Industrial Control System (ICS) Cybersecurity Engineer
Job Description
ASRC Federal is seeking an Industrial Control System (ICS) Cybersecurity Engineer to support cybersecurity engineering and RMF execution for KAFB owned and operated control systems in Albuquerque, NM (onsite). In this role, you will serve as an Information System Security Officer (ISSO), providing technical leadership across cybersecurity requirements and authorization activities while supporting the lifecycle of industrial control environments.
Key Responsibilities
- Support the implementation and ongoing maintenance of cyber security requirements within control networks.
- Provide technical guidance for standardizing control systems and shaping operational technology network architecture across the enterprise.
- Specify control systems, instrumentation, and supporting equipment, and assist with procurement activities.
- Provide RMF support to obtain and maintain Authority to Operate (ATO) approvals for multiple networks.
- Create and maintain required RMF documentation and artifacts in Enterprise Mission Assurance Support Services (eMASS).
- Perform software assurance and risk assessments for multiple software packages.
- Conduct and review vulnerability and compliance scans of information system hardware and software, and guide remediation of security flaws and configuration issues.
- Review and monitor audit records for information systems.
- Develop and maintain Standard Operating Procedures (SOP) and Work Instructions in alignment with Department of Defense and United States Air Force policies and procedures.
- Oversee communications with Program Management, the Information System Security Manager (ISSM), and the On-Site Representative (OSR).
- Direct remediation based on security assessment findings, working with the Security Control Accessor (SCA) to remediate controls for compliance.
- Administer mitigation for POA&M weaknesses and ensure timely closure according to the mitigation plan.
- Coordinate steps to reduce or eliminate identified weaknesses, and route security authorization packages for SCA assessment.
- Support configuration management processes, ensuring proposed changes are analyzed, tested, and approved prior to implementation.
- Develop and test contingency plans and disaster recovery plans.
- Create and manage system Plans of Action and Milestones (POA&M) for identified weaknesses and vulnerabilities.
- Oversee access control requirements, including privileged users, and ensure personnel complete required cybersecurity training.
Requirements
- At least three years of experience working in cybersecurity or related fields such as information technology or control systems management.
- Prefer experience in a military environment, including familiarity with US Air Force cybersecurity guidance, rules, and regulations.
- Bachelor’s degree or military-equivalent training in mechanical or electrical engineering, cybersecurity, information technology, or a closely related field.
- Have or be able to obtain within six months DoD 8570 (or 8140) IAT Level II certification.
- Working knowledge of computer security architectures and implementation of security controls.
- Ability to work independently with minimal supervision.
- Excellent verbal and written communication skills.
- Must be able to pass a drug screen.
- Must be a US citizen and currently possess or be able to obtain/maintain a U.S. government-issued security clearance.
- Proficiency with Microsoft Office 365 and Adobe Acrobat Pro.
- Must maintain a valid US driver’s license.
- Ability to perform repetitive physical tasks involving lifting at least 50 lbs.
- Commitment to providing for and maintaining a safe working environment.
Technologies
- Enterprise Mission Assurance Support Services (eMASS)
- Risk Management Framework (RMF)
- DoD 8570
- DoD 8140
- Microsoft Office 365
- Adobe Acrobat Pro
- BACnet
- Host Based Security System (HBSS)
- Niagara Workbench
- Sustainment Management System (SMS) BUILDER
- BUILDER Remote Entry Database (BRED)
- Energy Management Control Systems (EMCS)
- Fire Alarm Reporting Systems (FARS)
- Utility Monitoring Control Systems (UMCS)
Benefits
- Health care
- Dental
- Vision
- Life insurance
- 401(k)
- Education assistance
- Paid time off including PTO
- Holidays
- Any other paid leave required by law
Desired Qualifications
- Experience in a military environment, particularly familiarity with US Air Force cybersecurity guidance, rules, and regulations.
- Expertise in advanced process control (APC), distributed control systems (DCS), programmable logic controllers (PLC), and supervisory control and data acquisition (SCADA).
- Working knowledge of RMF package creation and maintenance.
- Experience using eMASS for RMF Assessment and Authorization (A&A) activities.
- Knowledge of EMCS, FARS, and UMCS using BACnet protocols.
- Familiarity with DoD RMF and eMASS Essentials.
- Knowledge of Host Based Security System (HBSS).
- Knowledge of Niagara Workbench software.
- Familiarity or experience performing facility assessments and Real Property Inventory Equipment (RPIE) condition assessments using SMS BUILDER and BRED.
- Experience working with data from geospatial databases.
- Knowledge of construction management software, project closeout procedures, preventive maintenance, and construction and repair terminology and processes.