • Regulationsunmatched
  • Risk Analysisunmatched
  • Risk Management Framework (RMF)unmatched
  • Sales Managementunmatched
  • Security Clearanceunmatched
  • Standard Operating Procedures (SOP)unmatched
  • System Architectureunmatched
  • Team Lead/Managerunmatched
  • Top Secret Clearanceunmatched
  • United States Department of Defense (DoD)unmatched
  • Vulnerability Scannersunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder