Cyber Security Systems Engineer- Polygraph

Location
Herndon, VA
Posted
Mar 09, 2017
Closes
May 18, 2017
Industry
Engineering, Security
Hours
Full Time
 The candidate will serve as an Advanced Technical Assessor conducting contract security assessment of Sponsor's IT systems (to include but not limited to Accreditation & Authorization assessments, security requirements validation, and penetration testing). This position will support activities of the group to target, assess, exploit, and report risks and vulnerabilities of organization systems in order to provide senior decisionmakers with actionable data to make strategic investment decisions.


Roles and responsibilities include but are not limited to:


- Provide documentation to Sponsor which describes all identified system risks, planned test procedures taken, and test results.
- Provide enhancement capabilities and SOPs to assessment operations for execution and implementation.
- Maintain accountability to endure integrity and confidentiality of the process.
- Provide analysis of vulnerabilities identified by compliance tools.
- Review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.)
- Develop and document security evaluation test plan and procedures.
- Assist in researching, evaluating, and developing relevant Information Security policies and guidance.
- Actively participate in or lead technical exchange meetings and application review boards, documenting actions items/results of these events.
- Brief management, as needed, on the status of action items and/or results of activities.
- Assist in providing guidance on the population of required security documentation for both internal Sponsor documentation as well as RMP reciprocity documentation. RMF reciprocity documentation includes the Security Controls Traceability Matrix (SCTM), System Security Plan (SSP), Concept of Operations (CONOPS), System Security Plan Questionnaire (SSPQ), Continuous Monitoring Plan, and functional tests.
- Conduct hands-on security testing, analyze test results, document risk, and recommend countermeasures.
- Coordinate with other program elements conducting security testing.
- Assess/calculate risk based on threats, vulnerabilities, and shortfalls uncovered in testing and provide recommendations for risk decisions to Sponsor.
- Identify mitigating countermeasures to identified threats, vulnerabilities, and shortfalls.
- Review the implementation of cloud based security, including architecture, security controls, access roles and rules, and dataflow.
- Participate in joint test teams to complete security assessment and adjudication.

Education 1. Bachelors Degree in Computer Science, Engineering or a related technical discipline, or the equivalent combination of education, technical training, or work/military experience.

 2. Masters degree preferred.

Qualifications Required:

1. At least five (5) years of demonstrated on-the-job experience conducting scans with security risk detection and compliance tools, providing analysis of the results, suggesting mitigation plans for security problems.
2. At least five (5) years of demonstrated on-the-job experience performing cyber security analysis of network architectures and using network management tools.
3. At least five (5) years of demonstrated on-the-job experience creating systems and applications security test plans and performing hands-on security testing leveraging adversarial tactics.
4. At least five (5) years of demonstrated on-the-job experience with Linux, Windows, wireless, and virtual platforms.
5. At least five (5) years of demonstrated on-the-job experience with system configuration, development, and design specifically around enterprise systems and hypervisors.
6. At least five (5) years of demonstrated on-the-job experience with cloud based infrastructure as a service technologies.
7. At least five (5) years of demonstrated on-the-job experience with cloud based security controls (for example NACLs security groups) and auditing.

 

Desired:

 1. At least five (5) years of demonstrated on-the-job experience with system exploitation and cyber security engineering.
2. At least five (5) years of demonstrated on-the-job experience with mobile device security.
3. At least five (5) years of demonstrated on-the-job experience with information security policies and guidance, as well as, assisting in researching, evaluating, and developing relevant security policies and guidance.
4. At least five (5) years of demonstrated on-the-job experience technical knowledge across the entire OSI model.
5. Certification in cyber security or penetration testing disciplines.
6. (OSCP) Offensive Security Certified Professional Certification.
7. At least five (5) years of demonstrated on-the-job experience performing complex technical tasks in pursuit of overall goals with minimal direction.
8. At least five (5) years of demonstrated on-the-job experience to work multiple and competing priorities set by Sponsor's senior leadership.

 

15-20 years of related systems engineering experience.

  As a trusted systems integrator for more than 50 years, General Dynamics Information Technology provides information technology (IT), systems engineering, professional services and simulation and training to customers in the defense, federal civilian government, health, homeland security, intelligence, state and local government and commercial sectors.With approximately 32,000 professionals worldwide, the company delivers IT enterprise solutions, manages large-scale, mission-critical IT programs and provides mission support services.GDIT is an Equal Opportunity/Affirmative Action Employer - Minorities/Females/Protected Veterans/Individuals with Disabilities.