Information System Security Manager (ISSM)
About the role
The role involves ensuring information system security objectives are met and managing organizational risk. Key responsibilities include serving as the ISSO for collateral systems, leading inspections, assessments, and audits, and executing system authorizations.
Responsibilities
- Ensure information system(s) security objectives are achieved and organizational risk is effectively managed.
- Lead SAP/SCI classified IT system(s) and serve as ISSO for collateral systems and alternate COMSEC custodian.
- Execute and maintain system authorization using RMF and applicable guidance.
- Develop, maintain, and validate cybersecurity plans, authorization artifacts, and compliance documentation.
- Identify, assess, and communicate cybersecurity risk to senior leadership and Authorizing Officials.
- Lead continuous monitoring activities, including evaluation of security posture, validation of control effectiveness, and tracking of security-relevant data.
- Drive closure of Plans of Action and Milestones (POA&Ms).
- Execute or coordinate corrective and protective security actions.
- Engage with Program Managers to integrate cybersecurity requirements.
- Coordinate with other cybersecurity teams across the enterprise.
- Prepare and deliver cybersecurity status reporting.
Requirements
- Active and transferable U.S. government issued security clearance required on day one.
- U.S. citizenship required, as only U.S. citizens are eligible for a security clearance.
- Active DOD Security Clearance day one.
- Active US Government TOP SECRET level security clearance preferred.
- IAM Level III certification compliant with DoD 8570 / DoD 8140 (e.g., CISSP, CISM, GSLC).
- Advanced knowledge of RMF and DoD system authorization processes.
Qualifications
- Typically requires a University Degree and minimum 10 years prior relevant experience or an Advanced Degree in a related field and minimum 7 years of experience.
- Experience as the primary ISSM for SAP and/or DoD collateral systems.
- Experience owning ATOs and driving POA&M closure.
- Experience working with cross-functional teams and enterprise cybersecurity organizations.
- Strong written and verbal communication skills for senior leadership briefings.
- Experience in the oversight and execution of the Assessment & Authorization processes (Certification & Accreditation), as defined in JSIG/RMF.
- Experience in the execution and management of Information System’s (IS) incident response and administrative inquiries/investigations in collaboration with the Investigations department.
- Experience in and execution of a continuous monitoring/improvement program (to include but not limited to self-inspections, security control assessments, training, log management systems, automated inventory utilities, etc.).
- Experience providing technical security expertise and oversight for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT) and other RTX Business Units.
- Experience with NISPOM, JAFAN 6/3, DCID 6/3, JSIG/RMF, and ICD-503 or equivalent requirements to include technical computer/network system auditing.
- Experience in professional engagements with internal and external customers (i.e., AOs, DAOs, SCAs, Program Managers, etc.), to include negotiating controls/requirements with government Contracting Activities.
- Experience executing authorization and continuous monitoring using JSIG and/or DAAG.
- Knowledge of cybersecurity regulations, contractual requirements, and DD Form 254 interpretation.
- Experience supporting inspections, assessments, and audit activities.
- Ability to independently assess risk and communicate cybersecurity status to leadership.
- Experience performing ISSM responsibilities for classified or controlled information systems.
Benefits
The salary range for this role is 132,400 USD - 251,600 USD. RTX provides various benefits including medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Pay
The salary range provided is a good faith estimate representative of all experience levels.
Schedule
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.