Skip to main content
Torch Technologies

Cybersecurity ISSE (Principal)

RemoteUnited States only
Published
Role
Security
Experience
Principal
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Principal-level Information System Security Engineer for U.S. citizen with active Secret (T3) clearance. 10+ years' experience and bachelor’s required; must meet/maintain DoD/AF cybersecurity certifications (e.g., GCSA, CISSP-ISSEP) and perform RMF/ISCM duties. Remote-hire approved outside OH but restricted to U.S. citizens and support DoD/AF systems.

Core skills

RMF/DoD/AF ISSE practices

Required skills

Risk Management Framework (RMF)Cybersecurity Framework (CSF)NISTISCMFortifyCheckmarxSonarQubeAppScanJiraHP ALMeMASSaccess controlconfiguration managementsystem and communications protectioncontingency planningincident handlingsystem and information integritysecure architecturesecure coding

Optional skills

CheckMarxSonarQubeMavenFortifyJiraConfluenceBitBucketCertified SCRUM Master

What you'll do

  • Provide the PMO/Capability Development Manager (CDM) cybersecurity support per DoWI 8500.01.
  • Assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities adhere to enterprise standards such as Risk Management Framework (RMF), Cybersecurity Framework (CSF), and National Institute of Standards and Technology (NIST) and per Authorization Official’s Information System’s Continuous Monitoring (ISCM) strategy.
  • Employs best practices when implementing security controls, including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques.
  • Coordinates their security-related activities with the information security architect, ISSM, ISSO, ISO, and common control provider.
  • Completes training and maintain certification IAW AFI 17-1303.
  • Ensures all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals.
  • Supports the PM or ISO in maintaining current authorization to operate, approval to connect (if required), and implementing corrective actions identified in the plan of actions and milestones.
  • Coordinates, with the PM and AO staffs, development of an ISCM strategy and monitors any proposed or actual changes to the system and its environment.
  • Continuously monitors the IT and environment for security-relevant events.
  • Assesses proposed configuration changes for potential impact to the cybersecurity posture.
  • Assesses the quality of security controls implementation against performance indicators.
  • Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the AO and other affected parties.
  • Ensures all ISSOs and privileged users receive necessary technical training and obtain cybersecurity certification IAW AFMAN 17-1301, AFMAN 17-1303, and maintain proper clearances IAW DoWI 8500.01.
  • Ensures the AF IT is acquired, documented, operated, used, maintained, and disposed of properly IAW DoWI 5000.02 and DoWI 8510.01.

What they require

  • U.S. Citizenship
  • Bachelor’s degree in a related field and 10 years of experience in the respective technical/professional discipline being performed.
  • Experience providing guidance on access control, configuration management, system and communications protection, contingency planning, incident handling, system and information integrity, security and privacy training and awareness, and software development activities related to Cybersecurity.
  • Experience performing cybersecurity duties as outlined in DoWI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT.
  • Experience validating, evaluating and analyzing finding results and developer adjudications using automated testing tools (e.g., Fortify, Checkmarx, SonarQube, AppScan).
  • Experience utilizing DoW tracking systems to input/document cybersecurity deficiencies, vulnerabilities, and change requests in appropriate tracking systems (e.g., Jira, HP ALM, eMASS).
  • Experience conducting information security continuous monitoring (ISCM) by maintaining ongoing awareness of information security, vulnerabilities, and threats IAW approved ISCM strategy.
  • Must meet the requirements for and maintain a personnel certification associated with the DCWF Information Systems Security Developer work role (631) at an advanced (principal) proficiency level as outlined in DoWI 8510.01, AFMAN 17-1305 and AFI 17-101 for assigned systems/applications.
  • Acceptable certifications listed: FITSI FITSP-D, GIAC GCSA, (ISC)2 CISSP-ISSEP.
  • Must have and maintain an active T3/ Secret security clearance.

Benefits

  • ESOP participation
  • 401(k) match
  • medical
  • dental
  • vision
  • life insurance
  • short-term disability
  • long-term disability
  • flexible spending accounts
  • Health Saving Accounts
  • Health Reimbursement Accounts
  • EAP
  • education assistance
  • paid time off
  • holidays

We are a 100% employee-owned, Certified Great Place To Work and named Best Places to Work in Huntsville/Madison County, headquartered in Huntsville, AL. Our team provides superior research, development, and engineering services to the Federal Government and Department of War. As one of the nation’s top 100 defense companies, the services we provide directly support the men and women who serve our country.

DefenseEnterprise

Details

Visa sponsorshipNo
Salary not disclosed