Cybersecurity (ISSO) Journeyman Job at Crossflow Technologies in Dayton
Crossflow Technologies, Dayton, OH, United States, 45444
Job Description
Job Title: Cybersecurity (ISSO) Journeyman
Location: Kettering, OH (Dayton/WPAFB)
Position Overview: Crossflow has an exciting opportunity for a Cybersecurity Engineer (ISSO) located Kettering, OH (Dayton/WPAFB area) to support two programs on our EPASS GB contract. As part of the AFLCMC/GB Business and Enterprise Systems Directorate (BES), the Requirements Management System (RMS) is used to forecast/determine, budget, and procure the range and depth of aircraft spare parts requirements based on aircraft and depot maintenance usage and readiness and sustainability goals. RMS supports the warfighter by computing procurement requirements for spares and determining depot level maintenance repair needs for the AF. RMS encompasses the automated and manual functions involved in the materiel requirements process. This process forecasts and controls procurement and repair requirements of materiel needed for logistics support of AF operated weapon systems. The warfighter aircraft maintainer benefits by having availability of the correct mix of spare parts to satisfy planned weapon system quantities and capabilities. The materiel involved is in direct support of the AF weapon systems and has a significant impact on the AF's ability to carry out its mission. RMS addresses the AFMC top-level Mission Essential Tasks and Objectives of Supply Management: "Provide and deliver repairable and consumable items (right product - right place - right time - right price).
ESSENTIAL DUTIES/POSITION DESCRIPTION:
The successful candidate will provide the PMO/Capability Development Manager (CDM) cybersecurity support per DoDI 8500.01. Support includes assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities adhere to enterprise standards such as Risk Management Framework (RMF), Cybersecurity Framework (CSF), and National Institute of Standards and Technology (NIST) and per Authorization Official's Information System's Continuous Monitoring (ISCM) strategy.
The Information System Security Officer (ISSO) is responsible for ensuring the appropriate operational security posture is maintained for the assigned IT. This includes the following related to maintaining situational awareness and initiating actions to improve or restore cybersecurity posture:
• Implements and enforce all AF cybersecurity policies, procedures, and countermeasures.
• Completes and maintains required cybersecurity certification IAW AFMAN 17-1303.
• Ensures all users have the requisite security clearances and need-to-know, complete annual cybersecurity training, and are aware of their responsibilities before being granted access to the IT according to AFMAN 17-1301. 2
• Maintains all authorized user access control documentation IAW the applicable AF Records Information Management System.
• Ensures software, hardware, and firmware complies with appropriate security configuration guidelines, e.g., security technical implementation guides/security requirement guides.
• Ensures proper configuration management procedures are followed prior to implementation and contingent upon necessary approval.
• Coordinate changes or modifications with the system-level ISSM, SCA, and/or the Wing Cybersecurity office.
• Initiates protective or corrective measures, in coordination with the ISSM, when a security incident or vulnerability is discovered.
• Reports security incidents or vulnerabilities to the system-level ISSM and wing cybersecurity office according to AFI 17-203, Cyber Incident Handling; and,
• Initiates exceptions, deviations, or waivers to cybersecurity requirements.
JOB REQUIREMENTS/QUALIFICATIONS:
The Information Systems Security Officer (ISSO) has the knowledge, experience and demonstrated ability to perform tasks related to the technical/professional discipline they are performing. Typically works independently and applies the proper procedures and processes related to their area of expertise. Has the ability to problem solve and troubleshoot various situations to develop successful outcomes within established program/project guidelines. Work is performed independently or under the oversight of more senior contractor employees (Program Office and Staff Level Support interface).
All Cybersecurity professionals should possess experience providing guidance on the following to include, but not limited to:
• Access control.
• Configuration management.
• System and communications protection.
• Contingency planning.
• Incident handling.
• System and information integrity.
• Security and privacy training and awareness; and,
• Software development activities, software and tools related to Cybersecurity.
Experience performing cybersecurity duties as outlined in DoDI 8500.01, AFI 17-130, and AFI 17-1301 for assigned AF IT.
Experience validating, evaluating and analyzing finding results and developer adjudications using automated testing tools, e.g., Fortify, Checkmarx, SonarQube, and AppScan.
Experience utilizing DoD tracking systems to input/document cybersecurity deficiencies, vulnerabilities, and change requests in the appropriate tracking system for each program, e.g., Jira, HP ALM, and eMASS.
Experience with conducting information security continuous monitoring (ISCM) by maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions IAW approved ISCM strategy.
EDUCATION:
Bachelor's or Master's Degree in a related field and at least three years of experience in the respective technical/professional discipline being performed, three of which must be in the DoD
3
OR, seven years of directly related experience with proper certifications, five of which must be in the DoD.
CERTIFICATION REQUIREMENTS:
At a minimum, the successful candidate will meet the requirements for and maintain a DoD 8570.01 IAT Level II Cybersecurity certification by possessing one of the following certifications:
• Cisco CCNA Security
• CompTIA CSA+/CySA+
• GIAC GICSP
• CompTIA Security+ CE
• (ISC)2 SSCP
• GIAC GSEC
• EC-Council CND
OTHER QUALIFICATIONS:
Candidate must be a US Citizen - REQUIRED
Candidate must possess and be able to maintain a T3/SECRET Clearance - REQUIRED
Benefit-Eligible Employee Perks:
EXCEPTIONAL HEALTH, DENTAL, AND VISION COVERAGE
Crossflow is pleased to offer employees with exceptional single and family options for health, dental, and vision coverage. Payments are taken from the first two paychecks of each month. At a glance,
• Health coverage choices (including an HSA) ranging from $0.00 to $146.40;
• Dental coverage ranges from $4.00 to $15.00; and
• Vision coverage ranges from $4.33 to $11.41.
CROSSFLOW KUDOS SPOT BONUS PROGRAM
We created a unique performance bonus program called Crossflow Kudos. Throughout the year, employees are nominated by other employees, company leads, and even individuals outside of Crossflow to receive additional compensation and personal recognition for their positive work. There are six broad categories in which employees can earn Kudos awards.
401(k) RETIREMENT PLAN & COMPANY MATCHING
Crossflow uses Principal as our 401(k) plan sponsor. Employees can choose payroll deduction and fund investing options. Payroll deductions will begin the month following your enrollment. Crossflow matches 100% of the first 3% of compensation, plus 50% of the next 2% of compensation.
HIGHER EDUCATION ASSISTANCE PROGRAM
Crossflow offers education assistance to benefit-eligible employees for degree programs at their director's discretion. Crossflow feels that a well-rounded education, even outside of an employee's current role, can enhance an employee's skillset and increase the company's value.
GENEROUS PTO ACCRUAL & FLEXIBLE LEAVE POLICY
Crossflow currently grants 11 federally observed paid holidays. In addition to these holidays, Crossflow offers a minimum of 2 weeks of paid time off (PTO) to all full-time employees. Employees may utilize PTO for any reason (sickness, vacation, personal day, etc.) and can carry over a maximum of 80 hours from year to year. Many employees are authorized to work additional hours within a normal, forty-hour pay period. This approval is included in the employee's offer letter for employment. These extra hours may be banked for compensatory (comp) time off.
PAID PARENTAL & BEREAVEMENT LEAVE
To help our employees be present with family during major life events, Crossflow provides additional PTO. We offer varying types of paid Parental Leave to aid birthing, non-birthing, and adoptive parents transition into parenthood. Crossflow also recognizes the importance of supporting employees who endure a death in their family by providing up to 5 days of paid Bereavement Leave a year.
PROFESSIONAL DEVELOPMENT FUNDING
We support employees who seek out personal or professional growth opportunities through a myriad of enabling programs to further equip themselves. Professional Development includes, but is not limited to, training courses, certificate programs, memberships to industry groups, and materials.
EMPLOYEE DRIVEN COMMUNITY ENGAGEMENT
We create as many opportunities as possible for employees to meet and build community. We offer monthly team bonding activities, allowing team members to assemble on a different level than at work. In addition to these gatherings, in 2021 we established Crossflow Cares, an employee-owned and operated charitable organization focused on awarding grants and providing volunteers to local non-profits. Furthermore, Crossflow Technologies is committed to serving the public by investing a large portion of our net income in the greater Huntsville/Madison County area.
MENTORSHIP PROGRAM & MORALE LUNCHES
The most successful people in the world always have a terrific team behind them, and Crossflow chooses to be the team behind the people, cheering our employees on to meaningful successes. Our Mentorship Program involves strategically pairing a protégé with a mentor who understands an employee's career aspirations and provides coaching towards that goal. A less structured version of this is our Morale Lunch program. We committed a portion of our budget to support our leads to meet with their team members over lunch and facilitate quality catch up sessions. The morale lunches have become a great tool for maintaining open communication and gaining insightful feedback.