Job Summary:
We here at Apriva ISS have the need for an Information Systems Security Engineer to support our customer located in Quantico, VA. This is a full-time, 100% on-site role, with the potential for limited travel as needed. This role will assist in supporting our existing Network & Systems Engineers in maintaining & implementing security controls within a CSfC Gateway solution. This role will be customer facing and embedded within the Client’s secure location, so a professional approach to troubleshooting, operational security, and incident response is paramount.
This is a multi-vendor & customer integrated solution, where functionality of the solution does have interdependencies with the customer’s enterprise services, so the ability to work successfully between a wide range of technical staff is expected. The ISSE will support the leadership team in vulnerability scanning, risk assessments, reporting, and evaluating the security of systems integrations.
Primary Duties/Responsibilities:
- Assist On-site and remote Infrastructure Engineering staff with systems security hardening efforts.
- Conduct vulnerability assessments, support incident handling, and advocate for future security needs.
- Support the organizational and customer to meet both internally and governmentally defined security postures for the purpose of achieving and maintaining ATO and successful registration and accreditation of an NSA Commercial Solutions for Classified (CSfC) Gateway solution.
- Assist in assessing security risks and developing mitigation strategies for the information systems and solution infrastructure.
- Support the program leadership team in designing, development, and implementation of configuration management controls and mechanisms.
- Support the creation of documentation such as: Systems Security Plans, Risk Assessment Reports, Incident Response Plans, and Systems Accreditation & Certifications packages.
Required Qualifications/Skills:
- A Bachelor’s degree in Cybersecurity, Data Science, Information Systems, or equivalent related technical experience is required.
- 3 – 5 Years of experience in Cybersecurity, Network Security, Security Engineering required.
- An active Federal TOP SECRET Security Clearance with SCI eligibility, and ability to take and pass CI Polygraph is required.
- Current Active DoD 8140 Information Assurance Qualifying Cyber Security Certification (Sec+, CySA+, SSCP, etc.) or ability to obtain within 6 months of employment is required.
- Direct hands-on experience with vulnerability scanning tools, assessments, and remediation is required.
- Direct experience in ensuring compliance with the NIST Risk Management Framework (RMF) 800-37 Rev 2 & 800-50 Rev 5 for support of the customers Assessment & Authorization (A&A) process and lifecycle is required.
- A solid knowledge base on: Identity & Access Management practices, Public Key Infrastructure, network & security architecture, and continuous monitoring tools is required.
- Excellent communication (both written and verbal) and organizational skills are required.
Preferred Qualifications/Skills:
- Additional Professional Cybersecurity or IT Security certification such as: CISA, CCNP Security, GCED, AWS/Azure Security, etc. are a plus.
- Previous experience or knowledge of the National Security Agency’s (NSA) CSfC program, requirements, constraints, and architectures is a plus.
- Working hands-on experience with IDS/IPS solutions, ACAS Scanning (Nessus), Trellix ePO, & Splunk are a plus.
- A working knowledge or previous experience with encryption and cryptography is a plus.
- Knowledge of previous hands-on experience supporting PKI and certificate-based authentication, Zero-Trust architectures, and multi-factor authentication is a plus.
PHYSICAL DEMANDS:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.Individuals may need to sit or stand as needed for long periods of time throughout the day. The candidate must be able to lift 50 pounds.
WORK ENVIRONMENT:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.For a large percentage of the work week, it will be ambient room temperatures, lighting and traditional office equipment as found in a typical business office environment. There is also work in a typical data center environment.
APRIVA IS AN AFFIRMATIVE ACTION/EQUAL OPPORTUNITY EMPLOYER
[