Cybersecurity Engineer or Technician— Portable Doppler Radar (PDR)
Job Description
Own cybersecurity for fielded Air Force Portable Doppler Radar (PDR) systems and supporting software, focused on patching, DISA STIG scanning, Tenable/ACAS scanning, and RMF/ATO evidence for often air-gapped deployments (not a SOC).
Responsibilities
- Own the Air Force PDR patch process: plan, test, package, and apply OS and application patches to radar servers and operator stations on the recurring AF calendar
- Run quarterly DISA STIG scans (including the Q2 STIG cycle) across Linux, Windows, web, database, and application stacks used by PDR and related systems
- Perform Tenable (Nessus / ACAS) scanning, triage findings, remediate or document residual risk using POA&Ms, and generate packages the USAF program office will accept
- Maintain the security baseline for fielded, often air-gapped radars, including offline updates, local accounts, certificates, SSH, firewall configuration, and adherence to customer constraints (including no-Java / isolated networks)
- Collaborate with Watch and related software so authentication, TLS, logging, containers, ports, and configuration changes remain inside the accredited baseline
- Keep RMF / ATO evidence current: STIGs, scan outputs, hardware/software inventory, configuration baselines, and change records
- Coordinate with EWR engineering in Kirkwood and with USAF PDR stakeholders for patch, STIG, and Tenable review cycles
- Occasional travel to U.S. or international customer sites; day-to-day work from the Kirkwood office
Requirements
- U.S. citizenship
- Ability to obtain and maintain a DoD Secret clearance (active Secret preferred)
- Hands-on DISA STIG execution experience, including applying STIGs (not only reading them), using tools such as STIG Viewer, SCC, Evaluate-STIG, or equivalent
- Hands-on Tenable or ACAS experience: scanning, false-positive handling, remediation, and residual-risk write-ups
- Linux administration for non-cloud-console servers (RHEL, Ubuntu, or similar), including packages, services, firewall, and logs/certificates
- Windows server/workstation hardening in a DoD context
- Patch management experience for systems that cannot be casually rebooted or updated from the internet
- Clear written English for scan reports, POA&Ms, and patch notes that a program office can file
Technologies
- C#, .NET, Linux, Docker
- DISA STIG, Tenable (Nessus / ACAS), STIG Viewer, SCC, Evaluate-STIG
- RHEL, Ubuntu, Windows, SSH, TLS
- nginx, Apache, PostgreSQL
- RMF, NIST SP 800-53, NIST SP 800-37, NIST SP 800-171, CMMC
- CompTIA Security+, CySA+, CISSP
Clearance
- Must be a U.S. citizen and able to obtain and maintain a DoD Secret security clearance
- Employment is contingent on remaining eligible for Secret
- Active Secret is preferred, but sponsorship may be possible to start
- Cannot hold the job if unable to be granted Secret
Strongly Preferred
- Active Secret clearance
- DoD RMF experience (NIST SP 800-53 / 800-37) supporting an ATO or ongoing authorization
- DISA STIG experience for nginx/Apache, PostgreSQL, .NET, and Docker/containers, plus Windows
- CMMC / NIST SP 800-171 experience in a small contractor environment
- Enough C# / .NET or application-security background to work alongside Watch developers
- Docker/nginx on Linux experience in offline or field-deployed systems
- CompTIA Security+, CySA+, CISSP, or another DoD 8140/8570 baseline certification
- Prior USAF, USMC, or other DoD C5ISR / weather / radar / industrial-control adjacent work
Benefits
- 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
How Work Is Structured
- EWR is a small manufacturer (tens of people); you own cybersecurity for PDR and related products across servers, scan tools, and paperwork
- Work alongside engineering in Kirkwood, not in a separate security department
- Resume should name specific STIGs, scanners, OS versions, and programs you have touched
- Include clearance status (active Secret, previously held, or eligible/never held)
- “Familiar with NIST” without scan/remediation evidence is not competitive
Not this role: 9-to-5 SOC watching SIEM alerts; GRC-only with no system access; cloud-native “zero trust in AWS” work. These radars are physical and often isolated, and must stay operational.