Cyber Security InfoSec Engineer $215,000.00

Mclean, VA
Oct 27, 2021
Oct 29, 2021
Full Time
Position Requires a Top Secret (TS/SCI) Clearance with a Polygraph. The Contractor shall provide for the tasks documented in this narrative on a best effort, Level of Effort (LOE) basis with the number of FTEs listed under labor categories. The hours shall be managed at the overall JITR level. The customer is responsible for providing IT services that range from applications and cloud services, Close Support, Enterprise Audit, Enterprise Monitoring, to video and mobile phone services. The customer requires Cyber Security support to manage IT applications and systems through the customer's IT Security Assessment and Accreditation (A&A) process and provide support to the tenants within the customer's site and several exterior facilities. The Contractor shall coordinate, gather, and document cyber security requirements with mission partners, service providers and security counterparts. The Contactor shall coordinate and facilitate technical exchange meetings to determine customer needs and consult with customers to clarify and validate complex requests. The Contractor shall gather requirements or information from customer resources in support of task completion. The Contractor shall manage internal and external customer expectations. The Contractor shall implement the Risk Management Framework (RMF) process for customer and the customer Partner's IT systems. The Contractor shall manage the IT Security Assessment & Authorization (A&A) process for customer and the customer Partner's IT systems. The Contractor shall process customer systems through the RMF and A&A process. The Contractor shall conduct comprehensive assessments of the management, operational, and technical security controls employed within or inherited by an information system. The Contractor shall determine the overall effectiveness of security controls for information systems and applications. The Contractor shall determine the extent to which the security controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for applications and systems. The Contractor shall provide assessments of the severity of weaknesses or deficiencies discovered in designated information systems and their environments of operation. The Contractor shall recommend corrective actions to address identified vulnerabilities. The Contractor shall assist in the development of system security documentation. The Contractor shall assist in auditing of operational systems. The Contractor shall play an active role in the monitoring of systems and their environments of operation. The Contractor shall develop and update security plans. The Contractor shall manage and control changes to systems. The Contractor shall assess the security impact of system changes. The Contractor shall provide forensic support for root-cause determination of security related issues. The Contractor shall capture auditable events in applications and infrastructures. The Contractor shall aggregate auditable events into one system for transfer to the customer Enterprise Audit team for analysis. The Contractor shall produce data to support compliance verification. The Contractor shall provide recommendations in support of the design and implementation of User Activity Monitoring (UAM) tools. The Contractor shall coordinate System Requirements Documents (SRDs) with governance oversight and management for review. The Contractor shall determine support for engineering, development and implementation. The Contractor shall coordinate and interface daily with stakeholders to identify and aid in the resolution of Cyber Security related issues. The Contractor shall process, track, and report on all Cyber Security tasking utilizing customer tools such as XACTA, customer's Help Desk Suite, ServiceNow, Primavera and JIRA. The Contractor shall create and brief required status reports and metrics reports and keep senior management apprised of status. The Contractor shall travel to attend technical exchange meetings or reviews. The Contractor shall provide coverage during customer office hours, Monday - Friday from 7:00am to 4:00pm. Estimated Salary: Position Level: All Levels Salary Range: Up to $215,000.00 per year B4Corp Estimated Salary Ranges: Position Level Min Salary Max Salary Level 1 - Subject Matter Expert $160,000 $215,000 Level 2 - Expert $140,000 $195,000 Level 3 - Senior $110,000 $170,000 Level 4 - Full Performance $60,000 $100,000 Mandatory Requirements: Demonstrated experience as an Information System Security Engineer or Information Systems Security Manager. Demonstrated experience with Risk Management Framework (RMF) Demonstrated experience analyzing security scans. Demonstrated experience reviewing RMF controls Demonstrated experience evaluating plans of action and milestones (POAMs) and determining if POAM body of evidence is acceptable. Demonstrated experience with security scanning tools providing malicious code detection or intrusion detection. Demonstrated experience interpreting the output from security tools such as Burp, HP WebInspect, AppDetective, Rapid 7, or Nessus for compliance and vulnerability concerns. . Demonstrated experience with XACTA or XACTA 360. Demonstrated experience developing and engineering information systems architectures. Demonstrated experience developing and implementing security for information systems. Demonstrated experience with information systems project integration. REQUIRED Certification: Certified Information Systems Security Professional (CISSP) Certification or equivalent level III certification. (list certification name and year obtained). Optional Requirements: Demonstrated experience with customer's A&A process, to include writing or reviewing required documentation. Demonstrated experience with manual auditing procedures associated with Amazon Web Services (AWS). Demonstrated experience performing network and firewall administration. Demonstrated experience performing patching and misconfiguration checks. Demonstrated experience with Confluence. Demonstrated experience mapping Active Directory and Public Key Infrastructure (PKI) group and membership accesses. Demonstrated experience in Lean Agile and DevOps Factory environments. Demonstrated experience setting up auditing services on Linux, Windows. Demonstrated experience monitoring privileged user actions and activities. Demonstrated experience with Splunk to aggregate the data collected in the auditing process. Demonstrated experience with system engineering and system development. Desired Certification: Certified in Risk and Information Security Controls (CRISC). Desired Certification: Completion of the customer's system administrator security course. B4CORP Company Information B4Corp is a small defense contracting company that focuses on providing an optimum environment for mission-focused, highly-skilled consultants to support the United States of America's intelligence community and other defense organizations. B4Corp provides a low overhead, highly efficient, high salary environment that allows employees to excel at meeting the client's needs. B4Corp is looking for information technology professionals that have a high sense of personal responsibility, self-motivation, and mission drive. B4Corp's dedication and care for its employees is reflected in the outstanding compensation and benefits B4Corp provides. Our salaries are second to none. B4Corp's benefits reflect the company's policy of putting the employees first. Our health insurance demonstrates this with 100% employer coverage and providing employees with a plan that has $0 copay, 0% coinsurance and an HSA that can allow employees to accrue health savings for the future. B4Corp's maximum flexibility comp / makeup time policy, along with the company's cafeteria-style benefit plan that allows employees to maximize their benefit dollars, reflects B4Corp's commitment to its employees. Compensation: Outstanding Salaries Retirement: Full Vanguard 401k Plan - Featuring a full scope of investment options - 100% employer matched contribution up to 6% of employee's salary - Ability to max out 401k savings $57k ($63.5k if over 50) Employees receive B4Corp phantom stock each year (2-year vesting period) Insurance 100% Employer-Paid Premiums: United Health Care Choice Plus HSA POS Gold 1500 w/HSA - Employer funded HSA to cover 100% health care deductible - Health insurance: $0 copay, $0 co-insurance. Full scope protection for you and your family! - 100% employer premium coverage for single and family Health Equity HSA - B4Corp contributes $1500.00 for single and $3000.00 for family into your Health Equity HSA to cover 100% of your health care deductible. Mutual of Omaha Dental VSP Vision Insurance Mutual of Omaha short-term disability (60% of salary up to $2,000.00/week) Mutual of Omaha long-term disability (60% of salary up to $10,000.00/month) Mutual of Omaha life insurance ($200,000.00) Employee Referral Bonus: Refer a friend or a coworker and receive $2,000 per year for every year the person works for B4CORP Paid Time Off (PTO): Seven weeks of leave per year (including ten federal holidays) Ability to purchase 2 additional weeks of vacation Flexible work schedule with comp time (with customer approval) Tuition and Training: Free CBTNuggets Online Training Account - More than 200 online IT courses on a large variety of topics, including networking, security, virtualization, and the cloud - from trusted vendors such as Cisco, Microsoft, and Google. - Train anytime, anywhere, and on a variety of devices - even offline! - Transcender(R) Practice Exams - Virtual Labs Free L inux Academy Online Training Account Internal Tracking -PJ1917