Cyber CareersHybrid Remote , Bethesda,Maryland
Location:
Bethesda, MD
Security Clearance:
Active TS/SCI
Responsibilities:
- Collect, review, assess, and provide feedback on system cybersecurity, architecture, and engineering artifacts
- Collect, review, assess, and provide feedback on system cybersecurity Body-of-Evidence (BOE) results required to support DoD & IC RMF cybersecurity authorization processes
- Conduct periodic compliance scanning, vulnerability assessments, and risk analysis for cloud-based systems
- Implement and manage security controls for containerized applications and the underlying cloud-based infrastructure
- Collaborate with DevSecOps, infrastructure, and software development teams to ensure secure coding and engineering practices
- Ensure integration of security measures into software development processes, CI/CD pipelines, and engineering tools
- Develop, maintain, and execute shell commands, scripts, and automation code for STIG compliance and validation
- Implement and manage continuous monitoring solutions of cloud-based architectures
- Support Government cybersecurity officials & program personnel in preparing cybersecurity packages, including Interim Authority to Test (IATT) packages, Authority to Operate (ATO) packages, and Change Requests (CRs)
- Stay current with emerging cloud security threats, technologies, and best practices
- Active or current Top Secret with SCI eligibility and the ability to obtain Polygraph
- Bachelor’s degree in Cybersecurity, Computer Science, Information Assurance, Engineering, or related technical discipline and 8-12 years of relevant experience OR Master’s degree with 6-10 years of relevant experience. Additional years of experience may be considered in lieu of a degree. ISSO experience must be supplemented with demonstrated technical expertise.
- Certification: At least one DoD 8570.01-M IAT and one IAT Level II or higher certification e.g., CCNA Security, CySA+, Security+ CE, CISSP (or Associate) and the ability to obtain Privileged User Account (PUA)/elevated access per DoD 8570 policy, and Linux+ certification
- At least 5 years of experience hardening Linux hosts and applying DISA STIG
- Demonstrated experience securing Kubernetes platforms (secrets management, RBAC, etc.) and integrating security into CI/CD pipelines and containers
- Demonstrated experience developing A&A packages to obtain and maintain ATO in secure environments.
- Grounded knowledge in NIST SP 800-37, SP 800-53, CNSSI 1253
- XACTA/eMass experience, performing vulnerability compliance with ACAS, STIG automation
- Experience with scripting languages (Bash, Python)
- Understanding of secure software development practices and code reviews
- Experience with encryption and transport
- Understanding of microservices architecture and service mesh.
Preferred Qualifications:
- Active TS/SCI with polygraph
- Experience with Commercial Cloud Services (C2S) and cloud-based enterprise services, preferably AWS
- Experience supporting the Intelligence Community in RMF activities with ICD 503 and related compliance directives, policies, procedures
- Experience with the Zero Trust pillars and applying Zero Trust framework to secure systems
- DAST & SAST tools for on-prem (Fortify, Checkmarx, SonarQube), configuring Nessus, Splunk
- Multiple IAT/IAM II or III advanced certifications such as, CISSP-ISSAP/ISSEP, CISM, CCSP, Security X/CASP+
- Cloud certifications such as AWS Solutions Architect, AWS Security Specialty, Kubernetes and Cloud Native Associate (KCNA), Certified Kubernetes Administrator (CKA), Certified Kubernetes Security Specialist (CKS)
- Experience applying security controls to various AI implementations
- Experience with ICD 503 compliance
- Experience applying security controls to Generative AI implementations
About Xcelerate Solutions:
Founded in 2009 and headquartered in McLean, VA, Xcelerate Solutions (www.xceleratesolutions.com) is one of America's fastest-growing companies. Xcelerate’s cultureis definedby our diversified workforce of dynamic and versatile professionals, supported with growth and development opportunities that contribute to individual and company growth. This strong commitment to our employees hasbeen recognizedby our inclusion on the Washington Business Journal’s “50 Best Places to Work” list as well asbeing a “Great Place to Work” certified company with a 4.6 star, and a 99% CEO approval Glassdoor rating. Come find out why Xcelerate Solutions is one of the DC Metro top employers!
Xcelerate Solutions is an Equal Employment Opportunity/Affirmative Action Employer. We evaluate qualified applicants without regard to race, color, national origin, religion, age, equal pay, disability, veteran status, sex, sexual orientation, gender identity, genetic information, or expression of another protected characteristic. As part of this commitment to the full inclusion of all qualified individuals, Xcelerate provides reasonable accommodations if needed because of an applicant's or an employee's disability.
Pay Transparency Notice: Xcelerate Solutions will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.