OverviewJourneyman Cybersecurity Engineer (ISSM)
LOCATION: Hanscom AFB, Bedford, MA
SALARY RANGE: $120,000.00 - $130,000.00 Annually
JOB STATUS: Full-time
CLEARANCE: Secret
CERTIFICATION: IAM Level III Certification
TRAVEL: Limited; as needed
Astrion has an exciting opportunity for a Journeyman Cybersecurity Engineer located at the Hanscom AFB in Bedford, MA providing support to the Command, Control, Communications (C3C)/Kessel Run division.
Kessel Run is an Air Force unit that delivers resilient command and control and targeting software capabilities that provide warfighters with decision advantage. Under the Department of the Air Force Program Executive Office for Command, Control, Communication, and Battle Management (DAF PEO C3BM), Kessel Run technologies make up the DAF BATTLE NETWORK, the systems-of-systems designed to help the Joint Force make operational decisions faster than our adversaries. The Division architects and acquires the means to connect weapon systems with warfighters and decision makers to enable the warfighter to win against the pacing challenge in an era of great power competition.
REQUIRED QUALIFICATIONS / SKILLS:
PREFERRED QUALIFICATIONS / SKILLS:
- Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm).
- Security+ or other relevant cybersecurity certifications.
- Experience with scripting languages such as Python or PowerShell.
- Familiarity with DoD security policies and procedures
RESPONSIBILITIES:
Primary cybersecurity advisor to the Program Manager and Authorizing Official (AO) charged with securing and accrediting the AOC weapon system, which orchestrates global air operations. This role bridges the gap between traditional RMF compliance and modern, continuous DevSecOps pipeline security
- Lead the Assessment & Authorization (A&A) process to obtain and maintain the system's Authorization to Operate (ATO) using the Enterprise Mission Assurance Support Service (eMASS)
- Oversee continuous monitoring (ConMon) strategies, vulnerability scanning (using ACAS/Nessus), and configuration hardening (DISA STIGs) across multi-classification networks
- Manage security incident reporting, perform root-cause analysis, and develop corrective action plans / POA&Ms
- Ensures the integration of cybersecurity into, and throughout the lifecycle of the Air Operations Center (AOC) Weapon System, on behalf of the AO and in accordance with DoDI 8510.01
- Completes and maintains required cybersecurity certification IAW AFMAN17-1303. Individuals in this position must be U.S. citizens
- Ensures all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals. AFI17-101 6 FEBRUARY 2020 15
- Supports the PM or ISO in maintaining current authorization to operate, and approval to connect and in implementing corrective actions identified in the plan of action and milestones
- Coordinates, with the PM and AO staffs, development of an ISCM strategy and monitor any proposed or actual changes to the system and its environment
- Continuously monitors the IT and environment for security-relevant events, assess proposed configuration changes for potential impact to the cybersecurity posture, and assess the quality of security controls implementation against performance indicators
- Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the AO and other affected parties, such as IOs and stewards and AOs of interconnected IT
- Ensures the AF IT is acquired, documented, operated, used, maintained, and disposed of properly and IAW DoDI 5000.02 and DoDI 8510.01
- Process Firewall Exemption Requests (FERs)
- Approve change requests (i.e.: Critical Security Updates)
- Assist with the installation, configuration, and maintenance of ACAS components, including Nessus scanners, SecurityCenter/Tenable.sc, and Nessus Network Monitor (NNM)/Tenable.asm.
- Assist in scheduling and executing vulnerability scans using Nessus scanners.
- Analyze scan results to identify vulnerabilities, and misconfigurations.
- Assist with compliance assessments against DoW standards and internal security policies.
- Generate reports on vulnerability status, compliance posture, and remediation progress.
- Collaborate with system administrators to facilitate vulnerability remediation efforts.
- Assist with system administration tasks for ACAS servers and databases.
- Stay up to date on the latest vulnerability trends and security threats.