CybersecurityJobs.io
← Back to all jobs

Job Description

Focus: Information system security engineering across the lifecycle, integrating security requirements into organizational and upgraded information systems while supporting Collateral, SCI, and Special Access Program (SAP) activities.

Responsibilities

  • Oversee development, implementation, and evaluation of information system security program policy, with special emphasis on integration of existing SAP network infrastructures
  • Conduct network security analysis using the Risk Management Framework (RMF), emphasizing the JSIG authorization process
  • Provide expert support, research, and analysis for exceptionally complex information security problems and associated processes
  • Deliver expert consultation and technical services across all aspects of information security
  • Serve as a technical expert to the Cybersecurity Assessment Program, providing technical direction, interpretation, and alternatives for complex issues
  • Build IA into systems deployed to operational environments
  • Support architects and system developers in identifying and implementing appropriate security functionality to ensure consistent application of DoD and other agency security policy and enterprise solutions
  • Enforce trusted relationships among external systems and architectures
  • Assess and mitigate system security threats and risks throughout the program lifecycle
  • Contribute to security planning, assessment, risk analysis, risk management, certification, and awareness activities for system and networking operations
  • Independently apply advanced technical principles, theories, and concepts with strong written and oral communication
  • Contribute to development of new principles, concepts, and methodologies
  • Work on unusually complex technical problems and provide innovative solutions
  • Recommend cybersecurity software tools; help develop tool requirements and selection criteria, including development of product-specific STIGs from applicable DISA SRGs
  • Review ISSE-related designs and provide security compliance recommendations
  • Lead technical teams in implementation of predetermined long-range goals and objectives
  • Support customer and SAP community IA working groups and participate in SSE IPT reviews
  • Provide IA risk management recommendations to the customer
  • Provide ISSE support for Mission and Training systems design and development
  • Assist with development and maintenance of the Program Protection Plan
  • Support site activation activities and design reviews
  • Represent the customer in ISSE-related working groups, advisory groups, and advisory council meetings
  • Chair or co-chair customer and SAP community IA working groups and participate in ISSE IPT reviews
  • Provide ISSE support as part of a security incident response team as needed
  • Maintain operational O&M checklists (daily, weekly, monthly, yearly) and develop associated TTPs and SOPs
  • Integrate COTS and GOTS products to collect, display, and remediate automated system security and operations/performance metrics
  • Integrate and tailor monitoring capabilities with enterprise SIEM, including creating complex event alarms/rules and summary reports
  • Write and execute cybersecurity test procedures for validation of control compliance
  • Monitor and analyze cybersecurity tool output for reportable security incidents and residual risk
  • Analyze technical risk of emerging cybersecurity tools and processes
  • Develop improvements to the accuracy and efficiency of security assessments
  • Integrate JSIG/RMF Continuous Monitoring tools and processes
  • Lead teams of System Security Engineers and Cybersecurity Analysts to protect national and international security interests during support equipment design and testing
  • Maintain relationship with System Engineer (SE) teams and enforce trusted relations among external systems and architectures
  • Assess and mitigate security threats/risks across the program lifecycle and contribute to certification and awareness activities for system and networking operations

Requirements

  • 12+ years related experience (REQ notes: 10+ years may vary based on training/certifications/degree)
  • 2+ years SAP experience required
  • Prior performance in roles such as ISSO, ISSM, SCA, or SAP IT Technical Director
  • Bachelor’s degree in related discipline OR Associate’s degree in a related area + 2 years experience OR equivalent experience (4 years)
  • IAAΕ Level I or Level II required within 6 months of date of hire (CASP+ CE, CISSP (or Associate), CSSLP)
  • Top Secret/SCI clearance required
  • Must be able to attain TS/SCI with CI Polygraph
  • U.S. Citizenship required
  • Certifications listed as applicable options: CSSLP (ISC)2; CASP CE+ (CompTIA); CASP+CE (CompTIA)

Technologies

  • Information Security, Information Security Management, Information System Security
  • Risk Management Framework (RMF), Joint Special Access Program Implementation Guide (JSIG)
  • Cybersecurity Assessment Program, Continuous Monitoring
  • DISA SRGs, STIGs, COTS, GOTS
  • SIEM, Logrhythm
  • Operations and Maintenance (O&M) checklists, Tactics, Techniques and Processes (TTPs), Standard Operating Processes (SOPs)
  • Microsoft Windows Server, Active Directory, Group Policy management
  • Red Hat Enterprise Linux, MS Hyper-V, VMWare, ESx, Xen hypervisors
  • Enterprise networking, firewalls, intrusion detection, intrusion prevention systems
  • Forensic analysis, vulnerability assessment
  • Configuration, Scripting, BMC Footprints, WSUS, Lumension, Bitlocker
  • SQL Server 2012, TomCat, IIS, Windows Server 2012r2/2016, Windows 10, Red Hat 6.5
  • ACAS/Nessus/SCAP
  • Mandatory/role-based access control concepts (SE Linux extensions to RHEL, PitBull, AppArmor, Sentris)
  • Video teleconferencing/VOIP
  • Oracle/MS SQL database security
  • Apache/IIS Web server security
  • Patch/Configuration management, DevOps, tier 3 support

Location: Colorado Springs, CO (onsite)

Travel: 10% to 25%

Clearance Level: Top Secret/SCI

Requisition #: RQ230157

Category: Cyber and IT Risk Management

Salary: USD 166,005 - 224,595 per year (may vary based on experience, geographic location, and contractual requirements)

Similar Jobs