EngineerJobs.io
← Back to all jobs

Job Description

Support Air Force Intelligence Community (AF IC) Risk Management Framework (RMF) modernization efforts at Lackland AFB, TX with cybersecurity engineering and automation for classified systems.

Responsibilities

  • Correlate threat data from multiple sources to identify hacker activity and the modus operandi within client networks.
  • Produce assessments and reporting that improve situational awareness of current cyber threats and adversaries.
  • Develop cyber threat profiles by geographic region, country, group, or individual actors.
  • Create cyber threat assessments using entity threat analysis.
  • Provide computer forensic and intrusion support for high technology investigations, including computer evidence seizure, forensic analysis, data recovery, and network assessments.
  • Research and maintain proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding, and network security and encryption.
  • Collaborate with intrusion analysts to identify, report on, and coordinate remediation of cyberthreats.
  • Deliver timely, actionable sanitized intelligence to support cyber incident response professionals.
  • Apply knowledge of computer systems and networks, paired with threat intelligence, to evaluate client security posture.
  • Conduct intelligence analysis to assess intrusion signatures and tactics, techniques, and procedures associated with cyber attack preparation and execution.
  • Research hackers, techniques, vulnerabilities, exploits, and brief leadership with detailed intelligence reports.
  • Engineer cybersecurity solutions for DoD and Intelligence Community information systems.
  • Design, implement, and document security controls aligned to NIST SP 800-53 Rev. 5 and applicable CNSSI 1253 overlays.
  • Build security architectures supporting Zero Trust, cloud, hybrid, and on-premises environments.
  • Integrate cybersecurity requirements across the System Development Life Cycle (SDLC).
  • Support Authority to Operate (ATO), Continuous Authorization (cATO), and Continuous Monitoring (ConMon).
  • Develop and maintain RMF authorization artifacts.
  • Engineer automated evidence collection and validation processes.
  • Create reusable security control implementations and standardized control inheritance strategies.
  • Support OSCAL-based RMF automation.
  • Design and implement AI-assisted capabilities for RMF documentation, evidence management, and compliance analysis.
  • Develop Retrieval-Augmented Generation (RAG) workflows for cybersecurity documentation.
  • Use Natural Language Processing (NLP) to analyze RMF artifacts and surface documentation inconsistencies.
  • Develop machine learning and rule-based models.
  • Implement human-in-the-loop validation for all AI-generated outputs and apply Responsible AI principles and AI governance.
  • Develop automated RMF workflows and integrate cybersecurity controls into CI/CD pipelines.
  • Implement Security-as-Code and Policy-as-Code.
  • Build dashboards for cybersecurity metrics, authorization status, and continuous monitoring.
  • Integrate automation with eMASS, Xacta, ServiceNow, Vuln Management platforms, and enterprise asset inventories.
  • Engineer automated collection of cybersecurity evidence supporting continuous monitoring and integrate security tooling.
  • Develop automated compliance scoring and risk dashboards, and provide technical recommendations supporting authorization decisions.
  • Support modernization of enterprise RMF processes across AF IC environments.

Requirements

  • Clearance Required: Top Secret/SCI
  • DoD 8140 IAT III certification required: CISSP, ISSEP, ISSAP, or CGRC
  • Experience: 10 years in one or more of: Cybersecurity Engineering, RMF implementation, Security Architecture, DevSecOps, Continuous Monitoring, Security Automation
  • Minimum experience: 5 years supporting DoD or Intelligence Community cybersecurity programs
  • Experience with eMASS, Xacta, NIST RMF, DoD RMF, AF IC cybersecurity processes, and classified information systems
  • Demonstrated experience with: NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199 and 200, DoD RMF, CNSSI, ICD 50, OSCAL implementation, machine-readable RMF artifacts, Zero Trust Architecture, cATO, security engineering principles, DevSecOps, and security automation
  • Programming/automation: Python, PowerShell, REST APIs, JSON/XML, Git, CI/CD platforms, integrating with enterprise APIs and cybersecurity platforms
  • AI-assisted cybersecurity: Large Language Models (LLMs), RAG, NLP, prompt engineering, vector databases, document intelligence, AI governance, and human-in-the-loop validation

Technologies

  • CISSP, ISSEP, ISSAP, CGRC
  • NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199, FIPS 200
  • DoD RMF, CNSSI, ICD 50, OSCAL
  • Zero Trust Architecture, Continuous Authorization (cATO), DevSecOps, Continuous Monitoring (ConMon), SDLC
  • eMASS, Xacta, ServiceNow, Vuln Management, enterprise asset inventories
  • Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD Platforms
  • Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), Natural Language Processing, prompt engineering, vector databases, document intelligence
  • Human-in-the-loop validation, machine learning, rule-based models, AI governance
  • Security-as-Code, Policy-as-Code

Location

  • Lackland AFB, TX (onsite)

Salary

  • USD 160,000 - 200,000 per year

Overview

  • Support advanced AF IC RMF modernization initiatives with technical leadership for cybersecurity engineering, RMF automation, and AI-enabled compliance capabilities.
  • Located at Lackland AFB, TX and performed onsite.
  • Focus on engineering and automating RMF processes, improving authorization efficiency, enhancing continuous monitoring, and integrating AI-assisted analysis into cybersecurity governance workflows.
  • Support system owners, ISSMs, ISSOs, Authorizing Officials (AOs), and Security Control Assessors (SCAs) by developing automation capabilities and engineering solutions.
  • Does not perform independent security control assessments to preserve RMF assessment independence.

Preferred Skills and Experience

  • Experience with the Space Force's network environment.

Similar Jobs