Overview
Principal Cybersecurity Engineer
LOCATION: Hanscom AFB, Bedford, MA
Salary Range: $170-$185,000 annually*
JOB STATUS: Full-time
CLEARANCE: TOP SECRET
CERTIFICATION: CISSP
TRAVEL: Limited; as needed
Astrion has an exciting opportunity for a Principal Cybersecurity Engineer located at Hanscom AFB in Bedford Massachusetts providing support to the Air Force Life Cycle Management Center-Ground Base Air Defense Sensor division (AFLCMC/ESG). The ESG Division manages efforts focused on developing, acquiring, fielding and sustaining programs that support worldwide communications, Battle Management, Command & Control, Intelligence, Surveillance & Reconnaissance (C2ISR), Air/Ground Surveillance, Time Critical Targeting, Combat Identification, Radar Imagery, Integrated Air/Missile Defense, and Mobile/Fixed C2ISR Performance, Exploitation & Dissemination Facilities.
Qualifications / Skills
- Citizenship: Must be a US citizen
- Clearance: Must be able to maintain a Top Secret Level Clearance
- Education: BS/BA Degree
- Years of Experience: 20 years of experience in the respective technical/professional discipline being performed, 10 of which must be in the DoD
- Proficieny in:
- Risk Management Framework (RMF), with empasis on taking projects from Step 1 to Step 5
- Vulnerability Management, Tenable Nessus (ACAS-DoD version of Nessus)
- STIGs
- CISSP Certification
Preferred Qualifications /Skills
- Experience with Cross Domain Solutions and USAF CDS-E
- Cloud Service Models
- Supply Chain Security
- NIAP
- DoD Policies for Procedures for Cybersecurity
- Network Security
- Endpoint
- DoD Impact Levels
- NSA Type 1 encryption
- Working with a CSSP - 16th AF
Responsibilities
Duties include, but not limited to:
Cybersecurity & RMF Support
- Lead development and review of system security documentation including System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, and security CONOPS in accordance with DoDI , DoDI , MIL-STD-1785, and the Adaptive Acquisition Framework
- Support system and application Authorization & Accreditation (A&A) activities under the Risk Management Framework (RMF), ensuring completeness, quality, and compliance of all artifacts
- Manage RMF implementation activities including ATO/ATC, reciprocity, and ongoing continuous monitoring
- Administer and manage eMASS system packages
System, Network & Infrastructure Security
- Provide technical leadership in network and system architecture design with an emphasis on cybersecurity, including DoD and joint networking environments
- Support cross-domain solutions (CDS), Commercial Solutions for Classified (CSfC), and NSA approval processes
- Assess and mitigate system, network, and application vulnerabilities, including ACAS scanning and STIG implementation
- Recommend security configurations, software changes, and compensating controls to mitigate risk
Risk, Compliance & Policy
- Conduct cybersecurity risk and vulnerability assessments across planned and fielded systems
- Develop risk-based mitigation strategies and advise leadership on security tradeoffs impacting mission execution
- Recommend and update cybersecurity policies, procedures, and contingency plans, including disaster recovery
- Support waivers and deviations for mandated security controls when required to meet mission performance needs
Program Security & Classified Information Support
- Provide acquisition program security support throughout the system lifecycle, including source selections
- Maintain and audit classified information databases, visit records, clearance tracking, and classified holdings
- Evaluate contractor classified data submissions for compliance with System Security Classification Guides (SSCGs)
- Update security classification guides and prepare acquisition security documentation
Leadership, Collaboration & Training
- Advise government leadership on cybersecurity design, implementation, and compliance
- Collaborate with government and commercial stakeholders to achieve RMF authorization approvals
- Develop and deliver cybersecurity awareness and training programs
Principal Cybersecurity Engineer in bedford at Unknown Company
This position is listed as contract and onsite.