
Information System Security Manager – ISSM
KBR, Inc.
full-time
Posted on:
Location Type: Hybrid
Location: Niceville • Alabama • District of Columbia • United States
Visit company websiteExplore more
Salary
💰 $115,800 - $173,700 per year
Tech Stack
About the role
- Deliver documentation to include: Executive level briefings, Assessments, Self-Assessments, RMF packages, and supporting RMF documentation
- Review Cybersecurity tool reports, ACAS, HBSS, for the purposes of reporting and compliance
- Software Certification package development
- Work directly with the TRMC SISO on all TRMC RMF packages and ATO Status updates
- Support security engineering projects and solution delivery.
- Lead security audit and compliance activities for each system responsible for
- Responsible for auditing all artifacts provided in each RMF package to determine system readiness for ATO packet submissions.
- Provide recommendations to the SISO, PM, and AO regarding remediation and mitigation of identified vulnerabilities on test reports and plan of action and milestones (POA&Ms).
- Monitor system status updates and report to senior leadership. Includes monthly executive reports, vulnerability reports, JFHQ DODIN reporting and briefing.
- Monthly executive briefing to SISO, PM on security metrics
- Interface with PMs and SISO on issues needing input/concurrence
- Draft and present RMF deliverables to senior leadership
- Attending Executive Program Reviews as the ISSM
- Work with outside agencies on Memorandums of Understanding / Interconnection Service Agreements, and other senior level agreements etc.
- Work directly with a distributed team to reduce travel
- Travel 25% of time
Requirements
- A minimum of 2 years of Information Technology Information Assurance, or Cyber Security engineering experience
- A minimum of 2 years of experience in conducting security assessments by reviewing security controls with the ISSO/ISSM and guide programs through RMF process
- Bachelor’s Degree in Engineering, Computer Science, or 8 years IT field experience in lieu of degree
- Proven expertise with assessing security controls in accordance with NIST Special Publications (i.e.: NIST 800 Series)
- Proven in-depth knowledge of Cybersecurity principles technologies, and processes
- Experience with NIST 800-53, Security Development
- Familiarity with performing assessments for Unclassified and Classified environments
- Ability to adapt to process changes
- Ability to interface with senior leadership
- Ability to support high visibility or high priority projects
- Possession of excellent oral and written communication skills.
Benefits
- KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation.
- Additional compensation may be in the form of a sign on bonus, relocation benefits, short-term incentives, long-term incentives, or discretionary payments for exceptional performance.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
CybersecurityInformation AssuranceSecurity AssessmentsRMF (Risk Management Framework)NIST 800 SeriesNIST 800-53Security DevelopmentVulnerability ReportingAudit ComplianceSoftware Certification
Soft Skills
CommunicationLeadershipAdaptabilityInterpersonal SkillsProblem SolvingTeam CollaborationPresentation SkillsExecutive BriefingReportingStakeholder Engagement