ApplyJob Type
Full-timeDescription
Overview:
We are looking for a DevOps Security Engineer, you will leverage your expertise in DevOps and cyber security operations for a Public Health Agency. We seek a specialist to assess security for a public facing website, identify potential vulnerabilities, and evaluate the effectiveness of mitigations and CI/CD pipelines. You are an expert at minimizing system risk, guiding the team toward effective, efficient technical solutions that reduce technical debt and long-term maintenance costs. You will work in close collaboration with the Senior Technical Lead in all aspects of the project.
You will help ensure federal security compliance and address security implementations, associated security documentation (e.g., security plan, POA&M), and coordinate relevant ATO approval requirements.
Responsibilities:
· Collaborate with ITAC ISSO and NIH/NHLBI security professionals to define and implement appropriate controls.· Ability to Develop Information Systems Security Plan, FIPS 199 Assessment, E-Authentication Risk Assessment, Privacy Impact Assessment (PIA), · Coordinate with ITAC Information Systems Security Officer (ISSO) and NIH/NHLBI information security professionals to define the most appropriate controls at the data source or along different data and application levels.· Ability to support security remediations and ensure that the systems are compliant with NIH and NHLBI security policies and procedures.· Knowledge of responding to Ad-Hoc Data Calls from ITAC Security Team· Ensure federal security compliance, document security plans, and coordinate Authority To Operate (ATO) approval requirements.· Support security remediations and ensure systems comply with NIH and NHLBI policies.· Respond to ad-hoc data requests from the ITAC Security team.· Support the Designated Approval Authority in obtaining ATO for Government systems.· Comply with M-22-18 for secure software development practices.· Utilize CI/CD tools like Jenkins as part of ITAC’s DevOps practices.Requirements
Required:
· Experience with CI/CD Tools like Jenkins as part of DevOps practices· Experience with ATO request submissions and RMF processes.· Knowledge of NIST 800-53 and CNSSI 1253 RMF Analysis, Authorization, and Assessment (A&A).· Public Trust Clearance· Bachelor's degree
Preferred:
· Knowledge or administration of CI/CD pipelines using Jenkins, Docker, GitHub, or similar· Possession of excellent interpersonal and team-oriented skills· Possession of excellent client service and critical thinking skills· Possession of excellent oral and written communication skills
Clearance:
· Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required.