Overview
The Information Systems Security Engineer (ISSE) is the security SME responsible for supporting Development, Engineering and Operations infrastructure solutions and strategic adherence to all aspects of the Information Assurance (IA) program as stipulated by various U.S. Government requirements. The successful candidate must:
- Prepare security test and evaluation plans.
- Provide certification and accreditation support in the development of security and contingency plans and conducts complex risk and vulnerability assessments.
- Analyze policies and procedures against Federal laws and regulations and provides recommendations for closing gaps.
- Recommend system enhancements to improve security deficiencies. Develops, tests, and integrates computer and network security tools.
- Secure system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration.
- Conduct security program audits and develops solutions to lessen identified risks.
- Provide information assurance support for the development and implementation of security architectures to meet new and evolving security requirements.
- Perform vulnerability assessments including development of risk mitigation strategies.
- Prepare systems Assessment and Authorization (A&A) documents and procedures. Interface with other IA team members, other security disciplines (industrial security, physical security, special programs security, etc.), program personnel, and Government security representatives.
Responsibilities
- Leverage SME level knowledge of Risk Management Framework and manage systems through the full Lifecyle of RMF
- Communicate system complexities with Assessors and ISSMs
- Initiate vulnerability and compliance scan
- Manage rick/threat mitigation/remediation
- Tailor systems A&A documents to unique environments and requirements
- Successfully work through POAMs with Developers, Engineers, and various groups
- Conduct the full spectrum system Continuous Monitoring
- Conduct various roles and responsibilities in Cloud computing environment
- Ensure the system security documentation, is developed, maintained, reviewed, and updated on a continuous basis
Qualifications
- Bachelors and 8+ years of experience OR Masters and 6+ years of experience OR PhD and 3+ years of experience; an additional four years of experience may be considered in lieu of degree
- High level of skills and knowledge with Risk Management Framework and Assessment and Authorization processes and related policies
- Experience with using Splunk, Rapid7, and other monitoring and auditing systems or software
- Exceptional written and verbal communication skills
- Familiarity with cloud computing and related security concepts
- Working knowledge of digital communications and related IT communications technologies
- Direct experience with patch management, continuous monitoring, and vulnerability scanning/remediation activities
- Proactive and forward leaning
All candidates must have a TS/SCI clearance with a Full-Scope Polygraph.
Eleccion provides a competitive, comprehensive benefits package for all our employees.