OCH Technologies is seeking a
Cybersecurity Engineer to support the assessment and operations teams by maintaining scanning infrastructure, building and managing sandboxing and simulation test environments, evaluating new cybersecurity tools for FAA approval, and performing specialized testing of equipment against FAA performance and cybersecurity requirements. This role is the technical backbone that keeps the assessment and pen testing teams productive. Candidate will support building the environments they test in, maintain the tools they test with, and evaluate the equipment the FAA is considering adding to its approved list.
This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.
LocationHybrid- William J. Hughes Technical Center (WJHTC) Egg Harbor, NJ
OR Air Traffic Control System Command Center (ATCSCC) Washington, DC
This position has the potential to travel up to 25%.
Core Responsibilities & Duties - Design, prepare, and maintain sandboxing and simulation test environments for penetration testing, red/blue team exercises, and specialized equipment evaluations.
- Maintain and administer vulnerability scanning infrastructure including Nessus, WebInspect, and related platforms.
- Perform specialized testing and evaluation of industry equipment (switches, firewalls, KVMs, TAPs, data diodes, Palo Alto appliances) against FAA and ATO cybersecurity requirements.
- Evaluate NAS edge devices being considered for deployment by NAS system owners. Gather requirements, conduct assessments, and produce written evaluation reports.
- Identify and evaluate emerging cybersecurity tools and technologies for potential adoption. Conduct risk analysis considering operational safety impact, data handling, supply chain risk, and integration complexity.
- Support pre- and post-scan activities for NAS systems. Coordinate scanning schedules with system owners.
- Develop and maintain technical documentation for test environments, tool configurations, and standard operating procedures.
- Support the NCO Technical Lead with monitoring tool deployment, log source integration, and detection rule development as needed.
- Provide technical support during on-site assessment and penetration testing events as needed.
Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.
Requirements
Minimum Qualifications Education Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution.
Experience - A minimum of eight (8)+ years of experience in cybersecurity engineering, security operations engineering, or related technical roles in federal or critical infrastructure environments. At least 2 years of relevant experience must be recent (performed within the last 3 years).
- Hands-on experience administering and configuring vulnerability scanning platforms (Nessus, WebInspect, or equivalents).
- Experience building and managing isolated test and simulation environments.
- Understanding of network architecture, firewall configuration, IDS/IPS deployment, and network segmentation.
- Experience evaluating cybersecurity tools and equipment against security requirements and producing written technical evaluations.
- Scripting/automation skills (Python, Bash, PowerShell) for tool integration, data processing, and workflow automation.
Security Clearance Requirement Candidate must have the ability to obtain and maintain a Public Trust
Certifications - At least one of the following risk assessment certifications required: CISSP, GCED (GIAC Certified Enterprise Defender), CASP (CompTIA Advanced Security Practitioner), or CISA (Certified Information Systems Auditor).
- Vendor-specific certifications (Palo Alto PCNSE, Cisco CCNP Security) a plus for specialized equipment evaluation work.
Preferred Qualifications - Understanding of NAS or critical infrastructure network architectures.
- Prior experience at WJHTC or other FAA test facilities.
- Experience with ICS/SCADA security tooling and assessment.
- Experience with container-based or virtualized test environment management.
- Familiarity with FAA-approved equipment lists and the ACG equipment evaluation process.
- Infrastructure-as-code (Terraform, Ansible) for repeatable, version-controlled test environment builds rather than manual standup.
- Container orchestration (Docker, Kubernetes) for building isolated, reproducible sandbox and simulation environments for red/blue team exercises.
- CI/CD pipeline security tooling (CodeQL, Semgrep, Trivy) for evaluating software supply chain risk in candidate NAS equipment and applications.
- AI/ML model evaluation tools for assessing the security posture of AI-enabled systems being introduced into NAS infrastructure.