Cyber A&A Engineer
$128,350–$173,650 year
On-siteColorado Springs, Colorado, United States
Job Summary
Process and track DD Form 2875 user account forms, perform annual validation of accounts, and collaborate with system administrators on account lifecycle management. Conduct passive and active evaluations using STIG Viewer, SCAP, and ACAS to identify system deviations from acceptable configurations and enclave policies. Develop test plans for STIG checks, update Risk Management Framework (RMF) documentation, and coordinate control certifications, compliance tests, and periodic audits to ensure mitigation of risks and support Assessment and Authorization activities. Prepare artifacts including Test Results, Authorization Boundary Diagrams, and Plan of Actions and Milestones while validating cybersecurity controls against NISPOM, NIST, and DoD policies. This role supports the Missile Defense Program's C2BMC initiatives in Colorado Springs, CO, requiring an active Top Secret clearance and 100% onsite presence.
Required Qualifications
- Bachelor's degree in engineering, engineering technology, computer science, engineering data science, mathematics, physics or chemistry
- 5 or more years' related work experience or an equivalent combination of technical education and experience
- IAT Level II/ IAM Level I DoD 8570 certification (CompTIA Security+ CE or equivalent)
- Security engineering skills with a working knowledge of cybersecurity technology and DoD/Federal cybersecurity policy (i.e., DoDI 8500.01, NIST SP 800-53, etc.)
- Understanding and utilization of Enterprise Mission Assurance Support Service (eMASS)
- Understanding of Risk Management Framework (RMF)
- Cybersecurity Lifecycle to include: identifying controls and overlays, generating testable requirements, identifying resilient architecture design, configuring, running, and scripting audit tools, providing analysis of vulnerability analyses, conducting verification testing for compliance assessment
- Knowledge of Software Assurance (SwA) static and dynamic code analysis (e.g. Fortify/SonarQube)
- Active Top Secret U.S. Security Clearance
- U.S. Citizenship
- Ability to obtain access to an MDA facility
- Acceptance by industry partner resource control board
- 100% onsite work at Colorado Springs, CO
- Willingness to relocate at own expense
Desired Qualifications
- ABET accreditation
- Windows and Red Hat Enterprise Linux (RHEL) system administration skills
- Previous background working in a virtual environment
- Previous background working with dockers and containers
- Administer ACAS and ESS (formally HBSS)
- Previous experience with ConfigOS
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.