Cybersecurity ISSE (Principal)
Senior
Application Security
Continuous Monitoring
Cybersecurity Tools
Data Security
Engineer
Enterprise Risk
Facilities Management
Information Security
InfoSec
Nist Cybersecurity Framework
Project Management
Risk Management
Security
Security Compliance
Security Operations
Security Standards
Security Testing
Solution Architecture
Job Description
Cybersecurity Principal ISSE supporting the EPASS GB contract in Kettering, OH, with a focus on risk assessment, RMF/CSF/NIST alignment, security controls, ISCM strategy, and collaboration with information security staff.
Responsibilities
- Provide cybersecurity support to the PMO and Capability Development Manager per DoWI 8500.01.
- Assess and continuously monitor cybersecurity risk to ensure legacy and new capabilities adhere to RMF, CSF, and NIST standards, following the Authorization Official’s ISCM strategy.
- Apply best practices for security controls across software engineering, system and security engineering, secure design and architecture, and secure coding techniques.
- Coordinate security-related activities with the information security architect, ISSM, ISSO, ISO, and common control providers.
- Complete required training and maintain certifications in accordance with AFI 17-1303.
- Acquire and maintain cybersecurity certifications as prescribed by AFMAN 17-1303.
- Keep all Air Force IT cybersecurity documentation current and accessible to properly authorized personnel.
- Assist the PM or ISO in maintaining current authorization to operate, approval to connect where required, and implementing corrective actions identified in the plan of actions and milestones.
- Collaborate with PM and AO staff to develop an ISCM strategy and monitor changes to the system and its environment.
- Continuously monitor IT environments for security-relevant events.
- Evaluate proposed configuration changes for potential impact on the cybersecurity posture.
- Assess the quality of security controls against defined performance indicators.
- Ensure cybersecurity events or configuration changes that affect AF IT authorization or security posture are formally reported to the AO and affected stakeholders, including IOs, stewards, and AOs of interconnected IT.
- Ensure ISSOs and privileged users receive necessary technical training and cybersecurity certification per AFMAN 17-1301, AFMAN 17-1303, and maintain required clearances per DoWI 8500.01.
- Ensure Air Force IT is acquired, documented, operated, used, maintained, and disposed of properly per DoWI 5000.02 and DoWI 8510.01.
Requirements
- U.S. Citizenship required.
- Bachelor's degree in a related field and 10 years of experience in the relevant technical/professional discipline.
- Experience providing guidance on access control, configuration management, system and communications protection, contingency planning, incident handling, and system and information integrity.
- Security and privacy training and awareness; software development activities and tools related to cybersecurity.
- Experience performing cybersecurity duties as described in DoWI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT.
- Experience validating, evaluating, and analyzing findings and developer adjudications using automated testing tools such as Fortify, Checkmarx, SonarQube, and AppScan.
- Experience using DoW tracking systems to document cybersecurity deficiencies, vulnerabilities, and change requests in Jira, HP ALM, and eMASS.
- Experience conducting information security continuous monitoring to maintain ongoing awareness of information security, vulnerabilities, and threats per the approved ISCM strategy.
- Must meet and maintain a DCWF Information Systems Security Developer (ISSD) work role 631 at an advanced principal proficiency level per DoWI 8510.01, AFMAN 17-1305, and AFI 17-101 for assigned systems/applications; includes:
- FITSP-D is required; GIAC GCSA; CISSP-ISSEP (ISC)2.
- Active T3/Secret security clearance.
Technologies
- Fortify
- Checkmarx
- SonarQube
- AppScan
- Jira
- HP ALM
- eMASS
- Mavin
- Confluence
- BitBucket
Benefits
- ESOP participation
- 401(k) match
- Medical, dental, and vision insurance
- Life insurance
- Short-term and long-term disability
- Flexible spending accounts
- Health Savings Accounts
- Health Reimbursement Accounts
- Employee Assistance Program
- Education assistance
- Paid time off and holidays
Schedule
- Monday through Friday, 8:00 am to 5:00 pm
Work Location
- Kettering, OH (onsite)
Travel
- Yes, 0-10%
Relocation Assistance
- No
Position Contingent Upon Award
- No