Job DescriptionWhat You Will Be Doing:- Writing information security policy drafts, writing and reviewing Memorandum of Agreements, and coordinating and managing all aspects of the Certification and Accreditation.
- Advising and assessing system design/architecture as well as defining, designing, and evaluating information security systems.
- Managing multi-agency information sharing and integration security.
- Maintaining affiliations with high-level personnel at multiple agencies and organizations involved in Information Security. Tasking includes incident response, system access approval, audit log review, Configuration Control Board and daily consultations/consulting on a wide variety of security issues.
- Reporting, documenting, and investigating all security-related incidents; assisting with development and implementation of corrective measures.
- Working with all IT groups to build IT systems with security planned from the start. Working with developers, system engineers, project managers, and users to identify the level of protection systems will need.
- Acting as the representative of the Information System Security Manager, ensuring compliance with IS security procedures.
- Supporting efforts to operate, maintain, and dispose of information system materials in accordance with security directives, policies, and practices and as annotated in Systems Security Plans.
- Generating and implementation of requisite security training, ensuring user security awareness of responsibilities prior to system access.
- Initiating protective and corrective measures when incident or vulnerabilities are discovered.
- Ensuring IA hardware and software complies with security configuration guides.
- Implementing and enforcing IA policies and procedures as defined by A&A documentation.
- Ensuring users are aware of their IA responsibilities.
- Working on multiple projects/tasks at once and operating in a dynamic, fast-paced, team-oriented environment.
- Performing Operations & Sustainment (O&S) functions for the NCE network security infrastructure (firewalls, web gateways, mail gateways, ids, load balancers, performance monitoring tools, mgt systems, etc.).
- Performing maintenance and/or advanced configuration of equipment in order to protect the network from emerging cyber threats.
- Conducting forensic traffic/log analysis to isolate issues or respond to analyst alerts.
- Responding to escalated troubleshooting requests.
- Maintaining and administering network infrastructure standards, documentation, and fault tolerance.
- Presenting Monitoring/Test Results and Reports as required.
- Performing/supporting integration testing as required.
- Participating in special projects as required.
- Reviewing Plan of Action and Milestones (POA&Ms) and conducting a technical decomposition categorization, remediation, and lien resolution.
- Executing remediation process to implement technical solutions to address vulnerability findings via ACAS security scan.
- Defining, planning, designing, and evaluating information security systems.
- Assessing architecture and current hardware limitations; defining and designing system specifications, input/output processes, and working parameters for hardware/software compatibility.
- Performing a variety of complex tasks associated with information security ranging from the design of security components to complex architectures.
- Supervising the work of other engineers performing a variety of information security tasks.
Required SkillsMust Have:- MUST HAVE a Current and Active Top Secret SCI with Polygraph, as the customer is NOT sponsoring clearances.
- Knowledge of and experience with ICD 503 and familiarity with Cloud Infrastructure/AWS-based solutions.
- IAM II certification in accordance with DOD 8570.1M. Understanding of how customer's RMF process work and how systems security requirements will be met.
- Experience with Cloud Infrastructure/AWS-based technology.
- Experience using security tools such as ACAS, HBSS, Carbon Black, Tanium, RedSeal, and EMET.
- Experience installing, hardening, deploying, documenting, and troubleshooting network perimeter security technologies.
- Experience and scripting ability on Unix and/or RHEL OS.
- Experience with complex Microsoft macros and PowerShell scripts.
- Basic understanding of Windows Enterprise AD architecture and VMWare Virtualization.
- Proficiency in network routing/vlan technology.
- Bachelor's Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training, or work experience.
- 10-15 years of related experience in data security administration.
Desired SkillsNice to Have:- CISSP certification or equivalent (CAP, GSLC, CISM).
- System administration experience.
- Network engineering experience.
- System design and development experience.
Additional DetailsCompensation & Benefits: This position has an anticipated salary range of $159,850 - $164,382 per year. Actual compensation will be determined based on factors including experience, qualifications, skills, education, certifications, and business needs. Crimson Phoenix offers a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) with company match, generous paid time off, company-paid life and disability insurance, tuition reimbursement, professional development opportunities, employee recognition programs, and additional wellness and work-life benefits.
U.S. citizenship and the ability to obtain or maintain a security clearance may be required for certain positions.