Torch Technologies has an exciting opportunity for a Cybersecurity Engineer (ISSM) located Kettering, OH (Dayton/WPAFB area) to support our EPASS GB contract. As part of the AFLCMC/GB Business and Enterprise Systems Directorate (BES), the Reliability, Availability, and Maintainability for Pods (RAMPOD) is an integrated weapons management information system that collects, reports, and maintains real-time reliability, availability, maintainability, configuration, warranty, and system on time, inventory, performance, sortie, and engineering (parametric) data for electronic combat countermeasures systems and avionics pods. All system produced metrics and statistics are based on operating time and serial tracking of failures. RAMPOD serially tracks all electronic combat and avionics pods by location, operational status, and configuration. The system uses state of the art technology to achieve near real-time logistics information that when combined with engineering, operational, exercise and combat sortie data or information supports the customer at all operational environments. RAMPOD provides critical, real-time aircraft pod maintenance (elapsed time indicator, component repair info, and warranty status) and location data to field level pod maintainers, logistics managers, and MAJCOM POCs. RAMPOD provides pod data not available from any other logistics or maintenance system and has been designated by USAF/IL and SAF/FM as the single official system of record for all Air Force pods. RAMPOD was directed to implement a Chief Financial Officer (CFO) compliant financial module effective 30 September 2005. RAMPOD successfully interfaces pods asset values exceeding $6 billion to DFAS each month and maintains, on-line, all data of a weapon system (or component) from birth to death.
ESSENTIAL DUTIES/POSITION DESCRIPTION:
The successful candidate will provide the PMO/Capability Development Manager (CDM) cybersecurity support per DoDI 8500.01. Support includes assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities adhere to enterprise standards such as Risk Management Framework (RMF), Cybersecurity Framework (CSF), and National Institute of Standards and Technology (NIST) and per Authorization Official’s Information System’s Continuous Monitoring (ISCM) strategy.
The ISSM is the primary cybersecurity technical advisor to the AO, PM, and ISO. The ISSM ensures the integration of cybersecurity into, and throughout, the lifecycle of the IT, on behalf of the AO and in accordance with DoDI 8510.01 for the following:
- Completes and maintains required cybersecurity certification IAW AFMAN 17-1303;
- Ensures all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals;
- Supports the PM or ISO in maintaining current authorization to operate, approval to connect (if required), and implementing corrective actions identified in the plan of actions and milestones;
- Coordinates, with the PM and AO staffs, development of an ISCM strategy and monitors any proposed or actual changes to the system and its environment;
- Continuously monitors the IT and environment for security-relevant events;
- Assesses proposed configuration changes for potential impact to the cybersecurity posture
- Assesses the quality of security controls implementation against performance indicators;
- Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the AO and other affected parties, such as IOs, stewards, and AOs of interconnected IT;
- Ensures all ISSOs and privileged users receive necessary technical training and obtain cybersecurity certification IAW AFMAN 17-1301, Computer Security (COMPUSEC), AFMAN 17-1303, and maintain proper clearances IAW DoDI 8500.01; and,
- Ensures the AF IT is acquired, documented, operated, used, maintained, and disposed of properly IAW DoDI 5000.02 and DoDI 8510.01.
JOB REQUIREMENTS/QUALIFICATIONS:
The Information Systems Security Manager (ISSM) has the knowledge, experience and recognized ability to be considered highly skilled in their technical/professional field. Possesses the ability to perform tasks independently and oversee the efforts of junior and journeyman contractor personnel within the technical/professional discipline. Demonstrates advanced knowledge of their technical/professional discipline as well as possess a comprehensive understanding and ability to apply associated standards, procedures and practices in their area of expertise (Program Office, Enterprise and Staff Level Support interface).
All Cybersecurity professionals should possess experience providing guidance on the following to include, but not limited to:
- Access control.
- Configuration management.
- System and communications protection.
- Contingency planning.
- Incident handling.
- System and information integrity.
- Security and privacy training and awareness; and,
- Software development activities, software and tools related to Cybersecurity.
Experience performing cybersecurity duties as outlined in DoDI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT.
Experience validating, evaluating and analyzing finding results and developer adjudications using automated testing tools, e.g., Fortify, Checkmarx, SonarQube, and AppScan.
Experience utilizing DoD tracking systems to input/document cybersecurity deficiencies, vulnerabilities, and change requests in the appropriate tracking system for each program, e.g., Jira, HP ALM, and eMASS.
Experience with conducting information security continuous monitoring (ISCM) by maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions IAW approved ISCM strategy.
EDUCATION:
Master's or Doctorate Degree in a related field and ten years of experience in the respective technical/professional discipline being performed, five years of which must be in the DoD
OR, Bachelor's Degree in a related field and 12 years of experience in the respective technical/professional discipline being performed, five of which must be in the DoD
OR, 15 years of directly related experience with proper certifications as described in the PWS labor category performance requirements, eight of which must be in the DoD.
CERTIFICATION REQUIREMENTS:
At a minimum, the successful candidate will meet the requirements for and maintain an IAM Level III Cybersecurity certification by possessing at least one of the following certifications as directed by DoD 8140 and outlined in DoD 8570.01 -M, Appendix3, Table 2,2 AFMAN 17-1303:
- ISACA CISM
- (ISC)2 CISSP
- GIAC GSLC
- EC Council CCISO
Additional Desired Certifications (Not Required):
- Certified SCRUM Master
- Other Agile Certifications
OTHER QUALIFICATIONS:
Candidate must be a US Citizen
Candidate must possess and be able to maintain a T3/Secret Clearance
The following skills are highly desirable but not required for this position:
- Working knowledge of the Agile Development methodology
- Experience using any, or all, of the following tools (Desired):
- CheckMarx
- SonarQube
- Jira
- Confluence
- Mavin
- Jenkins
- Bitbucket
U.S. Citizenship Required for this Position: Yes
Job Type: Regular Full-time
Security Clearance: Secret
Schedule: 40 Hrs/week
Work Location: Kettering, OH
Travel: 0-10%
Relocation Assistance Available: No
Position Contingent Upon Award of Contract: No
Benefits:
Torch Technologies is proud to offer a stable and professional work environment, a competitive salary, and an excellent, comprehensive benefit package including: ESOP participation, 401(k) match and safe-harbor contribution, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, Health Saving Accounts and Health Reimbursement Accounts, EAP, education assistance, paid time off, and holidays.
Applying to Torch Technologies:
Only those candidates invited for an interview will be contacted. Employment at Torch Technologies is contingent upon the successful completion of a comprehensive background check.
Torch Technologies is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Employment Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability or any other protected class .