> Markdown version of [/jobs/ext/1439424-cybersecurity-systems-engineer-sme](https://www.wearedevelopers.com/jobs/ext/1439424-cybersecurity-systems-engineer-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Systems Engineer, SME - **Company:** USfalcon - **Location:** Offutt Air Force Base, NE, United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, Cloud Computing Security, Code Review, Cyber Security, Linux, DevOps, Identity and Access Management, Information Security Management, Open Web Application Security, Web Application Security, Software Requirements Analysis, Software Systems, System Testing, Software Security, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Devsecops - **Published:** July 25, 2026 - **Apply:** https://recruiting.ultipro.com/USF1003UFLC/JobBoard/94666f6d-c6f2-47ce-a7c6-e41d0b8f4784/OpportunityDetail?opportunityId=754d3156-5dee-4cfc-8fc5-6a5b5c5ddd56 ## About the Role * Deep expertise in NIST 800-53, DoDI 8510.01 (RMF), DoDD 8500.1 * Experience with Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and Hardening Guides. * Familiarity with Operating Systems including Linux, UNIX, and Windows * Understanding of the MITRE ATT&CK Framework (Adversarial Tactics, Techniques, and Common Knowledge for cyberattacks and intrusions) * Knowledge of Military Advanced Persistent Threats (APTs) tactics, techniques and procedure (APT TTPs) * Knowledge of Open Worldwide Application Security Project (OWASP) and how is used to develop and maintain secure web applications PREFFERED QUALIFICATIONS: * 12 years of information system security development and management * Experience supporting NCC or USSTRATCOM systems * Hands-on experience with secure systems engineering and cloud security * Ability to analyze complex user and regulatory demands to translate them into technical system requirements, * Master's degree in IT, Computer Science, Engineering / 5840; additional years of experience may be used in lieu of education requirement * Cerification - DoD 8570 IAM Level II or 8140 Level II (i.e., Sec +) * CIISP certification or equivalent preferred. Must be able to obtain within 6 months from start date ## Description Join USfalcon and lead a mission-critical program supporting the Air Force Nuclear Weapons Center (AFNWC) and USSTRATCOM. The Cybersecurity SME serves as the senior leader responsible for the overall execution, performance, and success of Advisory & Assistance Services (A&AS) supporting Business, Engineering, and Cybersecurity functions across complex IT and mission programs. This role operates in a classified, fast-paced environment and serves as the primary interface with government stakeholders across high-visibility programs., JOB SUMMARY: We are seeking a highly skilled Cybersecurity Systems Engineer to support the design, implementation, and sustainment of secure hardware and software systems within the Computing Environment (CE). The Cybersecurity Systems Engineer will be responsible for ensuring that complex system-wide requirements satisfy rigorous Department of Defense (DoD) standards. This role involves developing RMF documentation, evaluating engineering proposals, and providing expert guidance on Secure DevOps (DevSecOps) pipelines., * Ensures the security of hardware, operating systems, and applications within the Computing Environment by implementing RMF processes for Secret, Top Secret, and JWICS networks * Primary duties include developing RMF documentation * Implement RMF, develop documentation, review code, advise on DevSecOps, manage POA&Ms, STIG/SRG hardening * Evaluating engineering proposals to ensure compliance with DoD mandates like NIST 800-53 * Ensure Security Technical Implementation Guide (STIG) configuration, patching, scanning and testing of systems ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)