McBride Consulting has an exciting opportunity for a Principal Cybersecurity Engineer providing support to the Air Force Life Cycle Management Center-Ground Base Air Defense Sensor division (AFLCMC/ESG).
The ESG Division manages efforts focused on developing, acquiring, fielding and sustaining programs that support worldwide communications, Battle Management, Command & Control, Intelligence, Surveillance & Reconnaissance (C2ISR), Air/Ground Surveillance, Time Critical Targeting, Combat Identification, Radar Imagery, Integrated Air/Missile Defense, and Mobile/Fixed C2ISR Performance, Exploitation & Dissemination Facilities.
Duties include, but not limited to:
Lead development and review of system security documentation including System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, and security CONOPS in accordance with DoDI 5000.02, DoDI 8510.01, MIL-STD-1785, and the Adaptive Acquisition Framework
Support system and application Authorization & Accreditation (A&A) activities under the Risk Management Framework (RMF), ensuring completeness, quality, and compliance of all artifacts
Manage RMF implementation activities including ATO/ATC, reciprocity, and ongoing continuous monitoring
Administer and manage eMASS system packages
Provide technical leadership in network and system architecture design with an emphasis on cybersecurity, including DoD and joint networking environments
Support cross-domain solutions (CDS), Commercial Solutions for Classified (CSfC), and NSA approval processes
Assess and mitigate system, network, and application vulnerabilities, including ACAS scanning and STIG implementation
Recommend security configurations, software changes, and compensating controls to mitigate risk
Conduct cybersecurity risk and vulnerability assessments across planned and fielded systems
Develop risk-based mitigation strategies and advise leadership on security tradeoffs impacting mission execution
Recommend and update cybersecurity policies, procedures, and contingency plans, including disaster recovery
Support waivers and deviations for mandated security controls when required to meet mission performance needs
Provide acquisition program security support throughout the system lifecycle, including source selections
Maintain and audit classified information databases, visit records, clearance tracking, and classified holdings
Evaluate contractor classified data submissions for compliance with System Security Classification Guides (SSCGs)
Update security classification guides and prepare acquisition security documentation
- Advise government leadership on cybersecurity design, implementation, and compliance
- Collaborate with government and commercial stakeholders to achieve RMF authorization approvals
- Develop and deliver cybersecurity awareness and training programs
- Advise government leadership on cybersecurity design, implementation, and compliance
Requirements
Citizenship: Must be a US citizen
Minimum Required Qualifications
Clearance: Must have a be able to maintain a Top Secret Level Clearance
Education: BS/BA Degree
Years of Experience:20 years of directly related experience, 10 years of which must be in the DoD
- Risk Management Framework (RMF), with emphasis on taking projects from Step 1 to Step 5
- Vulnerability Management, Tenable Nessus (ACAS-DoD version of Nessus)
- STIGs
- CISSP Certification
Preferred Qualifications
- Experience with Cross Domain Solutions and USAF CDS-E
- Cloud Service Models
- Supply Chain Security
- NIAP
- DoD Policies for Procedures for Cybersecurity
- Network Security
- Endpoint
- DoD Impact Levels
- NSA Type 1 encryption
- Working with a CSSP - 16th AF
Additional Information:
Location: Hanscom Air Force Base
Onsite
Benefits
- 401(k)
- Dental
insurance
- Health
insurance
- Life insurance
- Paid time off
- Professional
development assistance
- Referral
program
- Vision
insurance
Skills Required
- Must be a US citizen
- Must have and be able to maintain a Top Secret clearance
- Bachelor's degree in any relevant field
- 20 years of directly related experience
- 10 years of experience supporting the Department of Defense
- Experience with Risk Management Framework, including taking projects from Step 1 through Step 5
- Experience with vulnerability management and Tenable Nessus or ACAS
- Experience with Security Technical Implementation Guides
- CISSP certification
- Experience with Cross Domain Solutions and USAF CDS-E
- Experience with cloud service models
- Experience with supply chain security
- Experience with NIAP
- Knowledge of DoD cybersecurity policies and procedures
- Network security experience
- Endpoint security experience
- Knowledge of DoD Impact Levels
- Experience with NSA Type 1 encryption
- Experience working with a CSSP or the 16th Air Force
What We Do
McBride Consulting, LLC is a minority and Service-Disabled Veteran-Owned Small Business (SDVOSB) management and IT consulting firm with significant experience supporting Federal, state, local, commercial, and multi-lateral organizations.








