Senior Cybersecurity Specialist
Dayton, Ohio
Full Time Senior-level / Expert Clearance required USD 99K - 184K * est.
Phalanx Griffon (PG) is a topâpriority, openâarchitecture airborne node that stitches warfighter data into the DAF BATTLE NETWORK. As Senior Cybersecurity Specialist, you will be the programâs authority on securing Nomad hardware, Smith software, and Watch operations throughout Major Release 2 (FY 25â27). Your zeroâtrust designs, continuousâATO tooling, and crossâdomain safeguards will decide when PG can flyâand fightâin contested environments.
Essential Job Functions
Cyber Strategy & Governance
⢠Own the PG Cybersecurity Strategy, System Security Plan (SSP), and Plan of Action & Milestones (POA&M).
⢠Align all efforts with NIST 800â53, CNSSI 1253, and Air Force ZeroâTrust Reference Architecture.
⢠Chair cyber risk boards; brief metrics & burnâdowns to SES/GO stakeholders.
RMF & Continuous ATO
⢠Lead the PG Risk Management Framework (RMF) process from categorization through authorization; shepherd artifacts in eMASS.
⢠Stand up automated compliance scans (ACAS, SCAP, Nessus, Tanium) integrated with the DevSecOps pipeline; deliver continuousâATO dashboards.
Secure DevSecOps & SupplyâChain Risk
⢠Embed SâBOM analysis, container hardening, and codeâsigning into Smithâs 90âday software release cadence.
⢠Evaluate thirdâparty components for supplyâchain threats; drive mitigations and waivers.
CrossâDomain & Crypto Engineering
⢠Develop guard rulesets and dataâflow enforcement for MultiâLevel Security (MLS) crossâdomain solutions.
⢠Coordinate Typeâ1 crypto keyâmanagement plans with NSA; author KOVâ11 / SKL handling procedures.
Vulnerability Management & Incident Response
⢠Conduct penetration tests and redâteam exercises on Integration SIL builds; track findings to closure.
⢠Draft and rehearse PGâspecific incidentâresponse / huntâforward playbooks for Watch operations.
Platform & FlightâTest Support
⢠Generate âcyber annexesâ for AF Form 1067s, SafetyâofâFlight packages, and Interim Authorizations To Test (IATT).
⢠Deploy secure configs on flight hardware; provide onâsite cyber assurance during ground & flight events.
Mentorship & Culture
⢠Coach engineers on secureâbyâdesign principles, STIG implementation, and zeroâtrust concepts.
⢠Foster a DevSecOps, failâfast mindset inside classified environments.
Required Skills:
Due to the sensitivity of customer related requirements, U.S. Citizenship is required.
B.S. in Cybersecurity, Computer Science, Information Systems, or related field and 15 + years securing DoD or IC C4ISR/avionics systems; at least 5 years as the lead cybersecurity engineer or ISSM or a Masters plus 12 years of experience.Â
Active TS/SCI clearance.
Handsâon mastery of RMF, NIST 800â53, DISA STIGs, SCAP/ACAS, and eMASS workflows.
Experience designing or accrediting crossâdomain solutions and Typeâ1 crypto architectures.
Working knowledge of container security, IaC (Ansible/Terraform), and DevSecOps pipelines (Platform One, Iron Bank).
Desired Skills:
DoD 8570/8140 IAM/IASAE Level III certification (CISSPâISSEP, CISM, GSLC, etc.).
Prior involvement in ABMS, CJADC2, OMS/UCI, or tactical dataâlink programs.
Familiarity with zeroâtrust enforcement for SATCOM, SDR, and softwareâdefined networking environments.
Redâteam / penâtest credentials (OSCP, GXPN, CEH) and experience authoring mitigations.
Agile/Scrum or SAFe certification.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index đ°
Tags: ACAS Agile Ansible CEH CISM CISSP Clearance Compliance Computer Science Crypto DevSecOps DISA DoD DoDD 8140 DoDD 8570 eMASS Governance GSLC GXPN IAM Incident response Nessus NIST OSCP POA&M Risk management RMF SCAP Scrum STIGs Strategy System Security Plan Terraform TS/SCI Vulnerability management
Perks/benefits: Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.