Cybersecurity – Information System Security Officer (isso)

Boeing Boeing · Aerospace · Oklahoma City, OK

Cybersecurity Information System Security Officer (ISSO) role at Boeing supporting classified computing domains. Responsibilities include developing and deploying program information security, implementing Risk Management Framework (RMF), performing continuous monitoring, and supporting DFARS and CMMC requirements. Requires IAM Level 1 DoD 8140.01 compliant certification and 3+ years of experience in cybersecurity policies and RMF.

What you'd actually do

  1. Assist in the development and deployment of program information security for assigned systems to meet the program and enterprise requirements, policies, standards, guidelines and procedures
  2. Implement Risk Management Framework (RMF) processes, product development and product maintenance for assigned systems
  3. Perform security compliance continuous monitoring
  4. Participate in security assessments and audits
  5. Prepare and present technical reports and briefings

Skills

Required

  • IAM Level 1 DoD 8140.01 (previously 8570.01) compliant certification (i.e. CAP, Security+ CE, CISSP, CASP, CISM, GSLC)
  • 3+ years of experience in cybersecurity policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series
  • Active U.S. Secret Security Clearance

Nice to have

  • IAM Level III certification (CISSP, GSLC or CISM)
  • 3+ years of experience as an Information System Security Officer (ISSO) or Information System Security Manager (ISSM) supporting classified programs
  • 3+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
  • 3+ years of experience assessing and documenting test or analysis data to show cyber security compliance

What the JD emphasized

  • IAM Level 1 DoD 8140.01 (previously 8570.01) compliant certification
  • 3+ years of experience in cybersecurity policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series
  • Support Defense Federal Acquisition Regulation Supplement (DFARS) and Cybersecurity Maturity Model Certification (CMCC) requirements