Information Systems Security Engineer SME
Applied Research SolutionsAbout the role
Information Systems Security Engineer SME role located at Peterson, SFB.
Why ARS?
Applied Research Solutions (ARS) is respected as a world-class provider of technically integrated solutions as we deliver premier talent and technology across our focused markets for unparalleled, continuous mission support. Awarded a Best Places to Work nominee since 2020, ARS recognizes that without our career- driven, loyal professionals, we would not be able to deliver state-of-the-art results for our mission partners. We firmly believe that prioritizing our employees is of the upmost importance. We provide a culture where our employees are challenged to meet their career goals and aspirations, while still obtaining a work/life balance. ARS employees are motivated through our industry competitive benefits package, our awards and recognition program, and personalized attention from ARS Senior Managers.
The NCL Division’s primary mission is to sustain and support combat effective nuclear command, control, and communication (NC3) capabilities deployed worldwide. In addition, NCL supports NC3 terminals used under the NATO SATCOM Support Agreement and certain International Partner (IP) terminal support. Systems include fixed site, mobile, and airborne strategic Military SATCOM (MILSATCOM) terminals; aircrew alerting; strategic messaging; and PNVC capabilities.
Responsibilities include:
The ISSM (SME) serves as the Information System Security Manager (ISSM Advanced) and acts as technical advisor to the Program Manager (PM) and Systems Engineer (SE), are primarily responsible for maintaining the overall security posture of the systems within their organization and are accountable for the implementation of Department of Defense (DoD) 8510.01. The organization’s cybersecurity program developed by ISSMs includes cybersecurity architecture, requirements, objectives and policies, cybersecurity personnel, and cybersecurity processes and procedures.
ISSM SME responsibilities include:
- Manage the system/application Assessment and Authorization (A&A) efforts, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Department of the Air Force policies (i.e., RMF).
- Develop and conduct a Continuous Monitoring plan in support of A&A activities to maintain ongoing awareness of cybersecurity, vulnerabilities, and threats to facilitate risk-based decision making.
- Maintain and report system assessment and authorization status and issues in accordance with DoD Component guidance.
- Participate in meetings/teleconferences, change control boards (CCBs) and working groups (WGs) to ensure the continued alignment of cybersecurity requirements in the technical baselines, the system security architecture, information flows, design, and the security controls.
- Evaluate system sources of changes such as Deficiency Reports (DRs), Problem Reports (PRs), Change Requests/Proposals (CRs/CPs), and AF Form 1067s; provide inputs to the root cause analysis reporting and the formulation of recommended solution from alternatives; determine the security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and if any, document in written reports the changes/revisions to the system’s RMF artifacts.
- Review and provide inputs to modification packages, program/system documents and support agreements updates, and communications and network infrastructure upgrades to ensure proper cybersecurity configuration modification management; implementation of technical, managerial, operational requirements; and support requirements (e.g. planning, testing, test infrastructure, documentation, training, etc.) are identified.
- Review system test plans and test results and if necessary, observe system testing for security control implementation IAW cybersecurity policies, guidance, and plan. Document findings in a report.
- Perform security impact analysis on any system change and appropriately prepare letters of assurance, security impact letters, and risk assessment letters to include exceptions, deviations, or waivers to cybersecurity requirements when applicable.
- Continuously monitor intelligence and open-source information for vulnerabilities affecting AFNWC/NCL systems, assess risk, and provide POA&M recommendations to ISSM and PM as required.
- Act as the primary cybersecurity technical advisor to Program Management and System Engineers for systems under their purview.
- Coordinate Trusted Systems and Networks (TSN) and Supply Chain Risk Management (SCRM) evaluation of program information, software, and hardware throughout the program life cycle.
- Ensure that cybersecurity-related events or configuration changes that may impact systems
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s