> Markdown version of [/jobs/ext/1845352-cybersecurity-engineer-senior-issm](https://www.wearedevelopers.com/jobs/ext/1845352-cybersecurity-engineer-senior-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer, Senior (ISSM) - **Company:** Torch Technologies, Inc. - **Location:** Kettering, OH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Apple IOS, JIRA, Automation of Tests, Configuration Management, Cyber Security, Information Systems, Fortify (Software), Software Engineering, SonarQube, Enterprise Software Applications, Hp Alm, Atlassian Tools, Bitbucket, Checkmarx, Appscan, Jenkins - **Published:** July 2, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87616524/1 ## About the Role * U.S. Citizenship * Master's or Doctorate Degree in a related field and 10 years of experience in the respective technical/professional discipline being performed, five years of which must be in the DoW OR * Bachelor's Degreeand 12years of experience in the respective technical/professional discipline being performed, five of which must be in the DoW OR * 15 years of directly related experience with proper certifications as described in the PWS labor category performance requirements, eight of which must be in the DoW. * Must have the knowledge, experience and recognized ability to be considered highly skilled in their technical/professional field. * Must possess the ability to perform tasks independently and oversee the efforts of junior and journeyman contractor personnel within the technical/professional discipline. Demonstrates advanced knowledge of their technical/professional discipline as well as possess a comprehensive understanding and ability to apply associated standards, procedures and practices in their area of expertise (Program Office, Enterprise and Staff Level Support interface). * All Cybersecurity professionals should possess experience providing guidance on the following to include, but not limited to: + Access control. + Configuration management. + System and communications protection. + Contingency planning. + Incident handling. + System and information integrity. + Security and privacy training and awareness; and, + Software development activities, software and tools related to Cybersecurity. * Experience performing cybersecurity duties as outlined in DoWI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT. * Experience validating, evaluating and analyzing finding results and developer adjudications using automated testing tools, e.g., Fortify, Checkmarx, SonarQube, and AppScan. * Experience utilizing DoW tracking systems to input/document cybersecurity deficiencies, vulnerabilities, and change requests in the appropriate tracking system for each program, e.g., Jira, HP ALM, and eMASS. * Experience with conducting information security continuous monitoring (ISCM) by maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions IAW approved ISCM strategy. * At a minimum, the successful candidate will meet the requirements for and maintain a personnel certification associated with the DCWF ISSM work role (722) at an advanced (senior) proficiency level as outlined in DoWI 8510.01, AFMAN 17-1305 and AFI 17-101 for assigned systems/applications: * ISACA CISM * United America Technologies CISSO * FITSI FITSP-M * GIAC GCIA * GIAC GCSA * GIAC GCIH * GIAC GSLC * GIAC GICSP * (ISC)2 CISSP-ISSMP * (ISC)2 CISSP Preferred Qualifications: * Working knowledge of the Agile Development methodology * Experience using any, or all, of the following tools: + CheckMarx + SonarQube + Jira + Confluence + Mavin + Jenkins + Bitbucket ## Description Torch Technologies has an exciting opportunity for a Cybersecurity Engineer, Senior (ISSM) located at Kettering, OH (Dayton/WPAFB area) to support our EPASS GB contract. As part of the AFLCMC/GB Business and Enterprise Systems Directorate (BES), the Commercial Asset Visibility Air Force (CAV AF) is the web-enabled component that provides communication to an Inventory Control Point (ICP) for a repair action against a specific repair asset. Government and commercial repair sites monitor and track progress of repair components through the repair process. It allows the contractor to initiate and submit requisitions into the supply system and to accept Status and Inquiries from the supply system., * Provide the PMO/Capability Development Manager (CDM) cybersecurity support per DoWI 8500.01 to include assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities adhere to enterprise standards such as Risk Management Framework (RMF), Cybersecurity Framework (CSF), and National Institute of Standards and Technology (NIST) and per Authorization Official's Information System's Continuous Monitoring (ISCM) strategy. * Serves as the primary cybersecurity technical advisor to the AO, PM and ISO. * Ensures the integration of cybersecurity into, and throughout, the lifecycle of the IT, on behalf of the AO and in accordance with DoWI 8510.0. * Completes and maintains required cybersecurity certification IAW AFMAN 17-1303; * Ensures all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals; * Supports the PM or ISO in maintaining current authorization to operate, approval to connect (if required), and implementing corrective actions identified in the plan of actions and milestones; * Coordinates, with the PM and AO staffs, development of an ISCM strategy and monitors any proposed or actual changes to the system and its environment; * Continuously monitors the IT and environment for security-relevant events; * Assesses proposed configuration changes for potential impact to the cybersecurity posture; * Assesses the quality of security controls implementation against performance indicators; * Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the AO and other affected parties, such as IOs, stewards, and AOs of interconnected IT; * Ensures all ISSOs and privileged users receive necessary technical training and obtain cybersecurity certification IAW AFMAN 17-1301, Computer Security (COMPUSEC), AFMAN 17-1303, and maintain proper clearances IAW DoWI 8500.01; and, * Ensures the AF IT is acquired, documented, operated, used, maintained, and disposed of properly IAW DoWI 5000.02 and DoWI 8510.01. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [10 Creative Workshop Ideas for Conferences](https://www.wearedevelopers.com/magazine/363-10-creative-workshop-ideas-for-conferences)