Manager, ISS - Cybersecurity

<strong>Job Description</strong><br><br><strong>Job Summary:</strong><br><br>The Security Control Assessor / Cybersecurity Manager is responsible for performance of cybersecurity framework assessments to determine compliance with Government-mandated contractual cybersecurity regulatory certification. This includes: Cybersecurity Maturity Model Certification (CMMC) for Maturity Levels 1, 3, and 5, NIST SP 800-171, NIST SP 800-172, NIST SP 800-53 (RMF), ISO 27001, CIS, the NST Cybersecurity Framework, and many others. This role also serves as customer-facing CISO, providing continuous management of customer cyber policies, technical solution implementation, certification process guidance, and incident responder.<br><br><strong>Job Duties:</strong><br><ul> <li>Knowledge of applicable laws (e.g., Electronic Communications Privacy Act, Foreign Intelligence Surveillance Act, Protect America Act, search and seizure laws, civil liberties, and privacy laws), statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code), Presidential Directives, executive branch guidelines, and/or administrative/criminal legal guidelines and procedures relevant to work performed</li> <li>Knowledge of current and emerging cyber technologies</li> <li>Evaluates a system's compliance with information technology (IT) security, resilience, and dependability requirements </li> <li>Knowledge of computer networking concepts and protocols, and network security methodologies </li> <li>Ability to develop policy, plans, and strategy in compliance with laws, regulations, policies, and standards in support of organizational cyber activities</li> <li>Assesses the effectiveness of NIST 800-171/CMMC security controls </li> <li>Designs/integrates a cyber strategy that outlines the vision, mission, and goals that align with the organization's strategic plan. </li> <li>Drafts, staffs, and publishes cyber policy</li> <li>Develops methods to monitor and measure risk, compliance, and assurance efforts</li> <li>Develops specifications to ensure risk, compliance, and assurance efforts conform with security, resilience, and dependability requirements at the software application, system, and network environment level</li> <li>Drafts statements of preliminary or residual security risks for system operation. </li> <li>Maintains information systems assurance and accreditation materials</li> <li>Performs security reviews, identifies gaps in security architecture, and develops a security risk management plan</li> <li>Performs security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy</li> <li>Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change</li> <li>Plans and conducts security authorization reviews and assurance case development for initial installation of systems and networks</li> <li>Verifies that application software/network/system security postures are implemented as stated, documents deviations, and recommends required actions to correct those deviations</li> <li>Assesses policy needs and collaborates with stakeholders to develop policies to govern cyber activities </li> <li>Monitors the rigorous application of cyber policies, principles, and practices in the delivery of planning and management services </li> <li>Provides policy guidance to cyber management, staff, and users</li> <li>Reviews, conducts, or participates in audits of cyber programs and projects</li> <li>Supports the CIO in the formulation of cyber-related policies </li> <li>Interprets and applies applicable laws, statutes, and regulatory documents and integrate into policy </li> <li>Promotes awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization's mission, vision, and goals</li> <li>Knowledge of risk management processes (e.g., methods for assessing and mitigating risk) </li> <li>Knowledge of emerging technologies that have potential for exploitation by adversaries</li> <li>Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity </li> <li>Knowledge of specific operational impacts of cybersecurity lapses</li> <li>Ability to leverage best practices and lessons learned of external organizations and academic institutions dealing with cyber issues</li></ul><br><strong>Supervisory Responsibilities:</strong><br><ul> <li>Serves as a member of the consulting group's management team</li> <li>Supervises, develops, and trains associates and senior associates</li> <li>Reviews and evaluates work prepared by associates and senior associates</li> <li>Trains associates and senior associates on how to use current software tools and Industry Specialty Services methodology</li> <li>Schedules and supervises workload of associates and senior associates</li> <li>Provides verbal and written performance feedback to associates and senior associates</li> <li>Acts as a Career Advisor to associates and senior associates</li></ul><br><br><strong>Qualifications, Knowledge, Skills and Abilities:</strong><br><br><strong>Education:</strong><br><ul> <li>Bachelor's degree in Cybersecurity, Information Assurance, Information Technology, Software Engineering, Information Systems, Computer Science, Computer Engineering or other relevant field, required</li> <li>Master's degree, preferred</li></ul><br><strong>Experience:</strong><br><ul> <li>5 or more years of relevant experience including experience in Cybersecurity, information assurance, information technology, software engineering, information systems, computer science, computer engineering, required</li> <li>Prior experience in Risk Management Framework (RMF), Assessing NIST 800-171 or other cybersecurity Framework, preferred</li> <li>Prior experience in cyber architecture or systems/network administration or serving an IT role, preferred</li></ul><br><strong>License/Certifications: </strong><br><ul> <li>One (1) or more certifications, required: <ul> <li>Security +</li> <li>CISSP</li> <li>CISM</li> <li>CEH</li> <li>CHFI</li> <li>CySA+</li> <li>CCNA Security</li> <li>CAP</li> <li>CNDA</li> <li>CMMC Registered Practitioner</li> <li>CMMC Certified Assessor</li> </ul></li></ul><br><strong>Software:</strong><br><ul> <li>Proficient in Windows 10, Windows Server, Active Directory, Email platforms such as MS Exchange, preferred</li> <li>Cloud Platforms a plus (AWS, Microsoft Azure, Microsoft Office 365 GCC High), preferred</li></ul><br><strong>Hardware:</strong><br><ul> <li>Familiar with Firewalls, VPNs, IPS/IDS, Wifi, routers, network equipment, and general security concepts and secure configuration of network equipment, required</li> <li>Good knowledge of Network Security design and principles, required</li></ul><br><strong>Language:</strong><br><ul> <li>N/A</li></ul><br><strong>Other Knowledge, Skills & Abilities:</strong><br><ul> <li>Excellent oral and written communication skills, specifically business / report writing</li> <li>Strong analytical and basic research skills </li> <li>Solid organizational skills especially ability to meet project deadlines with a focus on details</li> <li>Ability to successfully multi-task while working independently or within a group environment</li> <li>Proven ability to work in a deadline-driven environment and handle multiple projects simultaneously </li> <li>Demonstrated command of Cybersecurity Assessment Frameworks (CMMC, NIST 800-171, NIST 800-53, ISO 27001, NIST CSF, CIS)</li> <li>Ability to follow and apply specific rules and regulations</li> <li>Ability to work with minimal supervision</li> <li>US citizenship required</li></ul><br>Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.<br><br>National Range: $130,000 - $150,000<br> NYC/Long Island/Westchester Range: $130,000 - $150,000<br> Maryland Range: $130,000 - $150,000<br><br><strong>About Us</strong><br><br>Join us at BDO, where you will find more than a career, you'll find a place where your work is impactful, and you are valued for your individuality. We offer flexibility and opportunities for advancement. Our culture is centered around making meaningful connections, approaching interactions with curiosity, and being true to yourself, all while making a positive difference in the world. <br><br>At BDO, our purpose of helping people thrive every day is at the heart of everything we do. Together, we are focused on delivering exceptional and sustainable outcomes and value for our people, our clients, and our communities. BDO is proud to be an ESOP company, reflecting a culture that puts people first, by sharing financially in our growth in value with our U.S. team. BDO professionals provide assurance, tax and advisory services for a diverse range of clients across the U.S. and in over 160 countries through our global organization.<br><br>BDO is the first large accounting and advisory organization to implement an Employee Stock Ownership Plan (ESOP). A qualified retirement plan, the ESOP offers participants a stake in the firm's success through beneficial ownership and a unique opportunity to enhance their financial well-being. The ESOP stands as a compelling addition to our comprehensive compensation and Total Rewards benefits* offerings. The annual allocation to the ESOP is fully funded by BDO through investments in company stock and grants employees the chance to grow their wealth over time as their shares vest and grow in value with the firm's success, with no employee contributions. <br><br>We are committed to delivering exceptional experiences to middle market leaders by sharing insight-driven perspectives, helping companies take business as usual to better than usual. With industry knowledge and experience, a breadth and depth of resources, and unwavering commitment to quality, we pride ourselves on:<br><br><ul> <li>Welcoming diverse perspectives and understanding the experience of our professionals and clients</li> <li>Empowering team members to explore their full potential</li> <li>Our talented team who brings varying skills, knowledge and experience to proactively help our clients navigate an expanding array of complex challenges and opportunities</li> <li>Celebrating ingenuity and innovation to transform our business and help our clients transform theirs</li> <li>Focus on resilience and sustainability to positively impact our people, clients, and communities</li> <li>BDO Total Rewards that encompass so much more than traditional "benefits." Click here to find out more!</li></ul><br>*Benefits may be subject to eligibility requirements.<br><br>Equal Opportunity Employer, including disability/vets<br><br>Click here to find out more!

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...