Cybersecurity Engineer, Senior (ISSM)

Crossflow Technologies Inc

Dayton, OH

JOB DETAILS
SALARY
SKILLS
Access Control, Adjudication, Agile Programming Methodologies, Air Force, Atlassian JIRA, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Certified ScrumMaster, Change Requests/Orders, Computer Security, Configuration Management, Contingency Plans, Corrective Action, Data Quality, Documentation, EEO Regulations, Federal Laws and Regulations, GCIA - GIAC Certified Intrusion Analyst, GCIH - GIAC Certified Incident Handler, GIAC - Global Information Assurance Certification, GSLC - GIAC Security Leadership Certificate, Hewlett-Packard Product Family, Higher Education, IBM Rational AppScan, ISACA (Information Systems Audit and Control Association), ISO (International Organization for Standardization), ISSMP - Information Systems Security Management Professional, Incident Response, Information Technology & Information Systems, Information/Data Security (InfoSec), Internet Security, Inventory Control System, Inventory Management, Mainframe Computer, Payroll Tax, People Management, Privacy Controls, Retail Asset Management, Risk Management, Risk Management Framework (RMF), Secret Clearance, Security Analysis, Security Attacks, Security Clearance, Security Monitoring, Software Development, State Laws and Regulations, Strategic Planning, Sustainability, Test Automation, Test Tools, Transaction Processing/Management, U.S. National Institute of Standards and Technology (NIST), United States Citizen, United States Department of Defense (DoD), United States Marine Corps (USMC), Wholesale Industry
LOCATION
Dayton, OH
POSTED
30+ days ago

Job Title: Cybersecurity Engineer, Senior (ISSM)

Location: Kettering, OH (Dayton/WPAFB area)

Crossflow Technologies, Inc. has an exciting opportunity for a Cybersecurity Engineer, Senior (ISSM) located at Kettering, OH (Dayton/WPAFB area) to support our EPASS GB contract. As part of the AFLCMC/GB Business and Enterprise Systems Directorate (BES), the Stock Control System (SCS) is a web-based and mainframe wholesale and depot retail asset management system. It provides enhanced processing of stock control transactions and management information for Air Force and Marine Corps (USMC) operations. The system directly supports AF, USMC, and other service/agency customers. It provides worldwide combat readiness and sustainability for the warfighter through allocation, custody, and distribution of supply and equipment items supporting the full range of Air Force weapon systems such as F-35, F22, F-15, F-16, A-10, C-130, C-17, C-5, etc.

The SCS FIAR RDT&E efforts are focused on modernizing and improving this Air Force capability. As a Cybersecurity Engineer, Senior (ISSM) your duties will include the following, but are not limited to:

• Provide the PMO/Capability Development Manager (CDM) cybersecurity support per DoDI 8500.01. • Support includes assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities adhere to enterprise standards such as Risk Management Framework (RMF), Cybersecurity Framework (CSF), and National Institute of Standards and Technology (NIST) and per Authorization Officials Information Systems Continuous Monitoring (ISCM) strategy. • Completes and maintains required cybersecurity certification IAW AFMAN 17-1303. • Ensures all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals. • Supports the PM or ISO in maintaining current authorization to operate, approval to connect (if required), and implementing corrective actions identified in the plan of actions and milestones. • Coordinates, with the PM and AO staffs, development of an ISCM strategy and monitors any proposed or actual changes to the system and its environment. • Continuously monitors the IT and environment for security-relevant events. • Assesses proposed configuration changes for potential impact to the cybersecurity posture. • Assesses the quality of security controls implementation against performance indicators. • Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the AO and other affected parties, such as IOs, stewards, and AOs of interconnected IT. • Ensures all ISSOs and privileged users receive necessary technical training and obtain cybersecurity certification IAW AFMAN 17-1301, Computer Security (COMPUSEC), AFMAN 17-1303, and maintain proper clearances IAW DoWI 8500.01. • Ensures the AF IT is acquired, documented, operated, used, maintained, and disposed of properly IAW DoWI 5000.02 and DoWI 8510.01.

Job Requirements

U.S. Citizenship

Masters or Doctorate Degree in a related field and 10 years of experience in the respective technical/professional discipline being performed, five years of which must be in the DoW

Bachelors Degree and 12 years of experience in the respective technical/professional discipline being performed, five of which must be in the DoW

15 years of directly related experience with proper certifications as described in the PWS labor category performance requirements, eight of which must be in the DoW

Must have the knowledge, experience and recognized ability to be considered highly skilled in their technical/professional field.

Must possess the ability to perform tasks independently and oversee the efforts of junior and journeyman contractor personnel within the technical/professional discipline.

Demonstrates advanced knowledge of their technical/professional discipline as well as possess a comprehensive understanding and ability to apply associated standards, procedures and practices in their area of expertise (Program Office, Enterprise and Staff Level Support interface).

All Cybersecurity professionals should possess experience providing guidance on the following to include, but not limited to:

• Access control • Configuration management • System and communications protection • Contingency planning • Incident handling • System and information integrity • Security and privacy training and awareness • Software development activities, software and tools related to Cybersecurity

Experience performing cybersecurity duties as outlined in DoDI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT.

Experience validating, evaluating and analyzing finding results and developer adjudications using automated testing tools, e.g., Fortify, Checkmarx, SonarQube, and AppScan.

Experience utilizing DoD tracking systems to input/document cybersecurity deficiencies, vulnerabilities, and change requests in the appropriate tracking system for each program, e.g., Jira, HP ALM, and eMASS.

Experience with conducting information security continuous monitoring (ISCM) by maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions IAW approved ISCM strategy.

Must have and maintain an active Secret security clearance.

At a minimum, the successful candidate will meet the requirements for and maintain a personnel certification associated with the DCWF ISSM work role (722) at an advanced (senior) proficiency level as outlined in DoWI 8510.01, AFMAN 17-1305 and AFI 17-101 for assigned systems/applications:

• ISACA CISM • United America Technologies CISSO • FITSI FITSP-M • GIAC GCIA • GIAC GCSA • GIAC GCIH • GIAC GSLC • GIAC GICSP • (ISC)2 CISSP-ISSMP • (ISC)2 CISSP

Preferred Qualifications

Certified SCRUM Master

Other Agile Certifications

Working knowledge of the Agile Development methodology

Experience using any, or all, of the following tools:

• CheckMarx • SonarQube • Jira • Confluence • Mavin • Jenkins • Bitbucket

Schedule: 40 Hrs/week

Work Location: Kettering, OH

Travel: 0-10%

Relocation Assistance Available: No

Position Contingent Upon Award of Contract: No

Equal Opportunity/Affirmative Action Employer: Crossflow ensures that employment decisions and personnel actions are administered fairly, equitably, and in compliance with the federal, state, and local laws and regulations governing EEO and personnel management. All qualified individuals will receive consideration for employment opportunities without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Why Crossflow?

Crossflow Technologies is proud to offer such wonderful benefits and perks to our employees; however, we feel the biggest perk is our company culture. We harbor a culture that extends down to the individual level by hiring people who understand and embrace our company values. Values like fervently protecting work-life balance and celebrating the achievements of others.

To help guide and shape this environment, we strive to solicit feedback as frequently as possible through direct conversations and anonymous input. We take great pride in the fact that weve won the Best Places to Work award for the past four years - particularly when paired with having made the Inc. 5000 list for growth the same four years. To us, this demonstrates our ability to effectively scale our culture showing that Crossflow has been and continues to be, a place that people want to be.

Benefit-Eligible Employee Perks

• EXCEPTIONAL HEALTH, DENTAL, AND VISION COVERAGE Crossflow is pleased to offer employees with exceptional single and family options for health, dental, and vision coverage. Payments are taken from the first two paychecks of each month. • At a glance: • Health coverage choices (including an HSA) ranging from $0.00 to $146.40; • Dental coverage ranges from $4.00 to $15.00; • Vision coverage ranges from $4.33 to $11.41.

CROSSFLOW KUDOS SPOT BONUS PROGRAM

We created a unique performance bonus program called Crossflow Kudos. Throughout the year, employees are nominated by other employees, company leads, and even individuals outside of Crossflow to receive additional compensation and personal recognition for their positive work. There are six broad categories in which employees can earn Kudos awards.

401(k) RETIREMENT PLAN & COMPANY MATCHING

Crossflow uses Principal as our 401(k) plan sponsor. Employees can choose payroll deduction and fund investing options. Payroll deductions will begin the month following your enrollment. Crossflow matches 100% of the first 3% of compensation, plus 50% of the next 2% of compensation.

HIGHER EDUCATION ASSISTANCE PROGRAM

Crossflow offers education assistance to benefit-eligible employees for degree programs at their directors discretion. Crossflow feels that a well-rounded education, even outside of an employees current role, can enhance an employees skillset and increase the companys value.

GENEROUS PTO ACCRUAL & FLEXIBLE LEAVE POLICY

Crossflow currently grants 11 federally observed paid holidays. In addition to these holidays, Crossflow offers a minimum of 2 weeks of paid time off (PTO) to all full-time employees. Employees may utilize PTO for any reason (sickness, vacation, personal day, etc.) and can carry over a maximum of 120 hours from year to year. Many employees are authorized to work additional hours within a normal, forty-hour pay period. This approval is included in the employees offer letter for employment. These extra hours may be banked for compensatory (comp) time off.

PAID PARENTAL & BEREAVEMENT LEAVE

To help our employees be present with

About the Company

C

Crossflow Technologies Inc