Cybersecurity Systems Engineer, SME

USfalcon
Offutt Air Force Base, NE, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Unix Cloud Computing Security Code Review Cyber Security Linux DevOps Identity and Access Management Information Security Management Open Web Application Security Web Application Security Software Requirements Analysis
+7 more
Software Systems System Testing Software Security Mitre Att&ck Cyber Threat Analysis Information Technology Devsecops

Job description

Join USfalcon and lead a mission-critical program supporting the Air Force Nuclear Weapons Center (AFNWC) and USSTRATCOM. The Cybersecurity SME serves as the senior leader responsible for the overall execution, performance, and success of Advisory & Assistance Services (A&AS) supporting Business, Engineering, and Cybersecurity functions across complex IT and mission programs. This role operates in a classified, fast-paced environment and serves as the primary interface with government stakeholders across high-visibility programs., JOB SUMMARY: We are seeking a highly skilled Cybersecurity Systems Engineer to support the design, implementation, and sustainment of secure hardware and software systems within the Computing Environment (CE). The Cybersecurity Systems Engineer will be responsible for ensuring that complex system-wide requirements satisfy rigorous Department of Defense (DoD) standards. This role involves developing RMF documentation, evaluating engineering proposals, and providing expert guidance on Secure DevOps (DevSecOps) pipelines., * Ensures the security of hardware, operating systems, and applications within the Computing Environment by implementing RMF processes for Secret, Top Secret, and JWICS networks

  • Primary duties include developing RMF documentation
  • Implement RMF, develop documentation, review code, advise on DevSecOps, manage POA&Ms, STIG/SRG hardening
  • Evaluating engineering proposals to ensure compliance with DoD mandates like NIST 800-53
  • Ensure Security Technical Implementation Guide (STIG) configuration, patching, scanning and testing of systems

Requirements

  • Deep expertise in NIST 800-53, DoDI 8510.01 (RMF), DoDD 8500.1
  • Experience with Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and Hardening Guides.
  • Familiarity with Operating Systems including Linux, UNIX, and Windows
  • Understanding of the MITRE ATT&CK Framework (Adversarial Tactics, Techniques, and Common Knowledge for cyberattacks and intrusions)
  • Knowledge of Military Advanced Persistent Threats (APTs) tactics, techniques and procedure (APT TTPs)
  • Knowledge of Open Worldwide Application Security Project (OWASP) and how is used to develop and maintain secure web applications

PREFFERED QUALIFICATIONS:

  • 12 years of information system security development and management
  • Experience supporting NCC or USSTRATCOM systems
  • Hands-on experience with secure systems engineering and cloud security
  • Ability to analyze complex user and regulatory demands to translate them into technical system requirements, * Master’s degree in IT, Computer Science, Engineering / 5840; additional years of experience may be used in lieu of education requirement
  • Cerification - DoD 8570 IAM Level II or 8140 Level II (i.e., Sec +)
  • CIISP certification or equivalent preferred. Must be able to obtain within 6 months from start date

Benefits & conditions

Benefits Offered: medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, EAP, parental leave, pet insurance, paid time off, and holidays.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all