1

Cybersecurity Manager Jobs in Guam (NOW HIRING)

GU · On-site

... Risk Management Framework (RMF), vulnerability management, continuous monitoring, and incident ... and cybersecurity engineering activities * At least one current qualifying certification: CCSP ...

GU · On-site

Provide administrative support to CIO3, including records management, office-automation process ... CompTIA Security+, EC-Council Certified Network Defender (CND), GIAC Foundational Cybersecurity ...

... cybersecurity compliance, and enabling users to effectively perform operational, training, and ... Manage incidents, service requests, and problem tickets using AESMP, ServiceNow, and other approved ...

Maintain awareness of federal cybersecurity, Controlled Unclassified Information (CUI), and secure data management requirements associated with federal and defense-related projects. * Collaborate ...

GU · On-site

Maintain awareness of federal cybersecurity, Controlled Unclassified Information (CUI), and secure data management requirements associated with federal and defense-related projects. * Collaborate ...

Cybersecurity Manager information

What are the key skills and qualifications needed to thrive as a cybersecurity manager?

To thrive as a Cybersecurity Manager, you need a deep understanding of information security principles, risk management, and network security, usually backed by a degree in computer science or a related field. Familiarity with security frameworks (such as NIST or ISO 27001), incident response tools, and certifications like CISSP or CISM is highly valued. Strong leadership, analytical thinking, and effective communication skills enable you to manage teams and convey complex threats to stakeholders. These skills are essential to protect organizational assets, ensure regulatory compliance, and respond swiftly to evolving cyber threats.

What are some of the main challenges cybersecurity managers face when leading a security team?

Cybersecurity Managers often encounter challenges such as balancing proactive threat mitigation with responding to real-time incidents, managing a diverse team with varying skill levels, and staying updated on rapidly evolving cyber threats. They must also effectively communicate risks and security needs to non-technical stakeholders and ensure compliance with industry regulations. Building collaboration between IT, development teams, and executive leadership is essential to create a unified security strategy.

What is the difference between Cybersecurity Manager vs Security Analyst?

AspectCybersecurity ManagerSecurity Analyst
CertificationsCISSP, CISM, CompTIA Security+CompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security teams, strategic planningMonitors security systems, analyzes threats
Employer & Industry UsageUsed in organizations with dedicated security teamsCommon in security operations centers (SOCs)

The main difference is that a Cybersecurity Manager focuses on managing security teams and developing security strategies, while a Security Analyst primarily monitors systems and responds to security incidents. Both roles require similar certifications but differ in responsibilities and scope within the cybersecurity field.

How much do cybersecurity managers earn?

Cybersecurity managers typically earn a median annual salary ranging from $100,000 to $150,000, depending on experience, certifications, and location. They often oversee security teams, implement security protocols, and use tools like firewalls and intrusion detection systems, with higher salaries for those with advanced certifications such as CISSP or CISM.

What does a cybersecurity manager do?

A cybersecurity manager oversees an organization’s security strategy, manages security teams, and implements policies to protect information systems from cyber threats. They analyze security risks, coordinate incident response, and often use tools like firewalls and intrusion detection systems, typically requiring certifications such as CISSP or CISM. Their role involves ensuring compliance with security standards and continuously improving security measures.

What are the most commonly searched types of Cybersecurity jobs in Guam?

The most popular types of Cybersecurity jobs in Guam are:

Infographic showing various Cybersecurity Manager job openings in Guam as of August 2026, with employment types broken down into 87% Full Time, 12% Part Time, and 1% Contract. Highlights an 84% Physical, 2% Hybrid, and 14% Remote job distribution.

Cybersecurity Analyst with Security Clearance

Ares Enterprise, LLC

Santa Rita, GU • On-site

Contractor

Posted 9 days ago


Job description

The Cybersecurity Analyst will provide hands-on cybersecurity support across NAVFAC Marianas Facility-Related Control Systems (FRCS) environments, helping protect the confidentiality, integrity, and availability of systems, networks, and data. The role supports the planning, implementation, documentation, maintenance, and improvement of cybersecurity programs, policies, procedures, and tools. This position works closely with system owners, independent validators, the Information Systems Security Manager (ISSM), NAVFAC CIO personnel, and other government stakeholders. The analyst will also support cybersecurity incident response as a member of the MAR Cyber Emergency Response Team (CERT), participate in on-call rotations, and independently drive RMF and cybersecurity activities with minimal supervision. The successful candidate will manage the full Risk Management Framework (RMF) lifecycle, Steps 1–6, in accordance with Department of the Navy and NAVFAC Echelon II guidance. The candidate will be capable of independently driving cybersecurity and RMF activities with minimal supervision, supporting systems throughout the full RMF lifecycle, maintaining Authorities to Operate (ATOs), conducting vulnerability and compliance assessments, and providing continuous monitoring and incident response support. Essential Duties & Responsibilities: Execute the end-to-end RMF lifecycle (Steps 1–6) and ensure required artifacts meet DoN and NAVFAC requirements and are properly uploaded and maintained within eMASS.
Support the attainment, maintenance, and tracking of Authorities to Operate (ATOs) for Facility-Related Control Systems.
Facilitate annual security reviews and develop Memorandums for Record associated withsystem baseline changes.
Develop and maintain cybersecurity policies, Standard Operating Procedures (SOPs), and implementation plans aligned with NIST SP 800-53 security control families and NAVFAC/DoN cybersecurity requirements.
Develop and execute a comprehensive vulnerability management strategy.
Perform vulnerability and compliance assessments using approved tools such as ACAS, SCAP, and Evaluate STIG.
Perform manual STIG and Security Requirements Guide (SRG) validations and maintain required checklists.
Generate Security Center and eMASSter reports and ensure vulnerability results are accurately maintained in the Vulnerability Remediation Asset Management (VRAM) database.
Conduct System-Level Continuous Monitoring (SLCM), including recurring vulnerability scanning, security control reviews, audit log analysis, vulnerability remediation/mitigation, and quarterly Plan of Action and Milestones (POA&M) updates.
Provide on-site validation and technical testing support for RMF Step 4 activities.
Coordinate with system owners and independent validators during site assessments and technical evidence collection.
Serve as a technical representative and/or Configuration Management Officer on the Configuration Control Board (CCB) and provide security impact analyses and risk assessments for proposed FRCS changes.
Support cybersecurity incident response operations as a member of the MAR Cyber Emergency Response Team (CERT) and participate in required on-call rotations.
Prepare incident response reports and operational documentation following cybersecurity events.
Provide bi-weekly RMF status reporting to the ISSM and maintain FRCS RMF project records in Maximo and/or eProjects.
Prepare recurring project, cybersecurity, continuous monitoring, and ATO milestone reporting in support of NAVFAC CIO priorities. Required Qualifications: U.S. Citizenship is required.
Minimum of five (5) years of Risk Management Framework (RMF) experience.
Minimum of one (1) year of specialized experience supporting Facility-Related Control Systems (FRCS) while performing RMF and cybersecurity engineering activities.
Must be fully qualified in accordance with DoDM 8140.03, Cyber Workforce Work Role 461 – Systems Security Analyst, at the Intermediate or Advanced proficiency level prior to onboarding.
Must possess and maintain an approved cybersecurity certification. Intermediate-level certifications include CCSP, Cloud+, GICSP, GISF, GSEC, or Security+. Advanced certifications identified include RCCE Level 1, CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, or GSNA.
Must maintain required certification status and complete at least 20 hours annually of Continuous Professional Development (CPD), or the minimum required to maintain the applicable commercial certification, whichever is greater.
Demonstrated ability to independently perform technical cybersecurity work with minimal government supervision.
Demonstrated experience developing comprehensive technical reports, cybersecurity policies, procedures, and related security documentation.
Ability to communicate effectively with government personnel, system owners, technical stakeholders, and Information Systems Security Managers.
Ability to communicate fluently and effectively in English, both verbally and in writing.
Ability to work in mechanical and facility environments and lift or move equipment weighing up to 25 pounds. Security clearance requirements: Must possess an active Tier 5 (T5) Top Secret security clearance or be able to obtain an interim T5 clearance prior to onboarding and the start of performance.
The required security clearance must be maintained in active and good standing throughout the period of contract performance.
Personnel must comply with all applicable DoD, Department of the Navy, NAVFAC, and site-specific information security and safeguarding requirements