Overview
Journeyman Cybersecurity Engineer
LOCATION: Tinker AFB, OK
JOB STATUS:Full-time
CLEARANCE:Top Secret
TRAVEL:Limited, as needed
Astrion has an exciting opportunity fora Journeyman Cybersecurity Engineer located at theTinker AFB in Oaklahomaproviding support to the Air Force Life Cycle Management Center-Ground Base Air Defense Sensor division (AFLCMC/ESG).
The ESG Division manages efforts focused on developing, acquiring, fielding and sustaining programs that support worldwide communications, Battle Management, Command & Control, Intelligence, Surveillance & Reconnaissance (C2ISR), Air/Ground Surveillance, Time Critical Targeting, Combat Identification, Radar Imagery, Integrated Air/Missile Defense, and Mobile/Fixed C2ISR Performance, Exploitation & Dissemination Facilities.
REQUIRED QUALIFICATIONS / SKILLS:
- Citizenship: Must be a US citizen
- Must have and be able to maintain an active Top Secret clearance
- Experience supporting legacy, nonstandard, isolated, or non-AFNET-connected systems is highly desirable.
- The selected candidate should be prepared to assume immediate responsibility for a high-volume ATO recovery effort, including assessment of approximately 2,000 remaining CCIs and development of SSP implementation narratives.
- Candidates should demonstrate the ability to work through incomplete documentation, aging artifacts, unresolved site dependencies, and large compliance backlogs while maintaining an accurate, auditable record in eMASS.
- The candidate must be able to communicate material risks clearly, particularly risks associated with ATO submission timelines, expiring coverage documentation, missing artifacts, and external tasker dependencies.
PREFERRED QUALIFICATIONS / SKILLS:
- Education: Bachelor’s degree in a professional engineering discipline from an ABET-accredited educational program and at least 7 years of experience in the respective technical/professional discipline, 3 of which must be in the DoD.
- Certifications: Security +
- Understanding of cybersecurity in DoD cloud infrastructure.
- Knowledge of Agile methodologies including CI/CD, DevSecOps, and DevOps.
- Expereinece with systems analysis and eMASS
- Strong ability to communicate technical topics effectively in both written and verbal forms.
- Prior experience with DAF authorization processes, CSSP coordination, POA&M remediation, and Security Plan development is strongly preferred.
TECHNICAL SKILLS:
- STIG compliance
- Risk Management Framework (RMF) implementation and documentation.
- DoD cybersecurity policies and compliance.
- System Authorization and Accreditation (A&A) processes.
- DoD cloud infrastructure security.
- Agile development methods including CI/CD, DevSecOps, and DevOps.
- Security risk, vulnerability, and contingency planning.
- PKI management and access control.
- Classified material handling and accountability.
INTERPERSONAL SKILLS:
- Strong verbal and written communication skills for both technical and non-technical audiences.
- Ability to collaborate with government, contractor, and industry stakeholders.
- Effective problem-solving and analytical thinking.
- Ability to work independently and manage multiple priorities in a fast-paced environment.
- Adaptability to evolving program requirements and security challenges.
RESPONSIBILITIES:
Duties include, but not limited to:
- Assist in the development of security documentation including System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, and other required system security engineering artifacts.
- Support RMF Authorization and Accreditation (A&A) activities, ensuring compliance with DoD and Air Force cybersecurity policies.
- Manage system user accounts, ports/protocols, PKI requirements, and access control lists.
- Implement and track system security updates, configurations, and vulnerability remediation in accordance with DoD requirements.
- Conduct risk and vulnerability assessments; recommend security policies, contingency plans, and disaster recovery procedures.
- Participate in system/network design to ensure alignment with security policies.
- Provide leadership in analyzing and integrating cybersecurity requirements into system design and operations.
- Review and assess the implementation of RMF security controls across system architecture, documentation, and design artifacts.
- Collaborate with stakeholders to ensure RMF A&A approval by all Authorizing Officials.
- Maintain and audit databases for classified information, visits, and clearances.
- Support classified material handling, accountability, and compliance with security classification guides.
- Develop and deliver security awareness training and education programs.
- Prepare and review acquisition security documentation and ensure compliance with CDRLs.
- Plan and implement security-related surveys, assessments, and evaluations throughout the program life cycle.