Salary
💰 $104,550 - $141,450 per year
Tech Stack
Cyber SecurityLinuxMacOSSplunkVMware
About the role
- Provide technical support for product cyber security and resiliency engineering through requirements, design, analysis, build, test, production, operations, support and sustainment
- Advise customers on maintaining product security and certification, including security consequences of modifying products and services
- Participate in change management activities and assist stakeholders with declaration and documentation of ports, protocols and services
- Participate in remanence security risk management processes and execute procedures to identify and mitigate residual risk and risk tolerance
- Implement Risk Management Framework (RMF) processes, product development and product maintenance for assigned systems
- Perform security compliance continuous monitoring, security assessments and audits
- Prepare and present technical reports and briefings and identify root causes and threat prioritization
- Provide mentoring and technical leadership within the information security program team
- Explore enterprise and industry for evolving information security knowledge and methods
- Support development of MTS information security policies, standards, guidelines and procedures
- Support DFARS and Cybersecurity Maturity Model Certification (CMMC) requirements based on contractual requirements for KC-46 MTS
- Align product engineering support with information system security taskings to support the KC-46 Maintenance Training System (MTS)
Requirements
- Bachelor of Science degree in Engineering, Engineering Technology (including Manufacturing Technology), Computer Science, Data Science, Mathematics, Physics, Chemistry or Equivalent
- Security certification, IAM Level 2 DoD 8570/8140 compliant certification (e.g., IAM Level 2 – CAP, GISF, GSLC, Security+)
- Experience with Risk Management Framework (RMF) processes and compliance with both NIST and DoD RMF standards
- 5+ years’ experience in development of cybersecurity philosophies, patterns, requirements, secure architecture, and designs
- 5+ years’ experience in coordinating and presenting technical content and preparing technical documentation
- Knowledge of cyber security incident response protocols (identification, impact assessment, containment, remediation, evidence handling, technical reporting)
- Experience generating product cyber security artifacts for customer/certifiers
- Experience performing threat analysis, security risk assessments, and maturing analysis throughout the development lifecycle
- Knowledge of VMware (infrastructure)
- Experience scanning for vulnerabilities and implementing mitigations
- Experience installing, administering, and troubleshooting Microsoft Windows 10, Windows Server 2016+, Linux Distributions (Red Hat Enterprise)
- Preferred: 8+ years’ experience in cybersecurity philosophies, patterns, requirements, secure architectures, and designs
- Preferred: 8+ years’ experience with RMF/DAAPM, CNSSI 1253, ICD-503, JSIG, and/or NIST SP 800 series
- Preferred: experience with macOS, Windows 11, Server 2022, Raspberry Pi, Splunk Syslogs, and scripting languages
- Preferred: 2+ years software experience and knowledge of high-level programming languages (e.g., C/C++, Ada) and secure coding practices
- Ability to meet export control compliance: must be a U.S. Person as defined by 22 C.F.R. §120.15 (U.S. Citizen, lawful permanent resident, refugee, or asylee)
- Visa Sponsorship: Employer will not sponsor applicants for employment visa status
- Drug Free Workplace: post-offer testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met
- Language Requirements: Not Applicable
- Security Clearance: This position does not require a Security Clearance