Cybersecurity Manager - Lead ISSO-EN
About Us
CAE’s vision is to be the worldwide partner of choice in defense and security, and civil aviation by revolutionizing our customers’ training and critical operations with digitally immersive solutions to elevate safety, efficiency and readiness.
CAE's Defense and Security business unit focuses on helping prepare military customers to develop and maintain the highest levels of mission readiness. Our values—Empowerment, Innovation, Excellence, Integrity and OneCAE—define who we are and guide us in making a difference in the world while helping each other succeed.
We offer a comprehensive and competitive benefits package, flexibility that promotes work-life balance, a work environment where all employees are valued, respected and safe, freedom to succeed by enabling team members to deliver and take initiatives, recognition, professional development, advancement opportunities, and a culture of fun.
About the Role
The Cybersecurity Manager leads all cybersecurity and Risk Management Framework (RMF) activities for the C-17 Training System, ensuring full compliance with contract requirements and U.S. Government directives. This role oversees planning, staffing, execution, and continuous governance of the cybersecurity program, including NISPOM/DAAPM/JSIG RMF, eMASS workflow, and customer-specific Information Assurance requirements. Serving as the primary security interface with internal and external stakeholders, the manager coordinates cybersecurity proposal inputs and Basis of Estimate (BOE) development, maintains the cybersecurity program schedule, and provides oversight to all Information System Security Officers (ISSOs).
Responsibilities
- Plan, organize, staff, manage, and control the C-17 TS Cybersecurity/Risk Management Framework (RMF) Program across 16 geographically separated locations.
- Manage the preparation, review, and submission of RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms).
- Ensure that system security controls are correctly implemented, continuously monitored, and aligned with USAF and DoD requirements.
- Guide the team through the accreditation process to achieve and maintain Authorization to Operate (ATO) status for all systems.
- Ensure accuracy of eMASS documents and ACAS scans.
- Integrate cybersecurity measures into all aspects of C-17 simulation and sustainment systems, including hardware, software, and network configurations.
- Oversee vulnerability assessments, penetration tests, and system security audits to identify and address potential risks.
- Collaborate with sustainment and simulation engineers to ensure secure integration of system updates, patches, and new capabilities without compromising security posture.
- Manage and respond to security incidents, ensuring timely containment, investigation, and reporting.
- Ensure compliance with DoD, USAF, and NIST policies, including NIST SP 800-53, NIST SP 800-171, and DoD 8500.01.
- Work closely with USAF leadership, IT, and engineering sustainment teams to ensure all systems supporting C-17 simulation and training systems are compliant.
- Interface with external auditors, inspectors, and regulatory bodies to support security assessments and address compliance issues.
- Act as the primary point of contact for cybersecurity matters related to C-17 simulation and sustainment systems, coordinating with program managers, system engineers, and external stakeholders.
- Communicate complex cybersecurity risks and issues to non-technical personnel and leadership in a clear and concise manner.
- Prepare and present reports on the security status of systems, risks, and recommended mitigations to USAF leadership and program stakeholders.
- Develop and deliver cybersecurity training and awareness programs to team members and system users involved in C-17 sustainment and simulation activities.
- Foster a security-conscious culture within the team, ensuring adherence to security best practices across all activities.
- Manage day-to-day progress of ISSO support staff in maintaining government compliance.
- Responsible for scheduling personnel, managing labor and material expenditures, attending meetings, managing delivery schedules, and coordinating configuration management activities.
- Ensure a safe and secure work environment is established and maintained.
- Provide supervision and oversight of ISSO cyber resources and personnel.
Requirements
- Bachelor’s Degree in Information Technology, Cybersecurity, Data Science, Information Systems, Computer Science or related field.
- A minimum of 8 years of experience in the cybersecurity field.
- Information Assurance Manager (IAM) Level I (Level II preferred) or Information Assurance Technician Level II certification in accordance with DoD 8570-01 or corresponding level under DoD 8140.
- Proficiency in Microsoft Excel, PowerPoint, Project, and Word.
- High performance and capability to work in a team environment.
- Ability to effectively deliver oral presentations to management and customers.
- Ability to work independently with minimal supervision.
- Willingness to work overtime, any shift, or day of the week as required.
- Understanding of military protocols and customs is essential.
- Domestic and international travel as required.
- Eligibility for DoD Personal Security Clearance (U.S. citizenship required due to U.S. Government contract requirements).
Security Responsibilities
- Comply with all company security and data protection/usage policies and procedures.
- Personally responsible for proper marking and handling of all information and materials, in any form.
- Shall not divulge any information, or afford access, to other employees not having a need-to-know.
- Shall not divulge information outside the company without management approval.
- All government and proprietary information will be accessed and stored electronically on company-provided resources.
Work Environment
Work is typically performed in a professional office setting using standard IT and office equipment. Occasional domestic and international travel may be required. Work may involve exposure to operational training environments that include risks associated with electrical systems, hydraulics, elevated temperatures, airborne particles, and loud noise levels.
Physical Demands
- Ability to walk, climb stairs, and access simulator or cockpit environments.
- Ability to stoop, bend, and crawl on or under training devices when necessary.
- Ability to detect environmental indicators such as odors or noises associated with mechanical or electrical issues.
- Ability to distinguish colors required for system indicators, wiring, or display diagnostics.