System Cybersecurity Engineer
Odyssey Systems Consulting Group, Ltd. · Colorado
📍 Colorado Springs, COvia icimsPosted 2024-07-25
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Odyssey Systems Consulting Group, Ltd..
Position Summary
Odyssey Systems has an exciting new opportunity for a System Cybersecurity Engineer to support SW&SS Directorate program offices at Peterson SFB, CO. This is a full-time position at Peterson SFB with some telework time approved at the discretion of the customer.
Responsibilities
Duties include, but not limited to:
Labor provided to deliver cybersecurity services are certified in accordance with DoDI 8140.03 and AFMAN 17-1303 standards.
DoDM 8140.03 and AFMAN 17-1303 standards.
Ensure that all system deliverables comply with latest applicable version of NIST SP 800-53, Risk Management Framework as incorporated and directed in DoW and Air Force/Space Force cybersecurity policy, specifically DoDI 8500.01, Cybersecurity , DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology , and AFI 17-101, Risk Management Framework (RMF) For Air Force Information Technology (IT).
Ensure that cybersecurity policy is implemented correctly on covered systems to both obtain and maintain Interim Authorities to Test (IATTs) and Authority to Operate (ATOs).
Direct the discovery, monitorization, and elimination or mitigation of both known and unknown vulnerabilities that could compromise the confidentiality, integrity, or availability of the information being processed, stored, or transmitted by covered systems and maintain eMASS Programs of Action and Milestones (POA&M) for same, to include DISA STIGs and the DoD IAVA/IAVM process.
Conduct Cybersecurity Risk Management for additions/changes to all systems via the Security Impact Assessment (SIA) process.
Develop a focused approach in the continual improvement of processes and producers to manage the RMF packages in Enterprise Mission Assurance Support Service (eMASS), Xacta and SGN/CORE.
Integrate Systems Security Engineering (SSE) into the DoW acquisition lifecycle, providing inputs on requirements, evaluating prime contractor deliverables (CDRLs), and serving as the primary cybersecurity SME during major program technical reviews (e.g., System Requirements Review [SRR], Preliminary Design Review [PDR], Critical Design Review [CDR]).
Oversee and validate contractor secure software development practices, ensuring the proper execution of automated security scanning (e.g., Static/Dynamic Application Security Testing [SAST/DAST], Software Composition Analysis [SCA]) within DevSecOps pipelines, and manage program Supply Chain Risk Management (SCRM) efforts.
Design Test & Evaluation (T&E) Requirements for RMF Control identification, to include building implementation plans and validation plans, overseeing broader Cybersecurity Test and Evaluation (T&E) strategies (e.g., Test & Evaluation Master Plan [TEMP] inputs, cooperative/adversarial assessments), in accordance with DoDM 5000.103, Cyber Developmental Test and Evaluation , and DoDI 5000.89, Test and Evaluation , assist with the entry and review of entered information to the Information Technology Investment Portfolio Suite (ITIPS), assist with the preparation and review of Federal Information Security Modernization Act documentation.
Advise on the secure design and integration of continuous monitoring architectures, and Zero Trust models, to include ensuring systems can securely interface and share required telemetry with enterprise Defensive Cyberspace Operations (DCO) and Cybersecurity Service Providers (CSSP).
Perform the full range of cyber security and information security processes, procedures, and functions, to include reviewing data, maintaining/implementing and compliance notification of required IAVAs, NOTAMs and cybersecurity posture for systems. This includes leading cybersecurity working groups to coordinate efforts across engineering, software, and test stakeholders.
Advise division leadership on architecture mitigations to limit risk posture within the systems and represent the risk posture in briefings and slides to DoD Chief Information Officer, Headquarters USSF and USSTRATCOM; utilize National Institute of Standards and Technology (NIST) 800 series special publications in the development of new system artifacts to ensure compliance.
Qualifications
Minimum Qualifications:
Citizenship: Must be a US Citizen
Clearance: Must have and be able to maintain a Top-Secret Security Clearance
Certification: DoD IAM Level I (CAP, CND, Cloud+, GSLC, Security+ CE, CISSP)
Education: High School Diploma
Years of Experience: 10 years’ directly related experience with proper certifications as described in the functionally aligned job description, 5 of which must be in the DoD; OR ,
BA/BS degree and 5 - 8 years of experience in the respective technical/professional discipline being performed, 3 of which must be in the DoD; OR ,
MA/MS degree and 2 - 3 years of experience in the respective technical/ professional discipline being performed, 2 of which must be in the DoD
Additional Experience:
Demonstrated experience building, managing, and successfully navigating Enterprise Mission Assurance Support Service (eMASS) packages through the complete Risk Management Framework (RMF) lifecycle to achieve Interim Authorities to Test (IATT) and Authorities to Operate (ATO).
Demonstrated experience in software engineering, secure coding practices, and the direct administration or engineering of DevSecOps Continuous Integration/Continuous Deployment (CI/CD) pipelines.
Experience securing and evaluating virtualization technologies, container orchestration platforms (e.g., Kubernetes), and hypervisors.
Experience engineering or assessing systems designed to meet Zero Trust Architecture (NIST SP 800-207) principles.
Familiarity with crypto-agile architectures and evolving NSA cryptographic modernization standards (CNSA 2.0).
Familiarity with Model-Based Systems Engineering (MBSE) tools (e.g., Cameo, DOORS) for requirements traceability.
Experience navigating the Mission-Based Cyber Risk Assessment (MBCRA) proces
More Colorado jobs
Colorado jobs · Browse all locations