CALIBRE Systems, inc., an employee-owned, mission focused solutions and digital transformation company is seeking a highly experienced and professional Information Systems Security Officer (ISSO) / Information Systems Security Manager (ISSM) to support a Department of War (DoW) cybersecurity modernization initiative focused on Risk Management Framework (RMF) execution, continuous monitoring, compliance automation, and enterprise adoption of RegScale. This role will serve as the onsite primary cybersecurity compliance lead and trusted advisor to government stakeholders, cybersecurity personnel, system owners, and senior leadership.
The successful candidate will possess considerable expertise in RMF, DoW cybersecurity policy requirements, and project management. The individual will play a critical role in driving the implementation and adoption of RegScale while ensuring compliance with federal and DoW cybersecurity standards.
This position will be performed onsite at Aberdeen Proving Grounds (APG) and will be in support of systems on the DoW SIPRNet environment. This position will be on site.
Responsibilities
- Serve as the onsite lead ISSO/ISSM supporting cybersecurity authorization and compliance efforts across multiple DoW systems.
- Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes.
- Act as onsite liaison between ASA(ALT) and Team CALIBRE to provide continued technical and product support for the RegScale application.
- Installation of software and experience with databases and OS installation and configuration.
- Provide expert guidance on all phases of the Risk Management Framework (RMF) lifecycle, including system categorization, control implementation, assessment, authorization, and continuous monitoring.
- Act as the organization's primary subject matter expert for eMASS, ensuring accurate management of authorization packages, security controls, inheritance relationships, POA&Ms, and system artifacts.
- Maintain the RegScale accreditation throughout the SDLC, to include develop, maintain, and review security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action & Milestones (POA&Ms), and Standard Operating Procedures (SOPs).
- Coordinate with government leadership, ISSMs, ISSOs, system owners, security control assessors, and engineers to ensure compliance with DoW cybersecurity requirements.
- Conduct RegScale and eMASS user training sessions and provide ongoing support to stakeholders throughout the authorization process.
- Support vulnerability management activities, including ACAS review, DISA STIG compliance, remediation tracking, and POA&M management for the RegScale application.
- Identify opportunities across ASA(ALT) and Army organizations to automate compliance activities, improve operational efficiencies, and streamline enterprise cybersecurity processes.
- Provide executive-level reporting, risk assessments, and recommendations to government and program leadership.