Cybersecurity Engineer Journeyman Cybersecurity Jrym Hanscom Air Force Base Bedford, Massachusetts HX5 is an award-winning provider of engineering, research and development, and technical services to clients such as NASA and the Department of Defense. Founded in 2004, HX5 is a fast-growing veteran- and woman-owned company with locations nationwide.
HX5 is currently seeking a Cybersecurity EngineerJourneyman to support the Command, Control, Communications, and Battle Management (C3BM) directorate at Hanscom Air Force Base, located in Bedford, MA. The selected candidate will play a key role in ensuring secure operations across C3BM's mission areas by applying expertise in cybersecurity engineering, security operations, and risk management. The Command, Control, Communications, and Battle Management (C3BM) Directorate is charged with delivering an integrated Department of the Air Force (DAF) Battle Network-providing resilient decision advantage and enabling the USAF, USSF, Joint, and Coalition Forces to prevail against the pacing challenge. C3BM drives execution across multiple mission areas, including Architecture and Systems Engineering (ASE), the Operational Response Team (ORT), mission integration teams (Air, Maritime, and others), and acquisition programs such as the Advanced Battle Management System (ABMS) and Space initiatives. The Security Manager will provide support to perform administrative security functions under the direction of the activity security manager without regard for job series or title or for rank, rate, or grade if they have the clearance required for the access needed to perform their assigned duties and tasks. Essential Duties and Responsibilities:
Identify and evaluate opportunities to apply innovative and emerging technologies, automate processes, continually improve the conduct and efficiency of audit activities and enterprise audit compliance of systems and infrastructure, and identify metrics for monitoring improvements. Develop/update and maintain system-specific audit review dashboards and reporting mechanisms to show compliance across enterprise. Review data and prepare ACAS reports for SPO Leadership to include pre/post VVA reports, GCCS-J STRATCOM reports, etc. Generate Third Party Applications/Systems vulnerability reports and provide to team for resolution with COTs/GOTs owners. Assist with creation of ACAS TTPs, SOPs, and capture of lessons learned to improve performance, efficiency, and effectiveness of Cybersecurity personnel using the ACAS for the AOC WS Enterprise. Daily center reporting - verifying security compliance with IAVA's and DISA STIGS. Daily central server maintenance - check logs, syncs, job queues, CSU dashboards, validate scans are credentialed and ACAS scanners and Security Center are operational and reporting properly for AOC sites. Gathering, and reporting of AOC WS Software and Hardware information for EDS/CM team on a monthly or when requested. Ensure AOC WS 10.1 baseline aligns with OPORDS and Cyber Tasking Orders. Review ARE/FT ACAS documentation and redline as necessary. Support the research and analysis of DoD and AF policies and tasking orders to mitigate implementation problems that may impact the AOC WS 10.1 ACAS implementation. Provide subject matter expertise (SME) on ACAS (Assured Compliance Assessment Solution) systems and related processes. Promoting awareness of security issues among management and ensuring sound security principles are reflected in organizations' visions and goals. Assist in the design, implementation, configuration, and maintenance of ACAS tools and applications for the KR enterprise. Standardize ACAS reporting and provide oversight to internal and external leadership, 20+ sites (CONUS and OCONUS), and ACAS cyber team members. Review and approve reports and metrics related to ACAS scans and vulnerability management efforts before released to KR leadership. Analyze security vulnerabilities identified by ACAS scans and provide oversite and recommendations for remediation. Collaborate with ACAS teams to ensure proper integration and utilization of ACAS tools within KR. Stay updated on industry best practices and emerging trends related to ACAS and cybersecurity. Support training efforts for staff members on the use of ACAS tools and interpretation of scan results for KR. Develop scripting to work with the ACAS applications to reduce manual assessment of compliance reporting. Update and maintain the KR ACAS (Nessus scanners and Security Centers) system at Hanscom AFB, including planning, delivery, installation, security hardening, configuration, integration, and testing. Administering Red Hat Enterprise Linux, including: Building, patching, and configuring RHEL systems (RHEL 7/8) to meet STIG requirements. Configuring DNS, NTP, and network settings to support ACAS installation. Performing backups and restores of system OS and installed software. Provide SME level support to define, analyze, implement, secure, test, and deploy new requirements and enhancements for network monitoring, vulnerability identification, remediation, and security compliance IAW current OPORDS. Assist with automation and implementation of periodic vulnerability reporting from ACAS to internal and external KR organizations. Review of discovery scan results to identify systems not being vulnerability scanned and automated reporting. Review of vulnerability scan results to identify, troubleshoot, and resolve credential and other common scan issues, and automated reporting. Review and compilation of scan results to support asset inventory requirements and automation. Assessment of scan results to identify areas where vulnerability remediation has the greatest impact on risk and automated reporting. Configuration of ACAS components to align with DISA Best Practice Guidance. - Troubleshooting and resolution of communication issues between ACAS software components, failed plugin updates, and other common software issues with the Hansom ACAS Servers
Education and Experience: Must have one of the following combinations of education and experience:
- Bachelor's or Master's degree in a related field, and three (3) years of directly related experience, three (3) which must be in DoD.
- Seven (7) years of directly related experience, five (5) of which must be in the DoD
- DoD 8570.01 M IAT Level II certification
Preferred Education and Experience:
- Bachelor's or Master's degree in a professional engineering discipline from an ABET accredited program and at least seven (7) years of relevant experience, three (3) of which must be in DoD.
- Hold an active security+ certification
Position Type/Expected Hours of Work: This is a full-time position requiring 40 hours per week and offers a flexible work schedule Monday through Friday during core business hours. Other Position Requirements:
- Proof of U.S. Citizenship or US Permanent Residency is a requirement for this position.
- Must be able to complete a U.S. government background investigation.
- Must have or be able to obtain a Top Secret clearance by date of hire.
- Must be able to travel, including air travel.
HX5 offers a competitive salary and benefits package to include:
- Medical/Dental/Vision Insurance
- 401(k) plan with Company Match
- Paid Holidays
- Paid Time Off
- Parental Leave
- Life Insurance
- Tuition Reimbursement
- Identity Protection
- Medical and Dependent Care Flexible Spending Accounts
- Commuter/Transit Spending Accounts
- Group Legal Coverage Options
- Pet Insurance
HX5, LLC is an Equal Opportunity Employer that recruits and hires qualified candidates without regard to race, religion, sex, age, national origin, ancestry, citizenship, disability, or veteran status. HX5, LLC is a Drug Free Workplace Employer. ACCESSIBILITY NOTICE: If you need a reasonable accommodation for any part of the employment process due to a physical or mental disability, pleasecall (850) 362-6551. CJ
|