INFORMATION SYSTEMS SECURITY MANAGER-ALTERNATE HIRING AUTHORITY
Click on "Learn more about this agency" button below for IMPORTANT additional information. The primary purpose of this position, Information Systems Security Manager, GG-2210-13, is to serve as the as the ISSM for the Air Force Sensitive Compartmented Information network. As the lead cybersecurity network authority you will oversee authorization boundaries, guide security policy, and ensure bulletproof defense-in-depth across multiple mission-critical networks within the secure facility.
Major duties
- Cybersecurity Leadership & Governance: Direct all cybersecurity controls, risk assessments, and compliance processes for classified and unclassified systems across AFLCMC SCI facilities.
- Team Oversight & Policy Direction: Provide strategic direction, mentoring, and technical oversight to facility ISSOs, ensuring synchronized network security practices across all assigned SCIFs.
- Network & Systems Protection: Maintain total operational integrity and security management of AFSCI network environments, encompassing workstations, server stacks, specialized interfaces, and boundary connections.
- Executive Subject Matter Expertise: Serve as principal cybersecurity advisor to the Senior Intelligence Officer (SIO), driving policy interpretation, proactive risk management, and long-range security roadmaps.
Qualifications
An ideal candidate's resume for the Air Force ISSM position would showcase extensive experience in cybersecurity program leadership, particularly within Sensitive Compartmented Information (SCI) environments. The resume should highlight expert-level knowledge of the Risk Management Framework (RMF), evidenced by successful system accreditations and the management of Assessment and Authorization (A&A) packages using tools like Xacta, eMASS, etc. It would detail a strong background in conducting IT audits, managing COMSEC cryptographic equipment, and developing security policies aligned with DoD, IC, and Air Force directives. The candidate would also list desirable certifications such as CISSP, CISM, CISA, etc. (WRC 722 - Advanced) and possess a TOP SECRET clearance with SCI eligibility, demonstrating a proven ability to manage high-stakes national security systems and communicate complex technical information to senior leadership. In order to qualify, you must meet the quality experience requirements described in the Office of Personnel Management (OPM) Qualification Standards, Information Technology (IT) Management Series 2210. BASIC REQUIREMENT OR INDIVIDUAL OCCUPATIONAL REQUIREMENT: For all positions individuals must have IT-related experience demonstrating each of the four competencies listed below. Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, considering the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. In addition to meeting the basic requirement above, to qualify for this position you must also meet the qualification requirements listed below: EXPERIENCE REQUIRED: Your resume must reflect the quality level of experience which demonstrates the possession of the knowledge, skills, abilities, and competencies necessary for successful job performance required for this position. Examples of creditable experience include: Direct experience serving as an Information Systems Security Manager (ISSM) or Information System Security Officers (ISSO) or Intelligence Community (IC) information systems; Proven, hands-on experience managing the full Assessment & Authorization (A&A) lifecycle using the Risk Management Framework (RMF); Demonstrated experience developing and maintaining core RMF documentation, including the System Security Plan (SSP), security control assessments, and managing a Plan of Action & Milestones (POA&M); and expertise in interpreting and implementing security controls from NIST SP 800-53 and ICD 503 within classified environments. KNOWLEDGE, SKILLS AND ABILITIES (KSAs): Your qualifications will be evaluated on the basis of your level of knowledge, skills, abilities and/or competencies in the following areas: 1. Expert knowledge of a full range of IT security principles, concepts, practices, new and emerging products and services (including systems software, database software, immediate access storage technology, and firewalls), and methods for evaluating risk and vulnerability, implementing mitigating improvement, disseminating IT security tools and procedures, and integration techniques. 2. Broad knowledge of IT INFOSEC security requirements for certification and accreditation, network operations and protocols, systems testing and evaluation, and performance management methods sufficient to plan and conduct security accreditation reviews for installed systems or networks and assess and advise on new revised security measures and countermeasures based on the results of accreditation reviews. 3. Expert knowledge of a broad range of telecommunications concepts and principles, operating modes, systems, media, equipment, equipment configuration, related software systems, advise on vulnerability to attack from a variety of sources (e.g., espionage, disruption of services, destructive programs/applications) and procedures methods for protection of systems and applications. 4. Ability to communication effectively, both orally and in writing, in order to produce technical reports and/or briefings for multiple forums and audiences and ability to make decisions independently in a self-directed manner in support of a team and/or organizational goals. 5. Ability to develop and conduct training on information technology and information security. PART-TIME OR UNPAID EXPERIENCE: Credit will be given for appropriate unpaid and or part-time work. You must clearly identify the duties and responsibilities in each position held and the total number of hours per week. VOLUNTEER WORK EXPERIENCE: Refers to paid and unpaid experience, including volunteer work done through National Service Programs (i.e., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community; student and social). Volunteer work helps build critical competencies, knowledge and skills that can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience. Additional Information: Position is designated special-sensitive and requires eligibility for access to Sensitive Compartmented Information (SCI), other intelligence-related Special Sensitive information, or involvement in Top Secret Special Access Programs (SAP) to fully perform the duties and responsibilities of the position. A non-disclosure agreement must be signed. This position has been designated by the Air Force as a Testing Designated Position (TDP) under the Air Force Civilian Drug Demand Reduction Program. Employee must pass initial and periodic short notice drug testing. Illegal drug use by employees in sensitive positions presents a clear threat to the mission of the Air Force, national security, and public safety. Cyberspace Qualification is a condition of employment. This position includes Cyberspace work as a paramount duty requirement. Per DoDM 8140.03, para 4.2.a.(2)., requires foundational qualification requirements within 9 months of assignment to a cyberspace work role and resident qualification requirements within 12 months of assignment to a cyberspace work role. A waiver of these requirements may be granted per DoDM 8140.03. Failure to achieve and maintain the proper Cyberspace Qualification may result in removal from this position. Position is designated as a DoD Cyber Workforce position in the 'Oversight and Governance (OV)' and 'Cybersecurity (CS)' categories (WRCs 722 [Advanced], 805 [Intermediate]) under the 'Cybersecurity' workforce element and 'Securely Provision' category (WRC 801 [Basic]) under the Cyber Enabler workforce element
Education
IF USING EDUCATION TO QUALIFY: If position has a positive degree requirement or education forms the basis for qualifications, you MUST submit transcripts with the application. Official transcripts are not required at the time of application; however, if position has a positive degree requirement, qualifying based on education alone or in combination with experience, transcripts must be verified prior to appointment. An accrediting institution recognized by the U.S. Department of Education must accredit education. Click here to check accreditation. FOREIGN EDUCATION: Education completed in foreign colleges or universities may be used to meet the requirements. You must show proof the education credentials have been deemed to be at least equivalent to that gained in conventional U.S. education program. It is your responsibility to provide such evidence when applying.