Information Systems Security Engineer
Job Description
Benefits package includes medical, dental, and vision coverage, TRICARE Supplemental, and Critical Illness insurance. You’ll also receive company-paid life and short-term disability, with optional long-term disability, paid leave, and a 401(k) retirement plan. Additional support includes identity theft protection, employee discounts, and wellness seminars.
Work is primarily onsite in Arlington, VA supporting the National Military Command Center (NMCC) customer, with ad-hoc telework when authorized.
Scope of work
The Information Systems Security Engineer supports the NMCC customer by providing cybersecurity and security engineering services, including system security engineering, cybersecurity risk assessments, and security architecture support. The role performs or reviews technical security assessments of computing environments to identify vulnerabilities and non-compliance with established cybersecurity standards and regulations, then recommends mitigation strategies.
Responsibilities
- Design, implement, and maintain complex information technology systems, including computing infrastructure, networking rules for cybersecurity, and troubleshooting of network errors and other technical issues.
- Lead technical solution development from customer requirement refinement through design, build, testing, and deployment.
- Document and communicate technical solutions and analysis results to support recommended courses of action.
- Build, deploy, and patch HBSS Windows and ACAS Red Hat Linux 7.9 and 8 servers.
- Build, maintain, and patch ePO, Security Center, and Nessus servers.
- Provide Security Center accounts for Vulnerability Managers to scan devices within ACAS.
- Review ACAS scan results and support remediation of identified vulnerability findings.
- Support licensing processes for HBSS ePO and Tenable Security Centers.
- Support acquisition of HBSS and ACAS kickstart ISOs from DISA.
- Build virtual servers and deploy and patch applicable McAfee modules through ePO.
- Configure McAfee policies and implement STIG requirements for HBSS Windows operating systems, McAfee policies, and ACAS RHEL servers.
- Run SCAP scans on Windows and RHEL servers.
- Update Red Hat 7.9 and 8 RPMs as released and establish Red Hat YUM local RPM repositories to patch offline ACAS servers.
- Deploy rogue sensors on applicable subnets and identify rogue subnets and endpoints.
- Troubleshoot Security Center and Nessus scanner issues.
- Adhere to company policies, procedures, and safety regulations; perform other duties as assigned.
Required qualifications
- Bachelor’s degree in computer science, information technology, or a related field, plus five or more years of systems engineering experience.
- Master’s degree in computer science, information technology, or a related field and three years of related experience may be substituted.
- In lieu of a degree, 12 years of intensive and progressive experience demonstrating the required proficiency levels may be considered.
- At least five or more years of systems engineering experience, including design and architecture.
- Demonstrated ability to identify security risks across information system network structures, including operating systems, hardware, and data-transfer protocols.
- Must currently possess and maintain an active DoD Top Secret / TS/SCI security clearance, as required for the position.
- Must be able to maintain ability to access the government worksite.
- Must possess and maintain a valid state driver’s license and a safe driving record, per company policy, to operate vehicles or equipment as required.
- Current CompTIA Security+ certification.
Technical skills and competencies
- Knowledge and experience with ACAS scan results and vulnerability remediation.
- Experience building, deploying, maintaining, and patching HBSS Windows and ACAS Red Hat Linux servers.
- Experience building, maintaining, and patching ePO, Security Center, and Nessus servers.
- Knowledge of HBSS/ePO, Tenable Security Center, DISA kickstart ISOs, and applicable licensing processes.
- Experience implementing STIG requirements for Windows and RHEL servers and applicable security policies.
- Experience running SCAP scans on Windows and RHEL servers.
- Knowledge of Red Hat RPM updates and local YUM repositories used to patch offline ACAS servers.
- Ability to deploy rogue sensors and identify rogue subnets and endpoints.
- Ability to troubleshoot Security Center and Nessus scanner issues.
- Effective communication and presentation skills in formal and informal settings.
- Strong planning, organizational, and time-management skills.
- Demonstrated initiative and ability to work independently.
Work environment and physical demands
- May require extended periods of sitting and screen time while performing systems engineering, cybersecurity, system administration, and technical analysis.
- Primarily onsite in an office or secure information technology environment at the National Military Command Center (NMCC), with ad-hoc telework as authorized.
- Must be able to operate standard office and computer equipment and perform work requiring close attention to technical details for extended periods.
- Must be able to support mission requirements and adjusted work schedules when necessary.
- Must maintain compliance with all government security, cybersecurity, and worksite access requirements.
Pre-employment screening
- Candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and a 5-panel drug screening, in accordance with company policy and applicable laws.
Reasonable accommodation
If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, notify the designated recruiter so appropriate assistance can be provided.