Cybersecurity - Information System Security Manager (issm)

Boeing Boeing · Aerospace · Herndon, VA

Cybersecurity Manager (ISSM) responsible for ensuring Information System Security policies, standards, and directives are enforced to support assessment, authorization, and continued operation of information systems processing classified information in classified computing domains.

What you'd actually do

  1. Performs security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards
  2. Leads and implements the Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF) for new and existing information systems
  3. Facilitates development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acknowledgement Letters (RAL) and support Continuous Monitoring (CONMON)
  4. Oversees configuration management of assigned systems; auditing systems to ensure security posture integrity
  5. Leads staff with assessments and test/analysis data to document state of compliance with security requirements

Skills

Required

  • Tier 5 Investigation (T5), formerly known as a Single Scope Background Investigation (SSBI) by the federal government within the last 5 years, or requires candidate to have been enrolled in a Continuous Vetting program within the last 5 years
  • Active Counterintelligence (CI) Polygraph
  • Currently hold certification in good standing to satisfy IAM Level III (CISSP, GSLC, or CISM)
  • 5+ years of experience with cyber security policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series

Nice to have

  • 5+ years of experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs
  • 5+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
  • 5+ years of experience assessing and documenting test or analysis data to show cyber security compliance

What the JD emphasized

  • Tier 5 Investigation (T5), formerly known as a Single Scope Background Investigation (SSBI) within the last 5 years
  • Active Counterintelligence (CI) Polygraph
  • IAM Level III (CISSP, GSLC, or CISM)
  • 5+ years of experience with cyber security policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series