Cybersecurity Engineer – ISSE

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 51-200Since 2003Company SiteLinkedIn

Location

Virginia

Posted

6 days ago

Salary

Not specified

Seniority

Senior

Bachelor Degree5 yrs expEnglishCloudCyber SecurityTypeScript

Job Description

• Provide Cybersecurity Engineering and Risk Management Framework (RMF) support for The United States Air Force (USAF) Life Cycle Management Center (AFLCMC) Engineering Directorate (AFLCMC/EN-EZ) Cyber Systems Engineering Division (AFLCMC/EZH). • Provide state-of-the-art technical support for the acquisition of cloud Development Security Operations (DevSecOps) boundary systems within AFLCMC. • Play a critical role in supporting the RMF Assessment and Authorization (A&A) processes for AFLCMC/EN-EZ. • Responsible for the technical implementation of the RMF. • Conduct cybersecurity and risk assessments on networks, systems and applications to identify and mitigate technical and non-technical vulnerabilities. • Handle multiple RMF authorization types, including baseline changes, use cases, Assessment Summary Results (ASR), Authorization to Operate (ATO), CAR, Denial of Authorization to Operate (DATO) & HRR/HR. • Conduct vulnerability assessment and analysis utilizing standard technologies, such as Security Content Automation Protocols (SCAPs), Assured Compliance Assessment Solution (ACAS)/NESSUS scans and DISA Security Technical Implementation Guides (STIGs)/ Security Requirements Guides (SRGs). • Conduct security assessments and create RMF documentation, including Security Assessment Plans (SAPs), eMASS Security Risk Assessment (SARs), Special Access Programs (SAPs) Executive Summary, SAPs Body of Evidence (BOE). • Provide accurate assessments and document security posture, capabilities and vulnerabilities. • Lead the creation of the SAPs and SARs and convey technical findings and risk assessments. • Perform detailed risk analysis, identify system vulnerabilities and provide comprehensive recommendations for risk mitigation. • Verify, validate and document risk, perform Security Control Assessments (SCAs) and document compliant and failed security controls in eMASS. • Assess STIGs and SRGs. • Ensure traceability of all vulnerabilities from raw assessment results to the Plan of Action and Milestones (POA&Ms). • Support the Continuous Security Monitoring (CSM) program as necessary.

Job Requirements

  • Must possess a TS/SCI level security clearance; or a Top Secret with SCI eligibility will be considered.
  • Security+ CE is required, CISSP is desired.
  • Cloud certification is desired.
  • Bachelor’s degree in Information Technology or related field or business-related field
  • Desired: Advanced degree in Information Technology or related field or business or related field
  • Minimum of 5-7 years of experience in cybersecurity risk assessment and supporting RMF A&A processes for DoD and Navy systems.
  • Hands-on experience conducting vulnerability assessment and analysis utilizing standard technologies, such as SCAPs, ACAS/NESSUS scans and DISA STIGs/SRGs.
  • Experience developing mitigations and writing mitigation statements for ongoing vulnerabilities.
  • Experience using eMASS.
  • Experience working in Navy environments.
  • Experience with wireless networks technology.
  • Experience with Visio required.
  • Ability to author and maintain policy documents in support of RMF and Vulnerability Management.
  • Substantive knowledge of NIST RMF.
  • Good working knowledge of Windows and RHEL OS, layer 2 and 3 network devices and supporting infrastructure.
  • Analytical skills to troubleshoot high-level, complex, technical problems.
  • Employ strong written and verbal communication skills to advise various levels of technology stakeholders, program initiatives and accrediting authorities on security requirements and cybersecurity trends and solutions, to include risk assessments and mitigations.

Benefits

  • Competitive salary
  • Comprehensive benefits
  • Company that cares

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 501-1,000Since 2018

Security Engineer focused on application security at Neko Health

United States
Speed logo

Sales Director – Government Defense & Security

Speed

A Bitcoin & Stablecoin Company - Buy, Sell, Accept & Payout easily !

OtherRemoteTeam 11-50

Sales Director driving revenue growth for US federal government clients

Washington
$132K - $185K / year
OtherRemoteTeam 11-50Since 2020H1B No Sponsor

Chief Compliance Officer / Chief Information Security Officer leading compliance at LendSwift

United States
World Wide Technology Healthcare Solutions logo

Cloud Security Architect

World Wide Technology Healthcare Solutions

Founded in 1990, World Wide Technology (WWT) is a global systems integrator with $13.4 billion in annual revenue that provides digital strategy, innovative technology and supply chain solutions to large public and private organizations.

OtherRemoteSince 1990H1B No Sponsor

WWT is seeking strategic and hands-on Cloud Security Architect to drive cloud security posture, and operational efficiency across our cloud environments. Conducts risk assessment and provides recommendations for application design for cloud based solutions. Analyzes and defines s...

United States
$100K - $112K / year