Systems Security Engineer (Cybersecurity Analyst)
Job Description
Bowhead is seeking a Systems Security Engineer (Cybersecurity Analyst) to support onsite operations in Dahlgren, VA. In this role, you will help identify and mitigate vulnerabilities across security systems by leveraging vulnerability scanning, hardening practices, and risk-focused analysis.
The position centers on evaluating security posture through vulnerability and configuration data, conducting application assessments, and troubleshooting cyber defense infrastructure anomalies. You will also produce risk/impact assessments and translate findings into insights that strengthen an organization’s risk management posture while applying cybersecurity and privacy principles tied to confidentiality, integrity, availability, authentication, and non-repudiation.
What you will do
- Run vulnerability scans and identify vulnerabilities across security systems.
- Use DoD network analysis tools to identify vulnerabilities (including ACAS and HBSS).
- Perform application vulnerability assessments.
- Identify systemic security issues based on vulnerability and configuration data.
- Provide meaningful insights tied to an organization’s threat environment to improve its risk management posture.
- Apply cybersecurity and privacy principles to organizational requirements, including confidentiality, integrity, availability, authentication, and non-repudiation.
- Troubleshoot and diagnose cyber defense infrastructure anomalies and work through resolution.
- Conduct impact and risk assessments.
Minimum qualifications
- Bachelor’s degree required.
- 5+ years of systems engineering experience.
- Knowledge of computer networking concepts and protocols, plus network security methodologies.
- Knowledge of network security architecture concepts, including topology, protocols, components, and defense-in-depth and zero trust principles.
- Knowledge of basic system, network, and OS hardening techniques.
- Knowledge of IDS/IPS tools and applications.
- Knowledge of network protocols including TCP/IP, Dynamic Host Configuration, DNS, and directory services.
- Knowledge of application vulnerabilities.
- Knowledge of system administration and operating system hardening techniques, including Unix/Linux, IOS, Android, and Windows.
- Skill conducting vulnerability scans and recognizing vulnerabilities in security systems.
- Skill using DoD network analysis tools to identify vulnerabilities (e.g., ACAS, HBSS).
- Skill applying system, network, and OS hardening techniques (for example: removing unnecessary services, password policies, network segmentation, enabling logging, and least privilege).
- Ability to conduct application vulnerability assessments and identify systemic security issues from vulnerability and configuration data.
- Ability to communicate threat-environment context and apply cybersecurity and privacy principles to organizational requirements.
- Ability to troubleshoot and diagnose cyber defense infrastructure anomalies and work through resolution.
- Skill in applying host/network access controls (for example, access control list) and understanding host/network access control mechanisms.
- Knowledge of network traffic analysis methods.
- Knowledge of VPN security, encryption, and VPN devices.
- Knowledge of transmission records (including Bluetooth, RFID, IR, Wi-Fi, paging, cellular, satellite dishes, and VoIP) and jamming techniques that enable transmission of undesirable information or prevent installed systems from operating correctly.
- Knowledge of network access, identity, and access management concepts including public key infrastructure, OAuth, OpenID, SAML, and SPML.
- Knowledge of system and application security threats and vulnerabilities (including buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, and return-oriented attacks).
- Knowledge of classes of attacks (such as passive, active, insider, close-in, and distribution attacks).
- Knowledge of application security risks.
Tools and technologies
- ACAS (Tenable Assured Compliance Assessment Solution)
- HBSS (Trellix Endpoint Security System / previously McAfee Host Based Security System)
- IDS, IPS
- TCP/IP, Dynamic Host Configuration, DNS
- Unix/Linux, IOS, Android, Windows
- VPN, encryption
- NIPS, anti-malware, spam filters
- Access control list, host/network access control mechanisms
- Transmission records and related concepts: Bluetooth, RFID, Infrared Networking, Wi-Fi, paging, cellular, satellite dishes, VoIP
- Public key infrastructure, OAuth, OpenID, SAML, SPML
Physical demands
- Must be able to lift 10-25 pounds or more.
- Must be able to stand and walk for prolonged amounts of time.
- Must be able to twist, bend, and squat periodically.
Security clearance
- Must currently hold a Top Secret security clearance.
- US Citizenship is required for Top Secret clearance at this location.
Salary
$140,000 - $150,000 per year, based on qualifications and experience.