Information System Security Engineer (ISSE), Envisioneering, Washington, DC


Envisioneering -
N/A
Washington, DC, US
N/A

Information System Security Engineer (ISSE)

Job description

Envisioneering,Inc. is seekinganInformationSystemsSecurityEngineer(ISSE) to support an active government contract. Thisposition will beresponsiblefor the following:

Summary ISSE Responsibilities:

  • Overseethe development and maintenance of a system s cybersecurity solutions.
  • Identify AO andSCAcognizance(i.e.FAOorNAO, and FSCAor SCA) of the systemas well as any specific authorization requirementssuch as reciprocity,crossdomain, and applicable overlays to supportSystem Categorization.
  • Identify mission criticality.
  • Identify and tailor the security control baseline with applicable overlays.
  • Assist with development, maintenance, and tracking of theSP.
  • Leadthe security control implementation and testing efforts.
  • Perform vulnerability-level risk assessment on the POA&M/RISK Assessment Worksheet.
  • Assist with any security testing required as partof A&A or annual reviews.
  • Assist in the mitigation and closure of open vulnerabilities under the system s change control process.
  • Overseecybersecurity testing to assess securitycontrols and recording security controlcompliancestatusduring the continuous monitoring phase of the lifecycle.
  • Make data entries into the eMASS record and POA&M consistent with implementation results.
  • Utilize the Collaboration Board in the eMASS workflow for all formal coordination duringthe RMF process.Detailedfindings will beposted in the Artifacts tab(ifnecessary).
  • Rework shallbedocumented and provided to the PSO/PMOfor review.

Assist the ISSM/ISSO withthefollowingresponsibilities:

  • Leadthe RMF processforassigned programs, organizations,systems, or enclaves.
  • Maintain and report system s A&A status and events.
  • Manage theSPforassignedsystemsthroughout their lifecycle.
  • Perform annualsecurity reviews, annual testing of security controls, and annual testing ofthe contingency plan, in line with FISMA requirements.
  • Manage POA&Mentries and ensuring vulnerabilities are properly tracked, mitigated, and resolved.
  • Assist with identification of thesecurity control baselineset and any applicable overlays.
  • Supervise the validation ofsecuritycontrols with the PM/ISO, SCALiaison, PSO, and AO CSA.
  • Assemble the Security Authorization Package and submitforadjudication.
  • Register and maintain the system in eMASS.
  • Assess the quality ofsecurity control implementation against all requirements in accordance with the approvedSLCMstrategy.
  • Plan and performcybersecurity testing to assess securitycontrols and recording securitycontrol compliance status duringsustainment.
  • Reportchanges in the securitypostureofsystems to the AO.
  • Utilize the Collaboration Board in eMASS workflow for all formal coordination during the RMF process.Detailedfindings will beposted in the Artifacts tab (if necessary).
  • Assist the ISSMs in executingtheirduties and responsibilities.
  • Ensure compliance with all USN,DON,andDoDcybersecuritypolicies.
  • Ensure all userspossess the requisite securityclearances and awareness of their responsibilitiesforsystemsunder their purviewprior to being granted access.
  • Ensure an incident response, businesscontinuity,disaster recovery, as well as vulnerabilityand threat reportingplans and channels are in place and that team members are trained accordingly.
  • Ensure relevant policy and procedural documentation is current and accessible toproperly authorized individuals
  • Utilizethe Collaboration Board in the eMASS workflow for all formal coordination duringthe RMF process.Detailedfindings will beposted in the Artifacts tab(ifnecessary).

PHYSICALDEMANDS:

  • Sedentary/10 lbs. maximum. Occasional life/carry of smallarticles.Some occasional walking or standingmayberequired.

MINIMUM SKILLS / QUALIFICATIONS:

  • Must have and maintain a DoD TopSecretClearance.
  • CompTIA Security+ or other DOD 8570.01 IAT Level 2 or 3 certification.
  • 6-10 years of system administrationand/orcybersecurityexperience.
  • Working knowledge of system administration fundamentalswhich may include,but is not limited to, administration of desktop/workstations,dedicated and virtual servers,MicrosoftActiveDirectory.
  • Self-motivated and the ability to multi-task and balance multiple goals and priorities.
  • Must befamiliar with DOD Risk Management Framework(RMF)policies, standards, procedures and have relevant experience with associated tools (e.g., eMASS, XACTA 360, AssuredCompliance Assessment Solution (ACAS), Anchore, DISASecurityTechnical Implementation Guides(STIGs),SCAPCompliance Checker (SCC),STIG Viewer, eMASSter,EvalSTIG).

EDUCATION:

  • HighSchool diploma or GED equivalent.
  • Security+ or other DOD8570.01 IAT Level 2 or 3 certification.

BENEFITS: Envisioneering,Inc.offers a stable work environment, a competitive salary, and a comprehensive benefits package effective dateof hire; including 401k, Medical/Dental/Vision,FSA,ShortTerm,LongTerm, AD&D and Lifeinsurance, (employer paid), voluntary life, TuitionReimbursement, Paid Leave, Holidays and much more.

AS A CONDITIONOF EMPLOYMENT: You must pass a drug and pre-employmentdrug screening. U.S. Citizenship Required. Candidatemust follow all company and non-DOTDrug and AlcoholTesting. *ADepartmentof Defense(DoD)TopSecretsecurityclearance is requiredat time of hire. Applicants selected will besubject to a U.S.Governmentsecurityinvestigation and must meet eligibility requirements foraccess to classified information. Due to the nature of work performed within our facilities,U.S.citizenshipisrequired. Please confirm in your cover letteror resume.

#IT-SECURITY


Full-time 2024-06-02
N/A
N/A
USD

Privacy Policy  Contact US
Copyright © 2023 Employ America All rights reserved.