Cybersecurity/ISSM

Avion SolutionsKettering, OH
1hOnsite

About The Position

Avion Solutions Inc., an employee-owned company, is seeking candidates for a Cybersecurity/ISSM to support the EPASS contract. This position is located in Kettering, OH.

Requirements

  • Master's or Doctorate Degree in a related field and 10 years of experience in the respective technical/professional discipline being performed, five years of which must be in the DoD or
  • Bachelor's Degree and 12 years of experience in the respective technical/professional discipline being performed, five of which must be in the DoD or
  • 15 years of directly related experience with proper certifications as described in the PWS labor category performance requirements, eight of which must be in the DoD.
  • Must have the knowledge, experience, and recognized ability to be considered highly skilled in their technical/professional field.
  • Must possess the ability to perform tasks independently and oversee the efforts of junior and journeyman contractor personnel within the technical/professional discipline. Demonstrates advanced knowledge of their technical/professional discipline, as well as possesses a comprehensive understanding and ability to apply associated standards, procedures, and practices in their area of expertise (Program Office, Enterprise, and Staff Level Support interface).
  • All Cybersecurity professionals should possess experience guiding the following including, but not limited to:
  • Access control
  • Configuration management
  • System and communications protection
  • Contingency planning
  • Incident handling
  • System and information integrity
  • Security and privacy training and awareness
  • Software development activities, software, and tools related to Cybersecurity.
  • Experience performing cybersecurity duties as outlined in DoDI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT.
  • Experience validating, evaluating, and analyzing findings and developer adjudications using automated testing tools, e.g., Fortify, Checkmarx, SonarQube, and AppScan.
  • Experience utilizing DoD tracking systems to input/document cybersecurity deficiencies, vulnerabilities, and change requests in the appropriate tracking system for each program, e.g., Jira, HP ALM, and eMASS.
  • Experience with conducting information security continuous monitoring (ISCM) by maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions IAW approved ISCM strategy.
  • At a minimum, the successful candidate will meet the requirements for and maintain a personnel certification associated with the DCWF ISSM work role (722) at an advanced (senior) proficiency level as outlined in DoDI 8510.01, AFMAN 17-1305, and AFI 17-101 for assigned systems/applications:
  • · ISACA CISM
  • · United America Technologies CISSO
  • · FITSI FITSP-M
  • · GIAC GCIA
  • · GIAC GCSA
  • · GIAC GCIH
  • · GIAC GSLC
  • · GIAC GICSP
  • · (ISC)2 CISSP-ISSMP
  • · (ISC)2 CISSP
  • Must be a U.S. citizen and have an active DoD Secret Security Clearance.
  • Must be able to travel up to 15% of the time. US travel only.

Nice To Haves

  • Certified SCRUM Master.
  • Other Agile Certifications.
  • Working knowledge of the Agile Development methodology.
  • Experience using any or all of the following tools:
  • CheckMarx
  • SonarQube
  • Jira
  • Confluence
  • Mavin
  • Jenkins
  • Bitbucket

Responsibilities

  • Completes and maintains required cybersecurity certification IAW AFMAN 17-1303.
  • Ensures all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals.
  • Supports the PM or ISO in maintaining current authorization to operate, approval to connect (if required), and implementing corrective actions identified in the plans of action and milestones.
  • Coordinates, with the PM and AO staff, the development of an ISCM strategy and monitors any proposed or actual changes to the system and its environment.
  • Continuously monitors the IT and environment for security-relevant events.
  • Assesses proposed configuration changes for potential impact on the cybersecurity posture.
  • Assesses the quality of security controls implementation against performance indicators.
  • Ensures that cybersecurity-related events or configuration changes that impact AF IT authorization or adversely affect the security posture are formally reported to the AO and other affected parties, such as IOs, stewards, and AOs of interconnected IT systems.
  • Ensures all ISSOs and privileged users receive necessary technical training and obtain cybersecurity certification IAW AFMAN 17-1301, Computer Security (COMPUSEC), AFMAN 17-1303, and maintain proper clearances IAW DoDI 8500.01.
  • Ensures the AF IT is acquired, documented, operated, used, maintained, and disposed of properly IAW DoDI 5000.02 and DoDI 8510.01.
  • Other duties as assigned.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service