Hi Jason,
They way I see it this is not possible. As you said the callmanager actually listens to port 80 and then forwards everything to 8080.
If you block the port 80 then you would not be able to send any traffic to cucm. I believe this requires tweaking and it will no longer be a supported platform from TAC perspective.
That's my opinion if I understood correctly.
Regards,
Christos