PAE
PAE

78 Pae Environment Jobs Hiring Near You

Showing results 41-60

Information Systems Security Manager (ISSM) - PAE Fires IT Support Services

Information Systems Security Manager (ISSM) - PAE Fires IT Support Services

Technology, Automation, and Management, Inc.

Huntsville, AL โ€ข On-site

Other

Posted 6 days ago


Job description

PENDING CONTRACT AWARDMission Objectives - PAE Fires requires the implementation of a comprehensive cybersecurity program maintaining adequate security expertise across all levels of systems engineering, software design and integration, testing, and training. The ISSM serves as the contractor's primary point of contact for all cybersecurity and IS Systems Engineering (ISSE) issues and is responsible for achieving and maintaining Authorization to Operate (ATO) for all PAE Fires systems.Position Responsibility Summary:Protect the PAE Fires mission; understand that cybersecurity exists to enable operations, not block them; find ways to say 'yes, and here is how we do it securely' rather than defaulting to 'no'Maintain continuous situational awareness of the threat landscape as it applies to Army acquisition IT systems; proactively adjust defenses and configurations before threats materialize into incidentsDrive the RMF lifecycle with the urgency and precision required to maintain uninterrupted ATO status; an expired or revoked authorization means the mission stops, and this person owns preventing that outcomeServe as the trusted cybersecurity advisor to both contractor leadership and Government AOs; explain complex risk decisions in terms leadership can act on, and recommend accept/mitigate/avoid options with clear rationaleLead vulnerability management with a 'hunt and fix' mindset; do not wait for scan reports to tell you what is broken; actively assess the environment, prioritize by actual exploitability and mission impact, and drive remediation to completionArchitect security solutions that are integrated into system design from the start; work with the Systems, Network, and Development leads during planning phases so security is built in rather than retrofitted after deploymentManage incidents calmly and decisively; when a security event occurs, lead the containment, eradication, and recovery effort while maintaining clear communication to Government leadership about impact and statusBuild a cybersecurity team that thinks critically rather than mechanically; develop engineers who understand why a STIG control matters, not just how to implement it, so they can make sound judgment calls on novel situationsNavigate the complex relationship between mission urgency and security rigor; know when to push back on shortcuts that create unacceptable risk, and when to find creative solutions that enable time-critical mission needsMaintain productive working relationships with external cybersecurity organizations (ARCYBER, NETCOM, G-6, DISA) whose requirements and inspections directly impact PAE operations; anticipate their concerns and prepare accordinglyPWS Responsibility Summary:Implement Cybersecurity Program (PWS 1.16.4.1): Implements, leads, and manages the comprehensive Cybersecurity (CS) program, providing strategic input and security expertise across all levels of systems engineering, software design, and integration.RMF & ATO Management (PWS 1.16.4.2): Drives the Risk Management Framework (RMF) Assessment & Authorization (A&A) process to achieve and maintain full Authorization to Operate/Authorization to Connect (ATO/ATC) across all PAE Fires systems. Acts as the contractor's primary Point of Contact (POC) for all CS and IS Systems Engineering (ISSE) issues.Cross-Functional Network Security Integration (PWS 1.16.2.3):* Maintains cross-trained expertise in Network Security and Authorization to ensure cybersecurity governance decisions are informed by real-time network posture

During security incidents spanning network and server boundaries, independently assesses compromised segments, dictates immediate firewall reconfigurations, and validates baseline status without awaiting separate assessments from Network and Enterprise Architecture teams.Cross-Functional Configuration Management Oversight (PWS 1.16.5):* Cross-trained in Configuration Management to independently validate that CM baseline changes have been properly assessed for security impact, thereby accelerating the Change Control Board (CCB) approval cycle and ensuring rapid, secure deployments.Vulnerability Remediation & Threat Awareness: Leads vulnerability management with a proactive threat-hunting mindset, identifying and prioritizing remediation actions for all identified vulnerabilities and weaknesses, ensuring critical High and Moderate risks are addressed as the highest priority.