Cyber Security Systems Engineer - Expert with Security Clearance
We're searching for talented individuals who provide engineering services for network infrastructure as well as sophisticated enterprise computing infrastructure including end–point devices, data center hosted servers, multi–Cloud services as well as virtualized applications, and storage systems. This program will maximize the effectiveness and efficiency of our country's most important missions both at home and abroad. If you are ready to support a high–performing team that truly makes a difference, then come join us!
Job Description: We are looking for a Cyber Security Systems Engineer to join our technology–based program supporting a key government customer. The Cyber Security Systems Engineer assesses and mitigates system security threats/risks throughout the program life cycle. Contributes to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations. As a Cyber Security Systems Engineer, you will play a crucial role in enhancing our security infrastructure and ensuring a secure network.
Responsibilities:
- Assess and mitigate system security threats/risks throughout the program life cycle.
- Contribute to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations.
- Document the various security control implementations and gather artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for various Assessment and Authorization (A&A) efforts.
- Document and obtain a general understanding of the architecture being developed or that was developed for each project to write the Systems Security Plans (SSP)/CONOPS in the Xacta application.
- Gather information by working with various team members to write various additional A&A related documents such as Contingency Plan (CP), General User Guide (GUG), Privileged User Guide (PUG), Standard Operating Procedures (SOP's), etc.
- Support Accreditation and Authorization (A&A) reviews by ISSO/M, as well as the Security Controls Assessor (SCA).
- Document the Plans of Actions and Milestones (POA&Ms) implementation responses or mitigations, and provide all required artifacts.
- Coordinate with various contractor and staff personnel to obtain the A&A content, and work with various customer security organizations to navigate the customer's A&A process to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), as well as Authority to Operate (ATO).
- Keep track of where each of the various A&A projects are within the customer's A&A process to know when it's time to re–submit for accreditation or an accreditation extension.
Minimum Requirements:
- Minimum of Sixteen (16) years' experience supporting the customer's A&A projects.
- Possess multi–tasking skills, as well as be a good communicator/facilitator.
- Knowledge of complex network environments involving shared networks and multiple security enclaves.
- Ability to bridge the technical implementation into commonly understood security terms.
- Experience with various security tools and reports such as Xacta, RoadRunner, Rapid 7, WebInspect, App Detective, and Splunk.
- Public, private, and hybrid Cloud experience (AWS, Microsoft Azure, etc.)
- Basic knowledge of Cloud security control implementation, PKI implementation, STIG compliance and vulnerability management, and Security Development and Operations (SecDevOps).
- CISSP, or GSLC AWS Certified Security Specialty.
- Basic Excel and Microsoft Office365.
Qualifications:
- Bachelor's or Master's Degree are preferred in one or more technical disciplines but can be waived if previous direct ISSE support to this customer's agency.
- Three (3) years of experience can be considered in lieu of a degree for a total of six (6) years of experience.
- Position requires active Security Clearance with appropriate Polygraph.