At a Glance
- Tasks: Lead cybersecurity efforts to protect critical DoD cloud systems and implement risk management frameworks.
- Company: Join Avint, a dynamic company dedicated to cybersecurity excellence.
- Benefits: Competitive salary, health benefits, 401K plan, generous PTO, and professional development support.
- Why this job: Make a real impact in national security while advancing your career in cybersecurity.
- Qualifications: Active Top-Secret clearance, Master's degree, and extensive experience in DoD cybersecurity.
- Other info: 100% on-site role at Hanscom Air Force Base with opportunities for growth.
The predicted salary is between 132000 - 140000 £ per year.
Avint is hiring an Information Systems Security Manager (ISSM) - SME to support and protect critical DoD cloud-based systems. In this role, you’ll be part of a high-performing team responsible for implementing and overseeing all phases of the Risk Management Framework (RMF) while supporting day-to-day cybersecurity operations. You’ll work at the intersection of security, compliance, and mission impact, helping ensure systems are secure, resilient, and aligned with DoD and Air Force requirements.
This role is 100% ON-SITE at Hanscom Air Force Base in MA and requires an ACTIVE Top-Secret clearance.
The individual in this role will be a member of the team implementing and overseeing all phases of the RMF process and day-to-day cybersecurity activities for DoD cloud-based systems. Primary responsibilities include:
- Supporting the system/application authorization and accreditation (A&A) effort, including assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Air Force policies.
- Recommending policies and procedures to ensure the reliability of and accessibility to information systems and to prevent and defend against unauthorized access to systems, networks, and data.
- Conducting risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs.
- Promoting awareness of security issues among management and ensuring sound security principles are reflected in organisations’ visions and goals.
- Conducting systems security evaluations, audits, and reviews.
- Recommending systems security contingency plans and disaster recovery procedures.
- Recommending and implementing programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures.
- Participating in network and systems design to ensure implementation of appropriate systems security policies.
- Facilitating the gathering, analysis, and preservation of evidence used in the prosecution of computer crimes.
- Assessing security events to determine impact and implementing corrective actions.
- Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services.
- Performing the Information System Security Engineer (ISSE) duties in an Information Assurance Workforce System Architecture and Engineering (IASAE) position as outlined in AFI 33-200, AFI 33-210 and AFMAN 33-285 for assigned systems.
- Performing the Information System Security Officer (ISSO) duties as outlined in DoDI for assigned systems/applications.
- Performing the Information System Security Manager (ISSM) duties as outlined in DoDI for assigned systems/applications.
Technical Areas of Expertise
- Expert knowledge of NIST RMF processes, policies, and DoD directives.
- Expert ability to create and revise standard operating procedures (SOPs), work instructions (WI), and Tactics, Techniques, and Procedures (TTPs).
- Expert ability to create presentations and present policies, guidance, and procedures to varied audiences including senior leadership levels.
- A demonstrated expertise in RMF process.
- Customer service skills.
- A demonstrated ability (including knowledge and experience) to perform tasks related to AF cyber security.
- Knowledge of cloud-based solutions is a plus.
Qualifications
- Active DoD Top Secret clearance.
- Master's Degree in a Related Field.
- IAM Level III Certification (CISSP is desired).
- 15 years of experience, of which 5 must be in the DoD.
- In-depth knowledge of DoD cyber security policies and regulations.
- Experience in providing security recommendations to senior leadership.
- Bachelor’s Degree and 10 years of prior experience; additional experience may be considered in lieu of degree.
- Candidate must have valid CISSP, Clearance, eMASS experience, DoD/RMF experience, on-site work.
Joining Avint is a win-win proposition! You will feel the personal touch of a small business and receive BIG business benefits, including competitive salaries, full health, a unique 401K plan, and generous PTO and Federal Holidays. Additionally, we encourage every Avint employee to further their professional development. To assist you in achieving your goals, we offer reimbursement for courses, exams, and tuition. Interested in a class, conference, program, or degree? Avint will invest in YOU and your professional development!
Avint is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity employer.
Salary: $165,000-$175,000 based on experience.
Information Systems Security Manager (ISSM) - SME in England employer: Avint
Contact Detail:
Avint Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Systems Security Manager (ISSM) - SME in England
✨Tip Number 1
Network like a pro! Reach out to folks in the cybersecurity field, especially those who work with DoD systems. Attend industry events or join online forums to connect with potential employers and get insider info on job openings.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of the NIST RMF processes and DoD directives. Be ready to discuss how you've implemented security measures in past roles, as this will show you're the right fit for the ISSM position.
✨Tip Number 3
Don’t just apply anywhere—focus on companies like Avint that value professional development. Highlight your willingness to learn and grow, and mention any relevant certifications you’re pursuing or have completed.
✨Tip Number 4
When you find a role that excites you, apply through our website! Tailor your application to showcase your experience with cloud-based systems and your active Top-Secret clearance, making it clear why you’re the ideal candidate for the job.
We think you need these skills to ace Information Systems Security Manager (ISSM) - SME in England
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with the Risk Management Framework (RMF) and DoD cybersecurity. We want to see how your skills align with the specific requirements of the Information Systems Security Manager role.
Showcase Your Expertise: Don’t hold back on showcasing your knowledge of NIST RMF processes and DoD directives. We’re looking for someone who can demonstrate their expertise clearly, so include relevant examples from your past roles that illustrate your capabilities.
Be Clear and Concise: When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. Remember, we appreciate straightforward communication!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re proactive and keen to join our team!
How to prepare for a job interview at Avint
✨Know Your RMF Inside Out
Make sure you have a solid grasp of the Risk Management Framework (RMF) processes and policies. Brush up on NIST guidelines and DoD directives, as you'll likely be asked to discuss how you've applied these in past roles.
✨Showcase Your Cybersecurity Experience
Prepare specific examples from your 15 years of experience that highlight your expertise in cybersecurity, especially within the DoD. Be ready to discuss your role in system/application authorisation and accreditation efforts.
✨Communicate Clearly with Confidence
Since you'll be presenting policies and procedures to varied audiences, practice articulating complex security concepts in simple terms. This will demonstrate your ability to communicate effectively with both technical and non-technical stakeholders.
✨Demonstrate Leadership and Teamwork
Emphasise your experience working in high-performing teams and your ability to lead initiatives. Share examples of how you've promoted security awareness and collaborated with management to align security principles with organisational goals.