Cybersecurity - Senior Information System Security Manager (issm)

Boeing Boeing · Aerospace · Berkeley, MO +1

This role is for a Senior Information System Security Manager (ISSM) at Boeing, focusing on cybersecurity for systems handling Controlled Unclassified Information (CUI) in compliance with DFARS, NIST SP 800-171, and CMMC requirements. The position involves leading a team, performing security analysis, overseeing configuration management, conducting risk assessments, and interfacing with government customers and stakeholders to ensure continuous compliance and protection of CUI.

What you'd actually do

  1. Leads a team of Information System Security Managers (ISSMs) and Information System Security Officers (ISSOs) performing cybersecurity governance work on CUI, DFARS, and CMMC systems
  2. Performs security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards
  3. Oversees configuration management of assigned systems; auditing systems to ensure security posture integrity
  4. Leads staff with assessments and test/analysis data to document state of compliance with security requirements
  5. Conducts risk assessments and investigations, execute appropriate risk mitigations, and oversee incident response activities

Skills

Required

  • IAM Level III certification (CISSP, GSLC, or CISM)
  • 10+ years of IT/cybersecurity experience
  • 5+ years of experience with Risk Management Framework (RMF)
  • 5+ years of experience with cybersecurity policies and RMF implementation
  • 5+ years of experience utilizing security relevant tools (NESSUS, ACAS, DISA, STIGs, SCAP, Audit Reduction, HBSS)
  • 5+ years of cybersecurity leadership experience
  • 1+ years of experience implementing DFARS 252.204-7012/NIST SP 800-171 controls and mapping to CMMC

Nice to have

  • Bachelor's degree or equivalent work or military experience
  • 5+ years of experience as an ISSO or ISSM supporting classified programs
  • 5+ years of experience assessing and documenting test or analysis data for cybersecurity compliance

What the JD emphasized

  • DFARS
  • NIST SP 800-171
  • CMMC
  • CUI
  • RMF
  • cybersecurity governance
  • IAM Level III (CISSP, GSLC, or CISM)