Cybersecurity Engineer
Astrion · Bedford, MA · 2 wk ago
Information Technology$160k/yrFull-time
About the Role
Astrion is seeking a Cybersecurity Engineer to support the Air Force Life Cycle Management Center Electronic Systems PEO (AFLCMC/ES) at Hanscom AFB, MA. The role involves managing and executing the modernization, design, development, testing, fielding, and sustainment of software and hardware within the ESS Portfolio.
Responsibilities
- Assist in the development of security documentation, including System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, and other required system security engineering artifacts.
- Support Risk Management Framework (RMF) Authorization and Accreditation (A&A) activities, ensuring compliance with DoD and Air Force cybersecurity policies.
- Manage system user accounts, ports/protocols, PKI requirements, and access control lists.
- Implement and track system security updates, configurations, and vulnerability remediation in accordance with DoD requirements.
- Conduct risk and vulnerability assessments; recommend security policies, contingency plans, and disaster recovery procedures.
- Participate in system/network design to ensure alignment with security policies.
- Provide leadership in analyzing and integrating cybersecurity requirements into system design and operations.
- Review and assess the implementation of RMF security controls across system architecture, documentation, and design artifacts.
- Collaborate with stakeholders to ensure RMF A&A approval by all Authorizing Officials.
- Maintain and audit databases for classified information, visits, and clearances.
- Support classified material handling, accountability, and compliance with security classification guides.
- Develop and deliver security awareness training and education programs.
- Prepare and review acquisition security documentation and ensure compliance with CDRLs.
- Plan and implement security-related surveys, assessments, and evaluations throughout the program life cycle.
Qualifications
- Must be a U.S. citizen.
- Must have and maintain an active Secret clearance.
- Bachelor’s degree in a professional engineering discipline from an ABET-accredited educational program.
- At least 7 years of experience in the respective technical/professional discipline, 3 of which must be in the DoD.
Skills
- Security+ certification.
- Understanding of cybersecurity in DoD cloud infrastructure.
- Knowledge of Agile methodologies, including CI/CD, DevSecOps, and DevOps.
- Experience with systems analysis and eMASS.
- Strong ability to communicate technical topics effectively in both written and verbal forms.
- STIG compliance.
- Risk Management Framework (RMF) implementation and documentation.
- DoD cybersecurity policies and compliance.
- System Authorization and Accreditation (A&A) processes.
- DoD cloud infrastructure security.
- Security risk, vulnerability, and contingency planning.
- PKI management and access control.
- Classified material handling and accountability.
- Strong verbal and written communication skills for both technical and non-technical audiences.
- Ability to collaborate with government, contractor, and industry stakeholders.
- Effective problem-solving and analytical thinking.
- Ability to work independently and manage multiple priorities in a fast-paced environment.
- Adaptability to evolving program requirements and security challenges.
Preferred Qualifications
- Experience with Agile development methods, including CI/CD, DevSecOps, and DevOps.
Pay
Salary Range: $150,000 - $160,000 annually, depending on experience, certifications, and qualifications.
Schedule
Full-time, with limited travel as needed.