Sr. Cyber Security Engineer
Hatchpad, Bethesda, MD, United States
Up to $155,000
Partially Remote
Bethesda, MD
hatch I.T. is partnering with cyDaptiv to find a Senior Cyber Security Engineer (CSE). See details below:
About The Role:
cyDaptiv Solutions is seeking a Senior Cyber Security Engineer (CSE) with experience supporting Federal and DoD cyber security and information assurance projects. The CSE must have knowledge of the Risk Management Framework (RMF), security principles, concepts, policies, and regulations and be able to identify risks in information systems and work with system administrators and engineers to resolve security weaknesses.
The successful candidate will have experience assessing security control implementation and system configurations using automated tools and manual checklists; determining compliance/risk severity; recommending remediations; and have the ability/skillset to implement fixes. The candidate must also have experience working with stakeholders at various organizational levels and be able to manage and coordinate assessment activities in a collaborative manner.
Responsibilities:
- Implementing the DoD Assess and Authorize (A&A) process IAW DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT).
- Ability to manage RMF Artifacts in eMASS.
- Assess systems using automated tools such as ACAS / Nessus and Security Content Automation Protocol (SCAP), and Manual STIGs reviews.
- Experience testing and implementing DoD STIGs and devising mitigation strategies, applying Information Assurance Vulnerability Management (IAVM) patches to systems and complete security compliance scans upon applying patches or updates to the system.
- Experience drafting Architecture Diagram, Hardware Software Inventory List, Ports Protocols Services Registration, and Data Flow diagram.
- Introduce new team members to project tasks and expectations.
Requirements
- Bachelor’s degree or higher in Computer Science, Information Systems/Technology or engineering discipline preferred.
- Strong technical understanding of the network and systems operations in secured DoD environments.
- Strong understanding of SDLC process in a DoD environment.
- 7 years of relevant experience in Federal and DoD network and computing environments.
- 4 years of experience supporting DoD Risk Management Framework (RMF) and implementation of technical controls.
- Meet DOD 8570/8140 certification requirements for IAT Level II. Includes: CCNA Sec, GISCP, GSEC, Security+ CE, CND, or SSCP.
- Hands-on experience with tools such as NMAP, ACAS/Nessus, and Security Content Automation Protocol (SCAP), and STIGViewer.
- Experience using DoD SRGs/STIGs and other manual system configuration review methods, developing mitigation strategies, and applying systems and vulnerability patches.
- Strong written and verbal communication skills to provide IA/cybersecurity guidance to relevant project stakeholders.
- Ability to work independently with minimal supervision.
- Must hold an Active Secret or clearable at the Secret Level.