Cybersecurity Specialist
Avion Solutions, Inc. · Huntsville, AL · 2 wk ago
On-siteEngineeringFull-time
Avion Solutions Inc., a 100% employee-owned company, is seeking candidates to support the Fixed Wing Project Office (FWPO) in Huntsville, AL.
Responsibilities
- Serve as the primary cybersecurity specialist while supporting aircraft systems engineers, software developers, and systems architects to embed RMF requirements directly into the engineering design process.
- Oversee the development, maintenance, and submission of RMF authorization packages utilizing the eMASS compliance tool to secure and maintain ATO for aviation Intelligence/Surveillance/Reconnaissance (ISR) and test platforms.
- Lead system lifecycles, including self-assessments against NIST SP 800-53/CNSSI 1253 security controls tailored for Closed Restricted Networks (CRN) and tactically deployed ISR systems.
- Develop and manage Plans of Action and Milestones (POA&Ms) for non-compliant controls, coordinating with engineering teams to implement mitigation strategies during platform integration.
- Provide cybersecurity guidance during the integration and testing of new sensor payloads, datalinks, and mission systems onto Federal Aviation Administration (FAA) certificated aircraft.
- Coordinate with external test organizations (DOT&E, Blue Teams, etc.) to execute Cyber Tabletop (CTT), Cyber Development Testing (CDT), and Cooperative Vulnerability and Penetration (CVPA) events on various fixed-wing aircraft platforms.
- Oversee and maintain the security posture of SILs and simulation environments used for pre-flight software testing and vulnerability discovery.
- Other duties as assigned.
Requirements
- Bachelor's Degree (engineering or related technical discipline) and 10+ years of relevant cybersecurity experience, preferably in aviation platforms.
- Experience with implementing and evaluating DoD Security Technical Implementation Guide (STIG) requirements, NIST RMF, IAVMs, and cybersecurity assessment tools (ACAS, Nessus, SCC, STIG Viewer).
- Prior experience embedding Risk Management Framework (RMF) requirements into aircraft system designs and managing RMF authorization packages through the Authority to Operate (ATO) process.
- Experience with NIST security controls and the Enterprise Mission Assurance Support Service (eMASS).
- Knowledge of NIST SP 800-53/CNSSI 1253 and collaboration with Program Managers, Original Classification Authority (OCA), and Systems Security Engineers (SSE).
- Knowledge of information system architecture and standards as they apply to cybersecurity, including confidentiality of information, privacy protection, data security, and other information security issues in a DoD-regulated industry.
- Experience with all forms of information technology security, policy writing, auditing, compliance, and creating, maintaining, and auditing IT security controls and procedures.
- DoD 8570 IAT or IAM Level II certification.
- Must be a U.S. citizen and have the ability to obtain/maintain a DoD security clearance.
- Must be able to travel up to 15% of the time.
Preferred Qualifications
- Master's Degree.
- 8570 IAT or IAM Level III certification (e.g., CISSP, CISA, CASP, GSLC, CAP, CISM, CEH).
- Experience in a DoD security environment.
- Experience in systems, network, and endpoint security.
- Excellent knowledge of information security technology, such as firewalls, Intrusion Detection Systems (IDS), Intrusion Detection and Prevention Systems (IDPS), and anti-malware.