Serves as a Supervisory IT Specialist in the NASEO Cybersecurity Group, AJW-B400. Duties Help
Manages a nationally diverse, multi-functional organization that is responsible for the strategic development of cybersecurity policy, evaluation of new technologies, effective reviews of system and service architectures and the proper application of international cybersecurity laws, policies, and guidance.
Combines knowledge of NAS systems and cybersecurity expertise to tactically apply information security/information assurance principles to track all planned changes to assigned systems, assessing planned changes to determine potential system security posture impact, ensure timely identification and reporting of planned NAS system changes with potential cybersecurity impact, and support Cyber Operations activity.
Manages projects, plans, and/or processes to ensure alignment with objectives, including schedule and constraints, and resolution of issues or technical problems.
Promotes cross team collaborates and external stakeholder engagement, as required, to ensure effective communication, transfer of information or accomplishment of process and procedures.
Strategically advises budget and resources planning decisions for both short-term and long-term needs utilizing advanced technical knowledge of work as well as budget, human resources, and applicable administrative policies and processes.
Ensures cybersecurity requirements, polices, principles, and practices are applied to all phases of the system lifecycle. This includes development and review of documentation, and coordination with program managers, system owners, acquisition planners and other decision-makers and supporting analysts within assigned due dates. Develops plans for IT security systems that anticipate, identify, evaluate, mitigate, and minimize risks associates with IT systems vulnerabilities in specific offices or complex applications.
Directs and assigns the work of subordinate employees of multiple organization and across multiple functions/ disciplines. Fosters a fair and equitable work environment, sets priorities and deadlines, assigns tasks and responsibilities, plans, and establishes work schedules, monitors, and evaluates performance, approves leaves, coaches and develops staff, and manages conduct and discipline as appropriate. Applies detailed knowledge of the technical aspects of the work directed, other administrative policies and procedures, and an understanding of the vision and objectives of the organization when communicating plans and strategies.
Assesses system engineering design and configuration changes for impact on security posture through involvement and oversight in System Configuration Monitoring & Management, Configuration Control Boards/ NAS Change Proposal reviews, and enterprise system configuration change assessments.
Applies advanced knowledge of FISMA and FIPS regulations.
Applies knowledge of NAS Enterprise Architecture, the Safety Management System, and the Acquisition Management System to ensure that cybersecurity is integrated into every aspect of NAS systems and services lifecycle from research and development through acquisition, implementation, operations, and decommissioning. NAS knowledge is essential to understand the business relationships and technical requirements to ensure all security series are maintained. Develops, reviews, and coordinates approval of the Information Security Guide for Systems Acquisitions (ISGSA) security assessments in support of system acquisition planning phases.