Journeyman Cybersecurity Engineer
Assessment & Authorization
Ato Maintenance
Continuous Monitoring
Cybersecurity Tools
Engineer
Incident Response
Information Security
Information Technology (IT)
InfoSec
Risk Management
Security Clearance
Security Compliance
Security Operations
Security Standards
Security Testing
Vulnerability Management
Job Description
Journeyman Cybersecurity Engineer onsite in Hanscom AFB supporting C3C (Kessel Run) with AOC weapon system cybersecurity, A&A, and RMF/continuous DevSecOps security.
Responsibilities
- Lead the Assessment & Authorization (A&A) process to obtain and maintain the system Authorization to Operate (ATO) using eMASS
- Oversee continuous monitoring (ConMon) strategies, including vulnerability scanning with ACAS/Nessus and configuration hardening using DISA STIGs across multi-classification networks
- Manage security incident reporting, perform root-cause analysis, and develop corrective action plans / POA&Ms
- Ensure cybersecurity is integrated into and throughout the lifecycle of the Air Operations Center (AOC) Weapon System in accordance with DoDI 8510.01
- Complete and maintain required cybersecurity certification IAW AFMAN17-1303; individuals in this position must be U.S. citizens
- Keep AF IT cybersecurity documentation current and accessible to properly authorized individuals (AFI17-101, 6 February 2020)
- Support the PM or ISO in maintaining current authorization to operate and approval to connect, and in implementing corrective actions identified in the plan of action and milestones
- Coordinate with PM and AO staffs to develop an ISCM strategy and monitor proposed or actual system/environment changes
- Continuously monitor the IT environment for security-relevant events, assess proposed configuration changes for impact to cybersecurity posture, and evaluate the quality of security control implementation against performance indicators
- Ensure cybersecurity-related events or configuration changes impacting AF IT authorization or security posture are formally reported to the AO and affected parties (IOs and stewards and AOs of interconnected IT)
- Ensure AF IT is acquired, documented, operated, used, maintained, and disposed of properly IAW DoDI 5000.02 and DoDI 8510.01
- Process Firewall Exemption Requests (FERs)
- Approve change requests (including Critical Security Updates)
- Assist with installation, configuration, and maintenance of ACAS components, including Nessus scanners, SecurityCenter/Tenable.sc, and Nessus Network Monitor (NNM)/Tenable.asm
- Assist in scheduling and executing vulnerability scans using Nessus scanners
- Analyze scan results to identify vulnerabilities and misconfigurations
- Assist with compliance assessments against DoW standards and internal security policies
- Generate reports on vulnerability status, compliance posture, and remediation progress
- Collaborate with system administrators to support vulnerability remediation
- Assist with system administration tasks for ACAS servers and databases
- Stay current on vulnerability trends and security threats
Requirements
- U.S. citizen (required)
- Secret clearance and ability to maintain it
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related technical field
- 5+ years of dedicated DoW cybersecurity experience executing RMF under NIST SP 800-53
- IAM Level III Certification (Certified Information Systems Security Professional / Certified Information Security Officer)
- Basic understanding of networking concepts and protocols
- Familiarity with Windows and Linux operating systems
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
Preferred Qualifications / Skills
- Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm)
- Security+ or other relevant cybersecurity certifications
- Experience with scripting languages such as Python or PowerShell
- Familiarity with DoD security policies and procedures
Technologies
- RMF, NIST SP 800-53, eMASS, ACAS, Nessus
- SecurityCenter/Tenable.sc, Nessus Network Monitor (NNM)/Tenable.asm
- DISA STIGs, DoDI 8510.01, AFMAN17-1303, AFI17-101, DoDI 5000.02
- ISCM, AF IT
- Python, PowerShell
Travel
- Limited; as needed
Salary: USD 120,000 - 130,000 per year
Job status: Full-time
Location: Hanscom AFB, Bedford, MA 01731 (onsite)
Clearance: Secret
Certification: IAM Level III Certification
Company: Astrion