> Markdown version of [/jobs/ext/1996175-cybersecurity-engineer-isso-journeyman](https://www.wearedevelopers.com/jobs/ext/1996175-cybersecurity-engineer-isso-journeyman). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer (ISSO) Journeyman - **Company:** Torch Technologies, Inc. - **Location:** Kettering, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Comptia Cloud+, JIRA, Automation of Tests, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Firmware, Fortify (Software), Software Engineering, SonarQube, Hp Alm, SC Clearance, Checkmarx, Appscan - **Published:** August 8, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87983453/1 ## About the Role * U.S. Citizenship * Bachelor's or Master's Degree in a related field and 3 years of experience in the respective technical/professional discipline being performed, three of which must be in the DoW OR * Seven years of directly related experience with proper certifications, five of which must be in the DoW. * Must have the ability to problem solve and troubleshoot various situations to develop successful outcomes within established program/project guidelines. * All Cybersecurity professionals should possess experience providing guidance on the following to include, but not limited to: + Access control. + Configuration management. + System and communications protection. + Contingency planning. + Incident handling. + System and information integrity. + Security and privacy training and awareness + Software development, software and tools * Experience performing cybersecurity duties as outlined in DoWI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT. * Experience validating, evaluating and analyzing finding results and developer adjudications using automated testing tools, e.g., Fortify, Checkmarx, SonarQube, and AppScan. * Experience utilizing DoW tracking systems to input/document cybersecurity deficiencies, vulnerabilities, and change requests in the appropriate tracking system for each program, e.g., Jira, HP ALM, and eMASS. * Experience with conducting information security continuous monitoring (ISCM) by maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions IAW approved ISCM strategy. * At a minimum, the successful candidate will meet the requirements for and maintain a personnel certification associated with the DCWF ISSO work role (722) at an intermediate (journeyman) proficiency level as outlined in DoWI 8510.01, AFMAN 17-1305 and AFI 17-101 for assigned systems/applications: + ISC)2 CGRC/CAP + CompTIA CASP+ + ISC)2 CCSP + CompTIA Cloud+ + ISC)2 SSCP + CompTIA Security+ CE + (GIAC) GSEC * Candidate must possess and be able to maintain a T3/Secret Clearance. ## Description As a Cybersecurity Engineer (ISSO) Journeyman your duties will include the following, but are not limited to: * Provide the PMO/Capability Development Manager (CDM) cybersecurity support per DoWI 8500.01. * Support includes assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities adhere to enterprise standards such as Risk Management Framework (RMF), Cybersecurity Framework (CSF), and National Institute of Standards and Technology (NIST) and per Authorization Official's Information System's Continuous Monitoring (ISCM) strategy. * Responsible for ensuring the appropriate operational securityposture is maintained for the assigned IT. * Implements and enforce all AF cybersecurity policies, procedures, and countermeasures. * Completes and maintains required cybersecurity certification IAW AFMAN 17-1303. * Ensures all users have the requisite security clearances and need-to-know, complete annualcybersecurity training, and are aware of their responsibilities before being granted access to the IT according toAFMAN 17-1301. * Maintains all authorized user access control documentation IAW the applicable AF Records Information Management System. * Ensures software, hardware, and firmware comply with appropriate security configuration guidelines, e.g., security technical implementation guides/security requirement guides. * Ensures proper configuration management procedures are followed prior to implementation and contingent upon necessary approval. * Coordinate changes or modifications with the system-level ISSM, SCA, and/or the Wing Cybersecurity office. * Initiates protective or corrective measures, in coordination with the ISSM, when a security incident or vulnerability is discovered. * Reports security incidents or vulnerabilities to the system-level ISSM and wing cybersecurity office according to AFI 17-203. * Initiates exceptions, deviations, or waivers to cybersecurity requirements. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)