Senior Cybersecurity Engineer

AstrionBedford, MA
Onsite

About The Position

Astrion has an exciting opportunity for a Senior Cybersecurity Engineer located at the Hanscom AFB in Bedford Massachusetts to support the Command, Control, Communications (C3C)/Kessel Run division. Kessel Run is an Air Force unit that delivers resilient command and control and targeting software capabilities that provide warfighters with decision advantage. Under the Department of the Air Force Program Executive Office for Command, Control, Communication, and Battle Management (DAF PEO C3BM), Kessel Run technologies make up the DAF BATTLE NETWORK, the systems-of-systems designed to help the Joint Force make operational decisions faster than our adversaries. The Division architects and acquires the means to connect weapon systems with warfighters and decision makers to enable the warfighter to win against the pacing challenge in an era of great power competition.

Requirements

  • Must be a US citizen
  • Must have and be able to maintain an active Top Secret clearance
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field
  • 12 years of experience in cybersecurity or a related field
  • Master’s or Doctorate Degree and 10 years of experience in the respective technical / professional discipline being performed, 5 years of which must be in the DoD
  • Bachelor’s Degree and 12 years of experience in the respective technical/professional discipline being performed, 5 of which must be in the DoD
  • 15 years of directly related experience with proper certifications, 8 of which must be in the DoD
  • GED and at least 5 years of experience in the respective profession being performed, 5 of which must be in the DoD.
  • Extensive knowledge and/or experience in the following: Commercial solutions for classified (CSfC) and/or NSA approval process
  • Cross domain solution (CDS) design and approval
  • Demonstrated experience with network architecture and design.
  • Demonstrated experience with DoD networking preferably with or supporting a Joint Communications Support Element (JCSE)
  • Working knowledge of software defined networking (SDN)
  • DoD RMF implementation (including ATO, ATC and reciprocity)
  • Skilled in managing eMASS system packages
  • Working knowledge of administrating servers, system and application security threats and vulnerabilities
  • DISA Security Technical Implementation Guide (STIG) implementation.
  • Assured Compliance Assessment Solution (ACAS) tool usage.

Nice To Haves

  • Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm).
  • Security+ or other relevant cybersecurity certifications.
  • Experience with scripting languages such as Python or PowerShell.
  • Familiarity with DoD security policies and procedures
  • Basic understanding of networking concepts and protocols.
  • Familiarity with Windows and Linux operating systems.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills

Responsibilities

  • Ensure that all system and application deliverables meet the requirements of all DoD and Air Force Cybersecurity policies.
  • Ensure compliance with DoD and Air Force Certification and Accreditation policies, specifically Department of Defense Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information Technology, and AFI 33-210, The Risk Management Framework (RMF) for Air Force Information Technology.
  • Support the system/application authorization and accreditation (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and Air Force policies, i.e., Risk Management Framework (RMF).
  • Recommend policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data.
  • Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs.
  • Promote awareness of security issues among management and ensure sound security principles are reflected in organizations’ visions and goals.
  • Conduct systems security evaluations, audits, and reviews.
  • Recommend systems security contingency plans and disaster recovery procedures.
  • Recommend and implement programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures.
  • Participate in network and systems design to ensure implementation of appropriate systems security policies.
  • Facilitate the gathering, analysis, and preservation of evidence.
  • Identify and Analyze risks and issues (including Operational Security (OPSEC) and Information Security (INFOSEC)).
  • Advise the Government on Cyber Security strategy(s) based on the system requirements and operating environment.
  • Propose mitigations to protect all types of information from unauthorized access.
  • Assess security events to determine impact and implement corrective actions.
  • Ensure the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services.
  • Perform the Information System Security Engineer (ISSE) duties in an Information Assurance Workforce System Architecture and Engineering (IASAE) position as outlined in AFI 33-200, AFI 33-210 and AFMAN 33-285 for assigned systems.
  • Perform the Information System Security Manager (ISSM) duties as outlined in DoDI 8510.01 for assigned systems/applications.
  • Perform the Information System Security Officer (ISSO) duties as outlined in DoDI 8510.01 for assigned systems/applications.
  • Develop, review, analyze, and support the preparation of Program Protection Plans (PPP), Anti-Tamper Plans (ATPs), Cybersecurity Plans, IATT (Test) and/or Operation (ATO) Authorization, System Security Authorization Agreement (SSAA), System Security Plan, System Threat Assessments.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service