Logo
Open SAN Consulting (OSC)

Cyber Security Engineer with Security Clearance

Open SAN Consulting (OSC), Augusta, Georgia, United States, 30910


Cyber Security Engineer with Security Clearance

As the Cyber Security Engineer, the candidate will perform tasks related to Assessment & Authorization (A&A) to ensure assigned DoD, DoA systems/Enclaves/Networks can obtain and maintain Authorization to Operate (ATO) and Authorization to Connect (ATC) certifications. In this role, the Cyber Security Engineer will conduct risk and vulnerability assessments of information systems to identify vulnerabilities, risks, and protection needs. Additionally, the individual will serve as regulations and Information Systems Security Officer (ISSO) and review and conduct technical security assessments of computing environments to identify points of vulnerability, as well as non–compliance with established cyber security standards and regulations, and recommend mitigation strategies to the team.Responsibilities

Develops RMF accreditation artifact documentation to include Risk Assessment Report (RAR), Information Security Continuous Monitoring (ISCM) Strategy, Security Authorization Package, engineering documentation, network drawings, and related documentation as required by DoD and DoN accreditation standards.Develops, maintains, and monitors the necessary artifacts for A&A package submission to receive ATC, ATT, and ATO certifications.Reviews weekly CND vulnerability scans utilizing DoD/DoA mandated practices and software utilities.Conducts FISMA assessments of cybersecurity control compliance in accordance with DoDI 8500.01, DoDI 8510.01, CNSSI 1253 and the Cybersecurity Strategy.Prepares daily, weekly, and monthly reports detailing task and responsibility status.Develops, reviews, and maintains RMF artifacts for RMF compliance.Supports Cybersecurity Test & Evaluation (CT&E) or Developmental Test & Evaluation (DT&E) activities of system security engineering and program protection activities.Drafts authorization artifacts in accordance with customer requirements.Monitors and executes compliance as defined by VRAM for the DoA.Updates and validates policies, processes, and SOPs, in accordance with DoA and DoD policies and regulations.Provides IT Security Incident Response support services and reports all tenant IT incidents ranging from security violations (i.e., information spillage and unauthorized usage) and suspicious activity reports.Performs system categorization; selects, tailors security controls, implements, and tests security controls.Attends and leads meetings and works in a collaborative team environment to provide network stability and continuity.Performs other tasks as required by OSC and the Government contracting office.Required Qualifications/Education and Experience

High School diploma or equivalent.Minimum of four (4) years of hands–on experience in the IT/Communications Security environment.Must have and maintain a Top–Secret personnel clearance and be eligible for a TS/SCI.Must be DoD 8570 certified at the IAM–II level.Must have at minimum (2) years' experience with DoA, DoD RMF process; must have completed full DoD RMF accreditation package from start to ATO.Must have strong working experience with eMASS and experience in the development of Assessment and Authorization plans.In-depth understanding of computer security, Department of Army, and DoD cyber security policies.Prior experience with DISA Security Technical Implementation Guides (STIG), Assured Compliance Assessment Solution (ACAS), other DoA, and DoD cybersecurity tools.Strong ability to communicate clearly and succinctly in written and oral presentations.Prior experience with computer networking and telecommunication architecture, the OSI model, and communications protocols and in collaborating with multiple technical teams to drive solutions that are requirement driven.Have knowledge in network, physical, systems, and application security practices.Must be familiar with intrusion detection and prevention measures and practices.Must be familiar with and have experience in tools and applications such as Firewalls, IDS/IPS, HBSS, ACAS, Nessus, ARCSIGHT and SIEMs.Familiarity with DoD, NIST, RMF and FedRAMP processes.Excellent written and verbal communication skills.Experience running ACAS scans.Knowledge of multiple architectures: Cisco, Linux, Windows, and VMWare.Preferred Qualifications/Education and Experience

Bachelor's degree (preferably in Information Technology, Information Management, or Cyber Security).Certified Information Systems Security Professional (CISSP) certification.Experience with SIEMs.

#J-18808-Ljbffr