Information Systems Security Manager (government)

AT&T AT&T · Telecom · San Antonio, TX

Information Systems Security Manager for AT&T Global Public Sector supporting the Defense Information Systems Agency (DISA) in a Department of War (DoW) environment. Responsibilities include contractual compliance, developing A&A artifacts (ATO packages), overseeing adherence to NIST SP 800-53, DoD Cloud SRG, STIGs, conducting continuous monitoring, vulnerability management, ST&E, and supporting CMMC Level 2 readiness. Requires a Secret clearance and specific DoD 8570.01/8140 certifications.

What you'd actually do

  1. Support the Program Manager in execution of contractual compliance.
  2. Develop and maintain Assessment & Authorization (A&A) artifacts, including Authority to Operate (ATO) packages (Interim ATOs, continuous ATOs)
  3. Oversee adherence to NIST SP 800-53 controls and DoD Cloud Security Requirements Guide (SRG); ensure compliance with Security Technical Implementation Guides (STIGs) and cloud security policies.
  4. Conduct continuous monitoring (log audits, vulnerability scans); track and drive remediation of open Plans of Action & Milestones (POA&M) related to identified security weaknesses.
  5. Plan and execute Security Test & Evaluation (ST&E) activities; validate the platform’s security posture through penetration tests, STIG checks, and compliance assessments.

Skills

Required

  • DoD or DISA IT service programs experience
  • CISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC certification
  • continuous monitoring experience
  • eMASS experience
  • STIGs experience
  • vulnerability management experience

Nice to have

  • FedRAMP+ requirements familiarity
  • cloud security architecture familiarity

What the JD emphasized

  • contractual compliance
  • Assessment & Authorization (A&A) artifacts
  • Authority to Operate (ATO) packages
  • NIST SP 800-53 controls
  • DoD Cloud Security Requirements Guide (SRG)
  • Security Technical Implementation Guides (STIGs)
  • continuous monitoring
  • vulnerability scans
  • Plans of Action & Milestones (POA&M)
  • Security Test & Evaluation (ST&E)
  • penetration tests
  • STIG checks
  • compliance assessments
  • Cyber Threat Security Plan
  • supply chain risk management
  • CMMC Level 2 readiness