Cybersecurity - Senior Information System Security Manager (issm)

Boeing Boeing · Aerospace · Fairfax, VA

Senior Information System Security Manager (ISSM) responsible for maintaining and enforcing Information System Security policies, standards, and directives for classified computing domains, managing Risk Management Framework (RMF) processes, and ensuring assessment and authorization of information systems.

What you'd actually do

  1. Lead the development and deployment of program information security for assigned systems to meet the program and enterprise requirements, policies, standards, guidelines and procedures
  2. Manage Risk Management Framework (RMF) processes, product development and product maintenance for assigned systems
  3. Manage and perform security compliance continuous monitoring
  4. Lead and participate in security assessments and audits
  5. Prepare, review, and present technical reports and briefings

Skills

Required

  • Cybersecurity policies
  • Risk Management Framework (RMF)
  • Information Assurance (IA)
  • Security assessments and audits
  • Technical reports and briefings
  • Threat identification and corrective action
  • Information security best practices
  • Enterprise-wide information security policies, standards, guidelines and procedures
  • Tier 5 Investigation (T5) / SSBI / Continuous Vetting
  • IAM Level III certification (CISSP, GSLC, or CISM)
  • NIST SP 800 series
  • SCI Program access
  • Counterintelligence Polygraph

Nice to have

  • Information system security officer (ISSO) or ISSM supporting classified programs
  • NESSUS
  • ACAS
  • DISA STIGs
  • SCAP
  • Audit Reduction
  • HBSS
  • Assessing and documenting test or analysis data for cyber security compliance

What the JD emphasized

  • Successfully completed Tier 5 Investigation (T5), formerly known as a Single Scope Background Investigation (SSBI) by the federal government within the last 5 years, or requires candidate to have been enrolled in a Continuous Vetting program within the last 5 years
  • Currently hold certification in good standing to satisfy IAM Level III (CISSP, GSLC, or CISM)
  • 5+ years of experience in cybersecurity policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series
  • Ability to obtain access to Sensitive Compartmented Information (SCI) Programs
  • Active Counterintelligence Polygraph with ability to obtain a Full Scope Polygraph