Cybersecurity – Information System Security Officer (isso)

Boeing Boeing · Aerospace · Mesa, AZ

The Boeing Company is seeking a Cybersecurity – Information System Security Officer (ISSO) in Mesa, AZ. This role involves maintaining and implementing Information System Security policies, standards, and directives to ensure assessment and authorization of information systems processing classified information within multiple classified computing domains. Responsibilities include performing security analysis, leading A&A processes under RMF, overseeing configuration management, conducting risk assessments, and serving as a spokesperson on advanced projects.

What you'd actually do

  1. Perform security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards
  2. Lead and implement the Assessment and Authorization (A&A) processes under the Risk Managed Framework (RMF) for new and existing information systems
  3. Facilitate development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acceptance Letters (RAL) and support Continuous Monitoring (CONMON)
  4. Oversee configuration management of assigned systems; auditing systems to ensure security posture integrity
  5. Partner with Information Technology, Program Engineering, and Management with security requirements

Skills

Required

  • IAM Level 1 DoD 8140.03 (previously 8570.01) compliant certification (i.e. Security+ CE, CAP, CISSP, CASP, CISM, GSLC)
  • 3+ years of combined experience and/or education in cybersecurity, IT, or a related field
  • 3+ years of experience with the Risk Management Framework (RMF), cybersecurity policies, and RMF implementation (e.g., DAAG, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series)
  • active U.S. Secret Security Clearance

Nice to have

  • 3+ years of experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs
  • 3+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
  • 3+ years of experience assessing and documenting test or analysis data to show cyber security compliance

What the JD emphasized

  • Risk Management Framework (RMF)
  • cybersecurity policies
  • RMF implementation
  • classified computing domains
  • active U.S. Secret Security Clearance