Jobs and Careers
SU

Cybersecurity Engineer, Journeyman

Sumaria Systems LLC
Hanscom AFB - SAS, United Statesfull_timeVerifiedPosted 30 Dec 2024
💰 $140,000/yr($130,000/yr$140,000/yr)

About the role

Job Title: Cybersecurity Engineer, Journeyman

Job Description:

  • Assist with development of System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, Computer Certification and Accreditation, Security Vulnerability and Countermeasures Analyses, Security Concepts of Operations, and other system security engineering-related documents identified in MIL-STD 1785, DoDI 5000.02, Operation of the Adaptive Acquisition Framework, and DoDI 8510.01
  • Support the system/application Authorization and Accreditation (A&A) effort to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and Air Force policies (i.e., Risk Management Framework (RMF) to support the AOC WS request for variance process. Review, validate, and work with the AOC WS ISSM to support the approval for both Site and Supported Requests for Variance (RFV) for over 20+ sites.
    • Support the approval or denial based on SPO Cyber RFV checklist Appendix D, as documented in Request for Variance Business Process for the Air Operations Center, ABP 005.
    • Review RFV artifacts including the site security test reports, PPSM, site POA&M, and all applicable cuber documentation then draft recommendation to the AOC WS ISSM
  • Provide Validation and Verification Assessment (VVA) Support implementing the continuous monitoring outlined in the AOC WS Continuous Monitoring Plan and AFI 17-101, Step 6 of RMF. Conduct VVA IAW Program Management Office (PMO) Validation and Verification Assessment (VVA) Business Process Guide, ABP 024.
    • Boots on Ground Assessment - Provide security assessments of subset of AOC WS baseline systems
    • Firewall evaluation IAW Annex E (approved PPSM for AOC WS)
    • Network evaluation IAW AOC WS CM releases
    • Windows server/clients and Red Hat server evaluations IAW AOC WS CM releases
    • Assess GPOs applied, Patches, ePO Policy settings, etc.
    • Develop site specific worksheet/POA&M and provide to site to close open finding
    • Work with site to ensure all open findings are closed IAW cyber plan/previously released CSUs and AREs
    • Work with PC to determine root cause of open findings/missing from current documents, missing scripts, etc
    • JIRA Support - Work with site to open tickets to help resolve cyber issues
    • Provide security assess and validate RFVs configurations IAW RFV test data and documentation
  • Update, monitor, and manage information in systems for the program office
  • Process and manage system user account requests and process tools
  • Process and manage system port/protocol and access control list requirements
  • Process and manage system Public Key Infrastructure (PKI) identification and authorization requirements
  • Manage the distribution, implementation, remediation, and tracking of system security updates and configurations as required by the DoD
  • Recommend policies and procedures to ensure information systems reliability and accessibility to prevent and defend against unauthorized access to systems, networks, and data
  • Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risk, and protection needs
  • Promote awareness of security issues among management and ensuring sound security principles are reflected in organizations’ vision and goals
  • Conduct systems security evaluations, audits and reviews
  • Recommend systems security contingency plans and disaster recovery procedures
  • Recommend and implementing programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures
  • Participate in network and systems design to ensure implementation of appropriate systems security policies
  • Recommend initial, or updates to, software and configurations to new or existing system security mechanisms
  • Obtain waivers to mandated security mechanisms/policies which would be detrimental to system performance and impact the system’s mission
  • Facilitate the gathering, analysis and preservation of evidence used in the prosecution of computer
  • Provide leadership assistance in the analysis of the design, development, integration, implementation and testing of cybersecurity requirements
  • Develop risk-based strategies to address identified gaps
  • Review, analyze, and assess implementations of cybersecurity (i.e. RMF security controls) throughout the open systems architecture and associated services, derived requirements specifications, design documents & design implementation
  • Collaborate with stakeholders (Government and commercial) to ensure the system is a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sumaria Systems LLC

View company profile →