ISSE
$112,000–$179,000 year
On-siteWashington, District of Columbia, United States or Herndon, Virginia, United States
Job Summary
Define information security requirements and integrate them into systems through purposeful security design. Develop and implement security designs ensuring hardware, operating systems, and software applications address cyber security requirements and Security Controls Traceability Matrix. Identify points of vulnerability, non-compliance with Information Assurance standards, and recommend mitigation strategies. Implement Security Technical Implementation Guide (STIG) requirements and perform SRG assessments for development projects. Develop, customize, and configure Splunk applications and dashboards. Develop Security Test Procedures, conduct self-assessments to verify compliance, and support A&A testing of security designs. Conduct risk analysis reviewing ACAS, CVEs, plugins, and CWEs to collaborate with System Administrators on mitigating vulnerabilities or authoring Plans of Actions and Milestones. Execute continuous monitoring efforts, responding to data calls, scan requests, and reporting weekly and monthly security metrics. Validate control implementations to enforce data access and network flow restrictions aligning with the continuous monitoring strategy. Participate in Agile Planning Events to provide technical input. Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework.
Required Qualifications
- Bachelor's degree in a relevant technical (STEM) field
- 8+ years of relevant experience
- Master's degree in a relevant technical (STEM) field
- 6+ years of experience with Master's degree
- 4+ additional years of experience in lieu of a degree
- TS/SCI with polygraph clearance adjudication
- Ability to obtain SCI and pass a poly
- Certified Information Systems Security Professional (CISSP) Certification
- One (1) year of experience with IC Community
- Proven experience in scripting languages
- Proven experience with Linux/RedHat
- Proven experience with Windows Server
- Proven experience with Networking Appliances
- Proven experience with DISA Security Technical Implementation Guide (STIG) implementation
- Proven experience with Security Content Automation Protocol (SCAP) tool usage
- Proven experience performing Systems Security tasks including: Security Information and Event Monitoring (Splunk)
- Proven experience performing Systems Security tasks including: Endpoint security (HBSS)
- Proven experience performing Systems Security tasks including: Compliance and vulnerability scanning (ACAS / Nessus)
- Demonstrated experience with creating and validating evidence for NIST security controls
Desired Qualifications
- Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems
- Possess a working knowledge of administrating servers, system and application security threats and vulnerabilities
- Experience extending existing applications in areas such as security, monitoring, task automation, continuous integration, deployment, and performance optimization
- Demonstrate writing of your own project in scripting/programming (use of Shell scripting, Python, Javascript, Powershell) in a Linux or Windows environment to support the various Cyber Security tools and applications required
- Provide guidance on vulnerability and malware remediation
- Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future
Additional Requirements
- Requires TS/SCI with polygraph clearance or ability to obtain it
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.