Security Engineer III

Paragon Technology

Shiloh (IL)

On-site

USD 85,000 - 90,000

Full time

5 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Paragon Technology is seeking a Security Engineer III at Scott AFB, IL. The role focuses on vulnerability and risk assessment, network security, security product evaluation, and ISCM concepts to maintain authorization and improve security posture.

The engineer will work autonomously with PMOs, draft deliverables, and advise leadership on risk and security improvements, including contingency planning and secure release processes.

Qualifications

  • 4+ years of security engineering experience or equivalent roles.
  • Experience developing/ reviewing RMF documentation and security plans.
  • Ability to translate security risks into business impact for leadership.

Responsibilities

  • Review NIST requirements to support risk assessments and compliance.
  • Develop POA&Ms and support risk acceptance activities.
  • Collaborate with PMOs and government customers on security enhancements.

Skills

Security engineering
RMF
ISCM

Education

Bachelor’s degree in CS/Cybersecurity
IAM II Certification

Tools

eMASS
ACAS/Nessus

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Security Engineer III

Full Time Scott AFB, IL, US

4 days ago Requisition ID: 1232

Salary Range: $85,000.00 To $90,000.00 Annually

Paragon is recruiting for a Security Engineer III to work on the PEO-T contract for USTRANSCOM.

A team member assigned as a Security Engineer III provides technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation. Responsible for designing and implementing solutions for protecting confidentiality, integrity, and availability of sensitive information. Provides technical evaluations of IT systems and assists with making security improvements. Participates in design of information system contingency plans that maintain appropriate levels of protection and meet time requirements for minimizing operations impact to customer organization. Conducts security product evaluations, and recommends products, technologies and upgrades to improve the organization’s security posture. Understands Information Security Continuous Monitoring (ISCM) concepts, security automation, and risk dashboarding tools. Must adhere to USTRANSCOM processes and procedures to identify and respond to risk while supporting efficient, accurate Assessment & Authorization reporting to facilitate ongoing authorization(s), secure release deployments, modernizations, migrations, and overall security enhancements. Conducts testing and audit log reviews to evaluate the effectiveness of current security measures. Employees in this role are required to operates with a high-level of autonomy. They should be capable of defining the solution recommendations and working with management to improve efficiencies in processes and procedures. These team members will be involved in supporting teammates learning processes and procedures. These team members will participate in team initiatives including the drafting of deliverables and peer reviews of others’ draft products. They must be capable of communicating technical details effectively within their assigned Program Management Offices (PMOs), translating complex security risks into operational or business impact for leadership and non-technical stakeholders. Effective communication skills and willingness collaborate with peers and management are critical to success. These team members may be asked to provide supplementary support to additional PMOs within the contract purview.

Tasks include, but are not limited to, the following:
  • Reviews evolving NIST requirements to support risk assessment activities associated with the affiliated system requirements and specifications (execution, mapping, and compliance tracking).
  • Prepares detailed specifications from which cybersecurity deficiencies identified during risk assessment will be mitigated/remediated and conducts follow-up risk assessment to ensure proper secure coding practices and STIG/SRG implementation are being built-in/enforced to the greatest extent possible.
  • Collaborates closely with government customers to develop appropriate POA&Ms and support risk acceptance activities as needed to support risk management processes.
Qualifications:

4+ years relevant experience in security engineering [or equivalent job role(s) such as ISSO, ISSM, SCA, etc.]:

  • Expertise to develop and/or review system authorization documentation (family plans and supplementary artifacts) in accordance with Department of War (DoW) implementation of the Risk Management Framework (RMF)
  • Experience participating in Technical Interchange Meetings (TIMs) on a wide range of Program Management Office (PMO) security engineering topics
  • Experience participating in Acquisition program Engineering Milestone Reviews
  • Experience coordinating and collaborating with Development contract personnel in Security, System Administration, System Engineering, and other supporting roles to identify, document, and plan for security enhancement requirements and to resolve program security issues
  • Experience coordinating and collaborating with inheritance providers (i.e., enterprise teams in USTRANSCOM, SDDC, AMC, Defense Information Systems Agency (DISA) Security Office, etc) to determine hybrid security requirements and established appropriate inheritance relationships using tools provided
  • Expertise performing security activities to maintain authorization of the PMO programs (i.e., Categorization, Control Selection, Evidence Collection and Audit, Risk Assessments, Reporting, Security Impact Assessments affiliated with Change Management practices, IR/CP Exercise Support, FISMA Reporting, Continuous Monitoring, etc.)
  • Experience using DoW Enterprise Mission Assurance Support Service (eMASS) system
  • Experience providing support to ensure PMO systems are designed, developed, and deployed in accordance with applicable Executive Orders, Federal Policy, DoW regulations, USTRANSCOM requirements, and commercial best practice
  • Experience reviewing vulnerability results documented using the government approved Static Application Security Testing (SAST) solution [i.e., OpenText (Fortify) SCA], analyzing outputs to identify vulnerabilities, and recommend mitigation and remediation actions
  • Experience reviewing vulnerability scans using ACAS/Nessus, analyzing outputs to identify vulnerabilities, recommending mitigation and remediation actions, ingest actions in eMASS
  • Expertise supporting the Customer through critical review of documented DISA STIG/SRGs, providing technical feedback and recommendations to customer for areas of improvement in reporting accurate qualitative results, and ingesting final product in the government-supplied tool (eMASS) to support risk assessment of the NIST controls.
  • Experience generating, sustaining, extending (when appropriate), and reporting status associated with POA&M requirements
  • Expertise conducting and evaluating security testing activities including security assessments and audits
  • Experience supporting operational security activities (e.g., risk mitigation, host security, encryption, intrusion detection, Virtual Private Network [VPN] implementations, and viral detections)
  • Experience with security lockdown and/or hardening of servers and network devices
  • Ability to coordinate overall security strategy with multiple agencies, Authorizing Official (AO) representatives
  • Ability to coordinate with developers, vendors, and other government organizations/agencies to assess security engineering issues
  • Experience recommending changes to network and security architecture to improve security posture and meet operational performance requirements
Required Education/Certification:
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent Information Technology academic studies
  • Active IAM II Certification in Good Standing (e.g., ISC2 CGRC [formerly CAP], CompTIA Security X [formerly CASP+CE], ISACA CISM, ISC2 CISSP (or associate), GIAC GSLC, EC-Council CCISO)
  • Must be a US Citizen with an active DoW Secret, or higher, clearance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer III
Security Engineer III

ADP, Inc. • Illinois

On-site
USD 85,000 - 90,000
Security Engineer III
Security Engineer III

Paragon Technology • Illinois

On-site
USD 85,000 - 90,000
Security Engineer III
Security Engineer III

Socket.dev • Illinois

On-site
USD 110,000 - 170,000
Security Engineer III
Security Engineer III

Paragon Technology Group, Inc. • Illinois

On-site
USD 130,000 - 170,000
Security Engineer II
Security Engineer II

ADP, Inc. • Illinois

On-site
USD 80,000 - 85,000
Security Engineer II
Security Engineer II

Paragon Technology • Illinois

On-site
USD 80,000 - 85,000
Security Engineer II
Security Engineer II

Paragon Technology Group • Illinois

On-site
USD 90,000 - 125,000
Security Engineer II
Security Engineer II

Paragon Technology Group, Inc. • Illinois

On-site
USD 95,000 - 135,000
Information Systems Security Engineer III
Information Systems Security Engineer III

ARMADA, Ltd. • Philadelphia

On-site
USD 90,000 - 110,000
System Engineer IV
System Engineer IV

Paragon Technology • Shiloh (IL)

On-site
USD 120,000 - 130,000