Assertive Professionals is seeking an Information System Security Engineer (ISSE) with Poygraph supporting our National Security Customer in Chantilly, VA.
This is a pipeline position.
Annual base compensation is $165,000 with either a $10,000 sign-on bonus or reimburseable relocation, plus an annual compliance bonus up to $1,200.
This is a great opportunity to work for an employee-centric, fast-growing small business. We offer an excellent benefits package, including PTO, 401k Match at 5%, Profit Sharing, Company paid Life Insurance, Dental, Vision, STD/LTD, and two options under a national medical plan with employee contribution.
Responsibilities Include:
Providing support to design, develop, and maintain the client's systems compliance with ICD 503 requirements. This also includes advising and assisting the client with: security and network accreditations; providing the client with a working understanding of the latest networking communications and protocols, server technologies, application technologies, and security vulnerabilities, organizing and maintaining awareness of both physical and logical placement of network nodes within a network; identifying software components that fulfill mission requirements; and translating a network's technology requirements into usable solutions. Prepare and maintain documentation for specified networks that provide a reference for users to understand the established restrictions associated with those specific networks. Develop and maintain System Security Plans (SSP) to meet ongoing security requirements. Ensure approved SSPs are kept up to date as changes are made to the networks.
Implement security requirements and ensure compliance with the client's Information System Security Manager (ISSM) approved SSPs for all networks. This includes: establishing or utilizing existing access control mechanisms; defining and configuring the appropriate firewall settings; conducting intrusion detection and prevention; conducting vulnerability scanning; conducting anti-virus management; and conducting the necessary incidence response actions in accordance with client security policies.
Exercise robust network oversight that incorporates rigorous compliance, privacy and data security standards and achieves the following objectives:
• Secure network. High network availability.
• High functionality and usability.
• High network performance.
• Low infrastructure cost and risk.
• Complete record of ongoing network changes to include activity logging and auditing.
Required Experience and Qualifications:
- Active TS/SCI with Polygraph
- A Bachelor’s degree in Electrical, Electronic, or Computer Engineering, Information Technology, or a related field.
- A Master’s degree in a relevant field will meet the educational requirement in the event a bachelor’s degree is not in a relevant field.
- Equivalent experience for Bachelor of Science degree (Computer Science, IT, or equivalent technical discipline) can be substituted by four (4) years of experience in a relevant field in the respective discipline.
- A minimum of eight (8) years of experience providing support in the respective discipline.
- Candidate should have experience in several of the following areas:
- Securing mission systems through the ICD 503 process for security risk management, certification, and accreditation.
- Securing and monitoring Microsoft Windows desktop and server in a secure IT environment including one or more of Windows 7, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016.
- Securing and monitoring Linux & Microsoft Windows desktops, servers, and other devices.
- Securing and monitoring Macintosh devices.
- Applying Risk Management Framework controls to systems with successful authorization of those systems
- Use of system authorization workflow tools including advising on how to navigate those tools and assisting projects with steps needed to complete authorization
- Xacta® or Greenlight 360 compliance and risk assessment application tool
- Rapid7 scanning and vulnerability remediation
- NMAP scans
- Splunk Administration knowledge and skills
- Securing and monitoring enterprise level Cisco network, VOIP, and VTC devices
- Administering, securing and monitoring enterprise level Windows and Linux network infrastructures
Desired Experience and Qualifications:
- Certified Information Systems Security Professional (CISSP) Certification(s).
- Certified Splunk Administrator
*Click here to read more about how we protect your information