- Salary
- $165k – $180k/yr
- Location
- Hill AFB, Utah, US
- Workplace
- Onsite
- Type
- Full-time
- Department
- Security
- Seniority
- Manager
- Education
- Bachelor
- Clearance
- Required
- Source
- BetterTeam
Description
- Provides technical leadership, direction, prioritization, and oversight for cybersecurity activities across the program.
- Coordinate cybersecurity activities across ISSOs, security engineers, system administrators, infrastructure teams, application teams, program management, customers, and other mission stakeholders.
- Manage multiple systems through the complete DoD Risk Management Framework lifecycle and maintain Authorization to Operate (ATO) packages within eMASS.
- Lead development, maintenance, and execution of program ATO packages and two customer ATO packages, including security controls, implementation statements, artifacts, assessment evidence, POA&Ms, continuous monitoring requirements, and authorization documentation.
- Serve as a primary cybersecurity point of contact for customer security organizations, assessors, Authorizing Official representatives, and other authorization stakeholders.
- Interpret and implement DoD RMF, NIST SP 800-53, Department of the Air Force, DISA, and applicable cybersecurity requirements across program systems and authorization boundaries.
- Develop and maintain system security documentation, including System Security Plans, continuous monitoring documentation, control implementation evidence, security procedures, risk documentation, and other RMF artifacts.
- Lead vulnerability management activities, including ACAS/Tenable scanning, vulnerability analysis, remediation prioritization, POA&M management, risk acceptance activities, and coordination of remediation efforts with infrastructure and sustainment teams.
- Oversee DISA STIG implementation and compliance activities, including STIG checklist development, validation of findings, documentation of applicability, and coordination of remediation with technical system owners.
- Monitor cybersecurity compliance and system security posture through continuous monitoring, vulnerability assessments, security control reviews, and analysis of technical and operational risk.
- Provide cybersecurity risk assessments and recommendations to Program Management and customer leadership, translating technical vulnerabilities and compliance deficiencies into mission and program risk.
- Develop, maintain, and communicate cybersecurity risks within the program risk register and coordinate mitigation strategies with Program Management and technical stakeholders.
- Support system architecture, data flow mapping, system boundary definition, network topology analysis, and cybersecurity requirements associated with modernization and hosting/cloud migration activities.
- Evaluate proposed system changes, architectures, software, hardware, and technical solutions for cybersecurity and RMF impacts.
- Coordinate security patching, vulnerability remediation, and configuration management activities with infrastructure and sustainment teams.
- Provide cybersecurity guidance and mentorship to program cybersecurity personnel and technical teams and establish priorities for cybersecurity activities based on mission risk and authorization requirements.
- Represent program cybersecurity status, risks, authorization progress, and significant issues during customer, technical, and program leadership meetings.
Education, Certification & Experience Requirements:
- Bachelor's Degree in Cybersecurity or IT related field.
- Must have relevant Air Force Risk Management Framework (RMF) experience.
- Must meet applicable DoD 8140 qualification requirements at time of hire.
- Certified Information Security Manager (CISM) (preferred)
- Certified Information Systems Security Professional (CISSP) (preferred)
- 10 or more years experience in cybersecurity, information assurance, cybersecurity engineering, or related disciplines.
- Significant experience serving as an ISSM, senior ISSO or comparable cybersecurity authority within a DoD environment.
- Demonstrated experience managing systems through the complete RMF lifecycle and obtaining or maintaining ATOs.
- Experience managing multiple concurrent authorization packages and coordinating cybersecurity requirements across multiple system owners or customers.
- Demonstrated experience with NIST SP 800-53 security controls, eMASS, POA&M management, continuous monitoring, ACAS/Tenable, vulnerability management, and DISA STIGs.
- Experience communicating cybersecurity risk and authorization status to technical teams, customers, assessors, and program leadership.
- Expert knowledge of DoD Risk Management Framework processes, NIST SP 800-53 security controls, and Department of the Air Force cybersecurity requirements.
- Advanced knowledge of system authorization, continuous monitoring, security control implementation and assessment, POA&M management, and cybersecurity risk management.
- Strong knowledge of DISA STIGs, ACAS/Tenable, eMASS, vulnerability management processes, and DoD cybersecurity compliance requirements.
- Working knowledge of enterprise infrastructure, networking, operating systems, virtualization, and cloud/hosted environments sufficient to assess cybersecurity risk and control implementation.
- Strong leadership and organizational skills with the ability to establish cybersecurity priorities across multiple simultaneous authorization and operational efforts.
- Advanced RMF, ATO, vulnerability management, STIG, and cybersecurity risk analysis skills.
- Strong written communication and technical documentation skills, including the ability to develop and review authorization artifacts and communicate cybersecurity risk to technical and nontechnical stakeholders.
- Strong interpersonal and stakeholder-management skills with the ability to work effectively with customers, government personnel, engineers, system administrators, cybersecurity personnel, and program leadership.
- Ability to lead cybersecurity activities across engineering, operations, sustainment, customer, and program management organizations.
- Ability to independently evaluate cybersecurity risk and provide technically sound recommendations to program and customer leadership.
- Ability to manage multiple concurrent ATO and continuous monitoring efforts while prioritizing activities based on mission impact and cybersecurity risk.
- Ability to interpret cybersecurity requirements and translate them into actionable technical and program requirements.
- Ability to balance operational mission requirements with DoD cybersecurity, authorization, and risk-management requirements.