Principal Cybersecurity Engineer

KIHOMAC
Massachusetts

Expertise and Functions

  • Develop System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, Computer Certification and Accreditation, Security Vulnerability and Countermeasures Analyses, Security Concepts of Operations, and other system security engineering-related documents identified in MIL-STD 1785, DoDI 5000.02, Operation of the Adaptive Acquisition Framework, and DoDI 8510.01
  • Support system and application Authorization and Accreditation (A&A) effort to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and Air Force policies (i.e., Risk Management Framework (RMF)
  • Update, monitor, and manage information in systems for the program office
  • Process and manage user account requests, access controls, port/protocol requirements, access control lists, and Public Key Infrastructure (PKI) identification and authorization
  • Manage the distribution, implementation, remediation, and tracking of system security updates and configurations as required by the DoD
  • Recommend policies and procedures to ensure information systems reliability and accessibility to prevent and defend against unauthorized access to systems, networks, and data
  • Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risk, and protection needs
  • Promote awareness of security issues among management and ensuring sound security principles are reflected in organizations’ vision and goals
  • Conduct systems security evaluations, audits and reviews
  • Recommend systems security contingency plans and disaster recovery procedures
  • Recommend and implement programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures
  • Participate in network and systems design to ensure implementation of appropriate systems security policies
  • Recommend initial, or updates to, software and configurations to new or existing system security mechanisms
  • Obtain waivers to mandated security mechanisms/policies which would be detrimental to system performance and impact the system’s mission
  • Facilitate the collection, analysis and preservation of evidence used in the prosecution of computer crimes
  • Provide leadership assistance in the analysis of the design, development, integration, implementation and testing of cybersecurity requirements
  • Develop risk-based strategies to address identified gaps
  • Review, analyze, and assess implementations of cybersecurity (i.e. RMF security controls) throughout the open systems architecture and associated services, derived requirements specifications, design documents & design implementation
  • Collaborate with Government and commercial stakeholders to obtain system authorization approvals from Authorizing Officials throughout the RMF A&A process.
  • Provide technical advice in the area of systems security across all systems and supports
  • Develop recommendations for the Government regarding how well designs satisfy current requirements and business goals
  • Maintain databases that reflect receipt, storage, inventory, and disposition of classified information to include data entry, updates, and generation of reports
  • Support Government program office in audits of Government classified holdings to ensure proper accountability
  • Maintain databases of classified visits and clearance levels
  • Perform inspection, inventory, logging, storage, documentation, transmittal and internal distribution of classified information received
  • Evaluate Contractor classified data submittals for compliance with the appropriate System Security Classification Guide (SSCG)
  • Provide security inspection and protection to areas where classified information is being stored, and develop and establish security procedures and policies IAW DOD, USAF, AFMC, and local directives
  • Develop training and provide security awareness and other security education programs
  • Review and verify personnel qualifications for access to special access programs
  • Develop, implement and maintain a communications security program
  • Assess program disclosure issues and provide FMS case management support
  • Advise FMS program office management and leadership in interfacing with FMS customers and all USG organizations, including but not limited to SAF/IA, Air Force Security Assistance Center (AFSAC), Air Force Security Assistance Training (AFSAT) squadron, Defense Finance and Accounting Services (DFAS)
  • Support execution of all aspects of acquisition program security throughout a program’s lifecycle
  • Develop and support the implementation of security practices and policies related to acquisition, physical, personnel, and documentation security.
  • Update security classification guides
  • Prepare acquisition security related sections of acquisition program documentation
  • Review Contractor deliverables to ensure compliance with CDRLs
  • Plan and implement security-related surveys, assessments, and studies
  • Evaluate program security information and hardware throughout the program life cycle, to include studies, analyses, plans, procedures, production, test plans/results, transportation, technology, and storage of end items
  • Provide security support to source selections
  • Other duties as assigned

Requirements

Education/Training:

  • Bachelor’s degree required
  • CISSP Certification required

Experience:

  • 15+ years of general work experience
  • 10+ years of experience in a DOD setting
  • Risk Management Framework (RMF), with emphasis on taking projects from Step 1 to Step 5
  • Vulnerability Management, Tenable Nessus (ACAS-DoD version of Nessus)
  • STIGs
  • Experience with Cross Domain Solutions and USAF CDS-E
  • Cloud Service Models
  • Supply Chain Security
  • NIAP
  • DoD Policies for Procedures for Cybersecurity
  • Network Security
  • Endpoint
  • DoD Impact Levels
  • NSA Type 1 encryption
  • Working with a CSSP - 16th AF

Security:

  • Must be a US citizen
  • Must have an active TS clearance

Physical Requirements:

  • Able to occasionally reach with hands and arms
  • Prolonged periods of computer screen use, while sitting or standing at a desk
  • Adhere to safety protocols when in work areas requiring use of PPE (e.g. eyewear, gloves, masks, hearing protection, steel toed shoes, etc.)
  • Able to safely lift and carry up to 20 pounds at a time

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources

Posted 2026-02-07

Recommended Jobs

Orthopedic Physician Assistant - Inpatient & Outpatient

Northeast Healthcare Recruitment, Inc.
Boston, MA

We are seeking a full-time Orthopedic Physician Assistant to join an established orthopedic team just south of Boston. This role includes both inpatient and outpatient responsibilities, working closel…

View Details
Posted 2026-01-28

Senior Paid Search Strategist

829 Studios
Boston, MA

The Senior Paid Search Strategist position is a senior level, client-facing role within 829’s Marketing Services department. This position is ideal for someone who is proactive, a great communicator, …

View Details
Posted 2026-01-14

Sales Support Specialist

Checkwriters
Northampton, MA

We’re looking for a go-to teammate who keeps our Sales Team shining and our clients raving. In the Sales Support Specialist role, you’ll join prospect calls, run demos, create proposals, and help new…

View Details
Posted 2025-08-19

Nurse Practitioner or Physician Assistant - Primary Care

Northeast Healthcare Recruitment, Inc.
Boston, MA

We are seeking a Nurse Practitioner or Physician Assistant to join our thriving outpatient primary care practice in a beautiful, state-of-the-art facility located just 45 minutes from Providence, RI, …

View Details
Posted 2026-01-28

Consultant Strategy - US Healthcare

2070Health
Boston, MA

*Please note this role is not for 2070 Health* Decimal.Health is a boutique digital health innovation consultancy and venture studio. We are a clinician-led company with over two decades of experi…

View Details
Posted 2025-09-03

Temp - Tech - MRI (Days) Pittsfield, MA

North Adams, MA

Type: Magnetic Resonance Imaging Pittsfield , MA   SkyBridge Healthcare is currently seeking Technologist with Magnetic Resonance Imaging experience for a 13-week contract in MA. SkyBridge Hea…

View Details
Posted 2025-08-07

Group Leader, Microsystems Integration

Draper
Cambridge, MA

Overview: Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of…

View Details
Posted 2026-02-06

System Administrator

SGS Consulting
Massachusetts

Job Responsibilities: Provide Tier-3 Support for FPGA development and integration into sensor test-beds and product lines. Provide Linux System Engineering and Integration insights into proprie…

View Details
Posted 2025-11-14

Director, State Management Analytics

MAPFRE
Webster, MA

Director, State Management Analytics Date: Jan 16, 2026 Location: Webster, MA, US Company: MAPFRE Summary The Director of State Management & Analytics leads a high-imp…

View Details
Posted 2026-02-02

Child and Special Needs Unit Nurse Program Director

Westborough Behavioral Healthcare Hospital
Westborough, MA

The Child and Special Needs Unit Program Director maintains direct oversight of the clinical and administrative operations of Westborough Behavioral Healthcare Hospitals’ Child and Special Needs Unit…

View Details
Posted 2026-01-14