Information Security Systems Engineer with TS/SCI Clearance
7 days left
- Full Time
Performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction. 1. Performs Computer Security Incident Response activities for a large organization, coordinates with other government agencies to record and report incidents. 2. Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation. 3. Recognizes potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information. 4. Evaluate firewall change requests and assess organizational risk. 5. Communicates alerts to agencies regarding intrusions and compromises to their network infrastructure, applications and operating systems. 6. Assists with implementation of counter-measures or mitigating controls. 7. Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices. 8. Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance. 9. Prepares incident reports of analysis methodology and results. 10. Provides guidance and work leadership to less-experienced technical staff members, and may have supervisory responsibilities. 11. May serve as a technical team or task leader. 12. Maintains current knowledge of relevant technology as assigned. 13. Participates in special projects as required. Position Responsibilities: The New Campus East (NCE) Active IT Program was established to provide infrastructure services for a new data center facility. We are seeking a candidate to support the AIT Information Assurance Team in ensuring all AIT systems are accredited and authorized in accordance with NCE OCIO policies and procedures. Position Summary: Candidate will represent AIT Information Assurance team as Information System Security Representative who provides recommendations and ensures compliance with IS security procedures for all AIT systems.
- Complete ITDR plans for approximately 180 AIT systems. Coordinate with Engineers to obtain correct information to complete the ITDR plan within NCE requirements. Coordinate with Engineers to complete ITDR tabletops and after action reports.
- Engage in Engineering Change Proposal meetings with AIT Engineers and AIT Business Office teams to ensure that security is being addressed when developing new AIT systems.
- Collaborate with OCIO regarding any system changes that could introduce potential security vulnerabilities into our environment to decide the best course of action to proceed in order to both meet our customer's mission by keeping systems operational as well as meeting all security policies and procedures.
- Manage security packages for approximately 180 AIT systems as they proceed through the certification and accreditation (or authorization and accreditation) process using XACTA as the documentation repository to maintain all relevant documents with OCIO.
- Provide security control analysis using a Security Control Traceability Matrix as required by DNI ICD 503, CNSS, NIST special publications, FISMA, FIPS, OMB, etc. of all AIT managed national security systems during the accreditation process by performing documentation review (system CONOPS, network diagrams, NCE and OCIO policies), interviewing key organizational personnel, and presenting the findings in XACTA for OCIO review and authorization.
- Compose Body of Evidence require documentation (system security plans, security categorizations, risk assessments, network diagrams, business impact analysis, etc.)
- 2-4 years with DoD certification & accreditation processes
- 2-4 years with DOD ITDR, tabletops, Coop, BCP planning
- 2-4 years developing and reviewing System Security Plans, Risk Assessment Reports, ST&E (SCTM) Reports, Contingency Plans, Disaster Recovery Plans, Privacy Impact Assessments, IT Security procedures, and other supporting documentation
- Certified Information System Security Professional (CISSP), Security+ certification or other DoD 8570.1 Level I or II certification(s)
- Ability to update and deliver on all DoD IA documentation
- Ability to conduct audits on systems controls to determine if standards and annual procedures are being performed according to standards
- Advanced knowledge of systems engineering principles, methods, and techniques
- Ability to interface with the customer on a consistent basis and exercise sound judgment and problem solving.
- Candidate must possess IAM I or II certification to start in accordance with DOD 8570.1M. This position is defined as in 8570.1M chapter 4, pg 35. Candidate is required to understand how our customer's DCID 6/3 and ICD 503 process work and how systems security requirements will be met.
- Knowledge of and experience with DCID 6/3 and ICD 503 and the customer's security requirements is desirable; supporting systems going through the system accreditation process. Experience with completing ITDR plans and ITDR tabletops' is required.
- Must have ability to support core hours in support of our customers.
- Basic understanding of Windows Enterprise AD architecture and VMWare Virtualization
- CISSP, Security+ certification or equivalent (CAP, GSLC, CISM)
- Active TS/SCI clearance required.