Information System Security Officer (CMMC Compliance)
![]() | |
![]() | |
![]() United States, California | |
![]() | |
The Opportunity: Under general supervision, develop and execute security controls, defenses and countermeasures to intercept and prevent internal or external attacks or attempts to infiltrate company email, data, e-commerce and web-based systems. Maintain hardware, software and network firewalls and encryption protocols. Administer cybersecurity policies to control physical and virtual access to systems. Perform network security audits and testing and evaluates system security configurations to ensure efficacy and compliance with policies and procedures. Conduct penetration testing and vulnerability assessments of applications, operating systems and/or networks. Provide information to management regarding impact on the business caused by theft, destruction, alteration or denial of access to information and systems.THE OPPORTUNITY: NuSil is seeking an Information System Security Officer to develop & administer a CMMC compliant information systems security program in support of our high-performance silicones business serving the Aerospace & Defense industries. WHAT WE'RE LOOKING FOR (EDUCATION): Bachelor's degree with three years of Information Security or related experience. In lieu of a degree, an additional four years of applicable work experience may be substituted. CERTIFICATIONS: CCP, CCA, CISSP, CISM or CISA preferred EXPERIENCE: Must have detailed knowledge of Cybersecurity Maturity Model Certification (CMMC) and/or NIST SP 800-171 with demonstrated experience in compliance assessment and risk management. Working knowledge of the National Industrial Security Program Operating Manual (NISPOM) and Defense Federal Acquisition Regulation Supplement (DFARS) preferred. THOSE NECESSARY TO PERFORM THE JOB COMPETENTLY:
PREFERRED QUALIFICATIONS:
HOW YOU WILL THRIVE AND CREATE AN IMPACT (MAJOR JOB DUTIES & RESPONSIBILTIES): The Information System Security Officer (CMMC Compliance) is responsible for tracking, managing, and overseeing compliance with Cybersecurity Maturity Model Certification (CMMC) requirements. This role includes managing the System Security Plan (SSP), Plan of Action and Milestones (POA&M), conducting cybersecurity risk assessments, and ensuring the protection of Controlled Unclassified Information (CUI). The ideal candidate will have extensive experience with NIST SP 800-171, continuous monitoring, and risk management/assessment.
Disclaimer: The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Avantor is proud to be an equal opportunity employer. Why Avantor? Dare to go further in your career. Join our global team of 14,000+ associates whose passion for discovery and determination to overcome challenges relentlessly advances life-changing science. Pay Transparency: The expected pre-tax pay for this position is $85,000.00 - $141,600.00Actual pay may differ depending on relevant factors such as prior experience and geographic location. EEO Statement: We are an Equal Employment/Affirmative Action employer and VEVRAA Federal Contractor. We do not discriminate in hiring on the basis of sex, gender identity, sexual orientation, race, color, religious creed, national origin, physical or mental disability, protected Veteran status, or any other characteristic protected by federal, state/province, or local law. If you need a reasonable accommodation for any part of the employment process, please contact us by email at recruiting@avantorsciences.comand let us know the nature of your request and your contact information. Requests for accommodation will be considered on a case-by-case basis. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this email address. For more information about equal employment opportunity protections, please view the Know Your Rights poster. 3rd Party Non-Solicitation Policy: By submitting candidates without having been formally assigned on and contracted for a specific job requisition by Avantor, or by failing to comply with the Avantor recruitment process, you forfeit any fee on the submitted candidates, regardless of your usual terms and conditions. Avantor works with a preferred supplier list and will take the initiative to engage with recruitment agencies based on its needs and will not be accepting any form of solicitation. |