Position Description & QualificationsSerco is seeking a highly experienced
Security Engineerto provide Security Control Assessor Representative (SCAR) support to the Air Force Life Cycle Management Center (AFLCMC) under AFMS 3.0 Task Order 1. The selected candidate will support Security Control Assessors (SCAs) and Authorizing Officials (AOs) in conducting security control assessments, supporting Assessment and Authorization (A&A) activities, implementing Risk Management Framework (RMF) requirements, and ensuring cybersecurity compliance across Modeling and Simulation (M&S) systems, networks, ranges, and operational training environments. The position supports AFLCMC cybersecurity operations and ensures Information Assurance (IA), Computer Network Defense (CND), Continuous Monitoring (CM), and vulnerability management activities are effectively executed.
In this role, you will:
- Perform Security Control Assessor Representative (SCAR) duties in support of Assessment and Authorization (A&A) activities for simulators, networks, ranges, operational training systems, and M&S environments.
- Assist Security Control Assessors and Authorizing Officials in evaluating and validating security controls and overall cybersecurity compliance.
- Monitor, evaluate, and maintain systems and procedures designed to protect information systems, databases, and networks from unauthorized access, disclosure, modification, or destruction.
- Identify potential cybersecurity threats, vulnerabilities, and compliance deficiencies and develop risk mitigation recommendations.
- Investigate reported security incidents and violations, determine root causes, and recommend corrective and preventive actions.
- Support Risk Management Framework (RMF) activities, including security assessments, authorization packages, security documentation reviews, and continuous monitoring activities.
- Review security requirements, assessment and authorization documentation, and security control implementations for operational test and training infrastructure systems.
- Develop, implement, and improve Computer Network Defense (CND) and Information Assurance Vulnerability Management (IAVM) programs across classified and unclassified environments.
- Review and assess program Plans of Action and Milestones (POA&Ms).
- Provide cybersecurity expertise and recommendations regarding DoD, Air Force, and RMF policies and procedures.
To be successful in this role, you will have:
- Active DoD Secret Security clearance.
- A Bachelor's Degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related technical field and 8 related experience;
- OR an Associate Degree's in Computer Science, Cybersecurity, Information Systems, Engineering, or a related technical field and 10 years of related experience.
- Experience supporting DoD cybersecurity programs, Assessment and Authorization (A&A) efforts, or Risk Management Framework (RMF) activities.
- Experience conducting security assessments, vulnerability assessments, compliance reviews, and risk analysis.
- Knowledge of NIST security controls, RMF processes, and Information Assurance requirements.
- Experience identifying cybersecurity risks and implementing effective mitigation strategies.
- Strong written and verbal communication skills with the ability to prepare technical reports, findings, and briefings.
- The ability to travel up to 10%.
Additional desired experience and skills:
- Active DoD Top Secret Security clearance with SCI eligibility.
- Experience serving as a SCAR, ISSM, ISSO, Security Control Assessor, or cybersecurity compliance lead.
- Experience supporting AFLCMC, AFAMS, Operational Test and Training Infrastructure (OTTI), or M&S environments.
- Experience with Continuous Monitoring (CM), POA&M management, and cybersecurity compliance reporting.
- Knowledge of DoDI 8510.01, NIST SP 800-53, and Air Force cybersecurity policies.
- Experience supporting classified and Special Access Required (SAR) environments.
- One or more of the following certifications is desired:
- CISSP
- CASP+
- Security+ CE
- CISM
- GSLC
- CCSP