Cybersecurity - Information System Security Manager (issm)

Boeing Boeing · Aerospace · Kent, WA +1

Seeking a Cybersecurity Manager (ISSM) to lead and enforce security policies, manage Assessment and Authorization (A&A) processes under RMF, conduct risk assessments, and oversee incident response for classified computing environments. Requires a strong background in cybersecurity, IA, and RMF implementation.

What you'd actually do

  1. Performs security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards
  2. Leads and implements the Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF) for new and existing information systems
  3. Facilitates development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acknowledgement Letters (RAL) and support Continuous Monitoring (CONMON)
  4. Oversees configuration management of assigned systems; auditing systems to ensure security posture integrity
  5. Leads staff with assessments and test/analysis data to document state of compliance with security requirements

Skills

Required

  • Cybersecurity policies
  • Risk Management Framework (RMF)
  • IAM Level III certification (CISSP, GSLC, or CISM)
  • Tier 5 Investigation (T5) or Continuous Vetting program enrollment

Nice to have

  • Information System Security Officer (ISSO) experience
  • Information System Security Manager (ISSM) experience
  • NESSUS
  • ACAS
  • DISA STIGs
  • SCAP
  • Audit Reduction
  • HBSS
  • Test or analysis data assessment

What the JD emphasized

  • Successfully completed Tier 5 Investigation (T5), formerly known as a Single Scope Background Investigation (SSBI) by the federal government within the last 5 years, or requires candidate to have been enrolled in a Continuous Vetting program within the last 5 years
  • Currently hold certification in good standing to satisfy IAM Level III (CISSP, GSLC, or CISM)
  • 3+ years of experience with cyber security policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series
  • 3+ years of experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs
  • 3+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
  • 3+ years of experience assessing and documenting test or analysis data to show cyber security compliance