JobHabor
Location
Sierra Vista, AZ, United States
Workplace
Employment
Salary
Apply on the employer’s site

ECS is seeking a CISO to work in our Sierra Vista, AZ office.

The Chief Information Security Officer will serve as the senior cybersecurity leader and principal security advisor to the Program Manager for The Army Endpoint Security Solution (AESS). This role is responsible for protecting the service delivery environment, including back-end and front-end security infrastructure, endpoints, servers, networks, customer-facing services, and supporting operational platforms.

The CISO will lead cybersecurity governance, risk management, information assurance, security operations, compliance, documentation, and policy activities across the program. The role provides oversight of Information Assurance and Security Operations Center personnel and ensures program alignment with DoD requirements, RMF, NIST SP 800-53, DoD security baselines, DISA STIGs, ACAS scanning, continuous monitoring, vulnerability management, and Zero Trust principles.

  • Senior security advisor to the Program Manager on cybersecurity risk, compliance, security operations, incident response, and mission assurance matters.
  • Lead the cybersecurity strategy for the AESS.
  • Oversee Information Assurance and SOC personnel, including day-to-day security operations, compliance activities, documentation, reporting, and process improvement.
  • Ensure the security of service delivery infrastructure, including endpoint security platforms, backend systems, frontend services, servers, networks, administrative access paths, and customer-facing capabilities.
  • Provide oversight of SOC, including monitoring, alert triage, incident response, threat hunting, detection engineering, escalation management, SIEM/EDR operations, and security reporting.
  • Lead Information Assurance activities, (RMF support, control documentation, evidence collection, assessment readiness, POA&M management, continuous monitoring, and security authorization support).
  • Ensure compliance with NIST SP 800-53, DoD cybersecurity requirements, DoD security baselines, DISA STIGs, ACAS scanning requirements, and applicable customer security policies.
  • Oversee vulnerability management activities, (ACAS scan coordination, findings analysis, remediation tracking, risk reporting, and compliance validation).
  • Ensure STIG compliance is implemented, documented, reviewed, and maintained across applicable endpoints, servers, applications, databases, infrastructure, and network devices.
  • Develop, maintain, and enforce cybersecurity policies, standards, plans, procedures, playbooks, runbooks, and security documentation.
  • Establish/maintain program-level cybersecurity risk management process, (risk identification, tracking, mitigation recommendations, and risk reporting).
  • Advise on security impacts of architecture changes, service enhancements, onboarding/offboarding activities, integrations, and operational changes.
  • Provide regular security posture updates to the Program Manager, customer stakeholders, and internal leadership.
  • Track/report key security metrics, (incident trends, vulnerability status, POA&M progress, compliance posture, SOC performance, and remediation activities).
  • Coordinate with endpoint engineering, infrastructure, network, systems administration, identity, cloud, service desk, compliance, and operations teams.
  • Support audits, assessments, inspections, cybersecurity reviews, and contract deliverables.
  • Mentor and guide security personnel while promoting a culture of accountability, mission support, and continuous improvement.

General Description of Benefits

  • Active Top Secret clearance.
  • Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related discipline.
  • Minimum of 12 years of cybersecurity experience.
  • Demonstrated experience supporting Department of Defense environments.
  • Experience in a senior cybersecurity leadership, information assurance, security operations, security architecture, or cyber risk management role.
  • Strong knowledge of RMF, NIST SP 800-53, DoD cybersecurity requirements, DISA STIGs, DoD security baselines, POA&M management, continuous monitoring, and vulnerability management.
  • Experience overseeing SOC activities, including security monitoring, alert triage, incident response, threat hunting, detection engineering, escalation, and reporting.
  • Familiarity with endpoint security, infrastructure security, network security, server security, identity and access management, logging, monitoring, and vulnerability management technologies.
  • Strong understanding of Zero Trust concepts and their application in enterprise or government environments.
  • Excellent written and verbal communication skills, including the ability to brief technical risk to program leadership, government customers, and non-technical stakeholders.
  • Must be local to the Sierra Vista, AZ
  • CISSP or CISM
  • ITIL Certification

Skills

  • ECS
  • NIST
  • Zero Trust
  • SIEM
  • EDR
  • CISSP

More jobs at Ecsfederal

All 203