• Experience with operating systems for embedded real-time environments typically used in avionics and aircraft systems (not Mobile or IoT)
• Experience with securely configuring and hardening Linux and Windows based operating systems.
• Highly skilled at creating and updating JSIG based Body of Evidence (BoE) packages including SSPs, SCTMs, POA&Ms, etc to achieve and maintain system authorizations (ATOs, IATTs, etc.).
• Experience conducting JSIG/RMF based continuous monitoring (CONMON), system analysis and auditing, and vulnerability assessments using cyber security tools such as Splunk, Solarwinds, Tenable Nessus/ACAS, Trellix ePO, etc.
• Highly skilled at verifying and validating patches and Security Technical Implementation Guides (STIGs) to address cyber vulnerabilities, feature changes, or obsolescence.
• Experience with implementation and deployment of DoD requirements, policies and processes as part of the Risk Management Framework (RMF) Assessment and Authorization (A&A) process.
• Demonstrated experience with one or more of the following standards/guides: RMF, JSIG, CNSSI-1253, Common Criteria, NSTISSIP 11, DoD8500.1, DoD8500.2, JAFAN 6/3, DITSCAP, DIACAP.
• Familiarity with secure software design, analysis, architecture and containerization including the application of Development, Security, and Operations (DevSecOps) principles to software development pipelines.
• Experience creating, updating and implementing cyber security scripts with Python, JavaScript, Bash/Shell, Powershell or similar scripting language.
• Strong analytical and organizational skills with excellent communication skills (written and verbal communications) and the ability to work in a dynamic work environment.
• Familiarity with supporting and mitigating cyber based Supply Chain Risk Management (SCRM) concerns.