Information Security Systems Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

By Light Professional IT Services ยท 21 hours ago

Information Security Systems Engineer

By Light Professional IT Services is a company that supports defense, civilian, and commercial IT customers worldwide. The Information Security Systems Engineer will conduct information system security engineering activities to ensure cybersecurity and compliance with government requirements, while also defining security requirements and implementing security designs.

GovernmentInformation ServicesInformation Technology
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Defines information security requirements and their integration into information systems and its technology component through purposeful security design
Develop and implement security designs ensurse the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM)
Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies
Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects
Develops Security Test Procedure (STP), conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs
Conducts risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborating with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed
Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements
Participates in Agile Planning Events to provide technical input
Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering
Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions
Perform other duties as assigned

Qualification

Information Security EngineeringNIST Risk Management FrameworkDISA STIG ImplementationSecurity Information MonitoringLinux AdministrationWindows Server AdministrationVulnerability AnalysisScriptingProblem SolvingTeam Collaboration

Required

5+ years of information security experience as a contractor in the DoD and IC community
Demonstrated experience in Linux, Windows Server, and/or Networking Appliances
Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
Demonstrated experience performing Systems Security tasks including Security Information and Event Monitoring, Endpoint Security, and Compliance and vulnerability scanning
Demonstrated experience with creating and validating evidence for NIST security controls
Bachelor's degree in a technical field or relevant experience
DoD 8570 IAT Level III certification or ability to achieve certification within 6 months of start of employment
Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems
Possess a working knowledge of administrating servers, system and application security threats and vulnerabilities
Experience extending existing applications in areas such as security, monitoring, task automation, continuous integration, deployment, and performance optimization
Scripting in a Linux or Windows environment to support the various Cyber Security tools and applications required
Experience providing guidance on vulnerability and malware remediation
Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future
U.S. Citizenship status and a TS/SCI security clearance and ability to successfully pass a CI polygraph if requested by customer

Benefits

Medical, Dental & Vision Coverage
Wellness Program
401(k) Matching
Employee Assistance Program
Life Insurance
Education & Training
Generous Leave Policy (11 Federal Holidays, PTO, Military Leave, Bereavement and Jury Duty)

Company

By Light Professional IT Services

twittertwittertwitter
company-logo
BY LIGHT Professional IT Services is a provider of IT, cloud, cyber and infrastructure solutions to the US Federal Government.

Funding

Current Stage
Late Stage
Total Funding
unknown
2017-05-31Acquired

Leadership Team

leader-logo
Bob Donahue
CEO By Light
linkedin
leader-logo
Mike Bowser
Chief Operating Officer
linkedin
Company data provided by crunchbase