Cybersecurity - Information System Security Officer (isso)

Boeing Boeing · Aerospace · El Segundo, CA +1

Seeking a Cybersecurity - Information System Security Officer (ISSO) to join a Classified Operations Cybersecurity team. Responsibilities include performing security analysis, supporting Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF), managing system configurations, conducting risk assessments, and ensuring compliance with cybersecurity requirements for classified information systems.

What you'd actually do

  1. Perform security analysis of operational and development environments, threats, vulnerabilities, and internal interfaces to define and assess compliance with accepted industry and government standards
  2. Support and implement the Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF) for new and existing information systems
  3. Facilitate development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acceptance Letters (RAL) and support Continuous Monitoring (CONMON)
  4. Perform configuration management of assigned systems; auditing systems to ensure security posture integrity
  5. Conduct risk assessments and investigations, execute appropriate risk mitigations, and participate in incident response activities

Skills

Required

  • Tier 5 Investigation (T5) or Continuous Vetting program enrollment within the last 5 years
  • IAM Level 1 DoD 8140.03 compliant certification (e.g., Security+ CE, CAP, CISSP, CASP, CISM, GSLC)
  • 3+ years of combined experience and/or education in cybersecurity, IT, or a related field
  • 3+ years of experience with the Risk Management Framework (RMF), cybersecurity policies, and RMF implementation (e.g., DAAG, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series)
  • Active U.S. Top Secret/SCI Security Clearance

Nice to have

  • 3+ years of experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs
  • 3+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
  • 3+ years of experience assessing and documenting test or analysis data to show cyber security compliance

What the JD emphasized

  • Tier 5 Investigation (T5), formerly known as a Single Scope Background Investigation (SSBI) by the federal government within the last 5 years
  • IAM Level 1 DoD 8140.03 (previously 8570.01) compliant certification
  • 3+ years of experience with the Risk Management Framework (RMF), cybersecurity policies, and RMF implementation