Journeyman Cybersecurity Engineer
Job Description
Lead cybersecurity assurance and continuous compliance support for the AOC Weapon System at Hanscom AFB in the C3C/Kessel Run division.
Responsibilities
- Own the Assessment & Authorization (A&A) effort to obtain and maintain the system Authorization to Operate (ATO) via eMASS
- Oversee continuous monitoring (ConMon) activities across multi-classification networks, including vulnerability scanning with ACAS/Nessus and configuration hardening using DISA STIGs
- Manage security incident reporting, conduct root-cause analysis, and develop corrective action plans / POA&Ms
- Ensure cybersecurity is integrated throughout the AOC Weapon System lifecycle in support of the AO and in accordance with DoDI 8510.01
- Complete and maintain required cybersecurity certification per AFMAN17-1303
- Keep AF IT cybersecurity documentation current and accessible to authorized users (per AFI17-101, 6 FEBRUARY 2020)
- Support the PM or ISO in maintaining current authorization to operate and approval to connect, including implementation of corrective actions in the plan of action and milestones
- Coordinate with PM and AO staff to develop and maintain an ISCM strategy, monitoring proposed and actual changes to the system and environment
- Continuously monitor IT and the environment for security-relevant events, evaluate the impact of proposed configuration changes, and assess control implementation quality using performance indicators
- Ensure cybersecurity-relevant events and configuration changes that affect AF IT authorization or degrade security posture are formally reported to the AO and other affected parties (including IOs, stewards, and AOs of interconnected IT)
- Support proper acquisition, documentation, operation, use, maintenance, and disposal of AF IT in accordance with DoDI 5000.02 and DoDI 8510.01
- Process Firewall Exemption Requests (FERs)
- Approve change requests including Critical Security Updates
- Support installation, configuration, and maintenance of ACAS components, including:
- Nessus scanners
- SecurityCenter/Tenable.sc
- Nessus Network Monitor (NNM)/Tenable.asm
- Assist with scheduling and executing vulnerability scans using Nessus scanners
- Analyze scan results to identify vulnerabilities and misconfigurations
- Assist compliance assessments against DoD standards and internal security policies
- Produce reports covering vulnerability status, compliance posture, and remediation progress
- Partner with system administrators to support vulnerability remediation efforts
- Assist with system administration tasks for ACAS servers and databases
- Track and stay current with vulnerability trends and security threats
Requirements
- US citizen
- Must have and be able to maintain a Secret Level Clearance
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related technical field
- 5+ years of dedicated D0D cybersecurity experience executing RMF under NIST SP 800-53
- IAM Level III Certification (Certified Information Systems Security Professional / Certified Information Security Officer)
- Basic understanding of networking concepts and protocols
- Familiarity with Windows and Linux operating systems
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
Preferred Qualifications
- Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm)
- Security+ or other relevant cybersecurity certifications
- Experience with scripting languages such as Python or PowerShell
- Familiarity with DoD security policies and procedures
Technologies
- RMF, NIST SP 800-53, eMASS, ACAS, Nessus
- SecurityCenter/Tenable.sc, Nessus Network Monitor (NNM)/Tenable.asm
- DISA STIGs, ISCM, AF IT
- DoDI 8510.01, AFMAN17-1303, AFI17-101, DoDI 5000.02
- Python, PowerShell
Logistics
- Travel: Limited; as needed
- Job Status: Full-time
- Location: Hanscom AFB, Bedford, MA 01731 (onsite)
Salary
- USD 120,000 - 130,000 per year