Cybersecurity - Information System Security Manager (ISSM)
BoeingAbout the role
Company:
The Boeing CompanyJob ID:
00000439476Date Posted:
2024-11-22Location:
USA - Oklahoma City, OKJob Description Qualifications:
East Region Classified Cybersecurity is seeking a highly motivated Cybersecurity – Information System Security Manager (ISSM) to join the team in Oklahoma City, OK.
The selected candidate will rely on cybersecurity and Information Assurance (IA) background to be a technical leader and support Enterprise activities and Boeing customers throughout multiple classified computing domains. The ISSM is responsible for ensuring all Information System Security policies, standards, and directives are enforced to support assessment, authorization and continued operation of information systems processing classified information.
Position Responsibilities:
Performs security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards
Leads and implements the Assessment and Authorization (A&A) processes under the Risk Managed Framework (RMF) for new and existing information systems
Facilitates development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acceptance Letters (RAL) and support Continuous Monitoring (CONMON)
Configures management of assigned systems; auditing systems to ensure security posture integrity
Leads staff with assessments and test/analysis data to document state of compliance with security requirements
Conducts risk assessments and investigations, implements appropriate risk mitigations, and coordinates incident response activities
Conducts periodic hardware/software inventory assessments
Serves as organization spokesperson on sophisticated projects and programs
Acts as advisor to management and customers on sophisticated technical research studies
Collaborates with the appropriate government customers, suppliers, and company personnel to implement protective mechanisms and to ensure understanding of and compliance with cybersecurity requirements
Supports and understands Defense Federal Acquisition Regulation Supplement (DFARS) and Cybersecurity Maturity Model Certification (CMCC) requirements, NIST 800-171, and contractual DFARS clauses
Additional Responsibilities:
Supervises the development and deployment of program information security for all program systems to meet the program and enterprise requirements, policies, standards, guidelines and procedures
Handles assigned team to facilitate effective execution of Risk Management Framework (RMF)
Provides guidance and mentor to support team within Information Security
Leads and performs security compliance continuous monitoring
Coordinates and participates in security assessments and audits
Prepares, reviews, and presents technical reports and briefings
Identifies root causes, prioritizes threats and recommends and/or implements corrective action
Explores the enterprise and industry for evolving state of industry knowledge and methods regarding information security best practices
Leads development of enterprise-wide information security policies, standards, guidelines and procedures that may reach across multiple partner organizations
This position is expected to be 100% onsite. The selected candidate will be required to work onsite at one of the listed location options.
This position requires an active U.S. Secret Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance active in the past 24 months is considered active.)
Basic Qualifications (Required Skills/Experience):
Currently hold certification in good standing to satisfy IAM Level III (CISSP, GSLC or CISM)
3+ years of experience in utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include: NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
Preferred Qualifications (Desired Skills/Experience):
Bachelor's degree or equivalent work or military experience
3+ years of experience with cybersecurity policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, and/or NIST SP 800 series
3+ years of experience as an information system s
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s