Job Monitor / Oil & Gas

Information System Security Manager (ISSM)

KBR · United States · Posted 1 hour ago

Company KBR Location USA, Beavercreek Township, 3725 Pentagon Boulevard, Suite 210, Ohio, United States Employment type Full-time Posted 1 hour ago Listed via KBR
We are KBR At KBR, we partner with clients to provide purposeful and comprehensive science, technology and engineering solutions to governments as well as the top tier commercial clients in green hydrogen and green ammonia. With a full portfolio of services, proprietary technologies and expertise, our approximately 37,000 employees are ready to handle projects and missions throughout their entire lifecycle, from planning and design to sustainability and maintenance. Whether at the bottom of the ocean or in outer space, our clients trust us to deliver the impossible on a daily basis. As the needs of the world change, we’re ready to respond and guide the way forward with strategic, sustainable, and technological advancements grounded in more than a century of practical application and execution. About the Role KBR is seeking an Information System Security Manager (ISSM) to serve as the onsite cybersecurity lead supporting Assessment & Authorization (A&A) activities and cybersecurity policy and procedure development to obtain and maintain Authorizations to Operate (ATOs) for assigned systems, applications, networks, and devices. Based in Beavercreek, Ohio, this position reports directly to the Information Assurance (IA) Operations Manager and serves as the primary onsite representative of the IA Operations organization. The ISSM develops and implements cybersecurity strategies, advises stakeholders on risk management and compliance requirements, and ensures adherence to applicable Department of Defense (DoD), Intelligence Community (IC), and National Institute of Standards and Technology (NIST) security standards. Key Responsibilities Serve as the onsite representative and subject matter expert (SME) for Information Assurance activities across multiple enclaves and network environments. Provide solutions to complex cybersecurity and compliance challenges requiring specialized technical expertise, independent judgment, and creative problem-solving. Conduct risk and vulnerability assessments of information systems to identify security risks, vulnerabilities, and protection requirements. Lead and participate in Assessment & Authorization (A&A) status meetings with government and contractor personnel to facilitate Risk Management Framework (RMF) efforts and address issues impacting authorization activities. Support the development, implementation, and continuous improvement of cybersecurity policies, procedures, and processes. Maintain awareness of evolving cybersecurity, RMF, NIST, DoD, and IC requirements and apply relevant changes to organizational practices and system authorization efforts. Develop, review, and maintain RMF documentation, including Security Plans (SPs), Risk Assessment Reports (RARs), Implementation Plans, and Plans of Action and Milestones (POA&Ms). Assess system compliance against NIST, DoD, and IC cybersecurity requirements, including NIST SP 800-53, NIST SP 800-171, DISA Security Technical Implementation Guides (STIGs), and Security Requirements Guides (SRGs). Generate, collect, and maintain evidence required to demonstrate compliance with RMF security controls and authorization requirements. Collaborate with system administrators, engineers, developers, and other stakeholders to create and maintain system and site security policies, procedures and process documentation. Coordinate with technical SMEs to develop authorization boundary diagrams, system architecture diagrams, and hardware and software inventories. Analyze vulnerability scan results and support remediation efforts to reduce cybersecurity risk and maintain compliance. Participate in recurring IA Operations team meetings to provide RMF package updates, communicate system status, identify risks or issues, and obtain guidance as needed. Lead or participate in stakeholder meetings regarding authorization activities, compliance status, and cybersecurity initiatives. Prepare and submit weekly status reports to leadership regarding system and program progress. Basic Qualifications Education & Experience Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline. 10+ years of experience in Cybersecurity, Information Technology, or a related area with 5+ years of experience performing ISSM and/or ISSO responsibilities in classified environments. Active DoD Top Secret security clearance with SCI eligibility. Current DoD 8570-compliant certification. Experience implementing and managing the Risk Management Framework (RMF). Experience developing and maintaining RMF authorization packages and supporting ATO efforts. Technical & Leadership Skills Knowledge of Assessment & Authorization (A&A) processes and cybersecurity compliance requirements. Experience assessing systems against NIST SP 800-53 controls and/or DISA STIG and SRG requirements. Experience developing RMF artifacts, including Security Plans, Risk Assessments, and POA
Explore more
1284 KBR jobs → 3540 jobs in United States →
Oil & Gas Alert tracks 21+ employer career pages and delivers daily digests of new vacancies. Set your own keywords →