Information Assurance Security Engineer

Crimson Phoenix

$116K — $164K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret SCI clearance with polygraph required; no sponsorship available.
  • In-depth knowledge of ICD 503 and experience with Cloud Infrastructure/AWS.
  • IAM II certification as per DOD 8570.1M standards.
  • 10-15 years of experience in data security administration.
  • Proficiency in security tools such as ACAS, HBSS, and Carbon Black.
  • Strong background in Unix and RHEL OS scripting, along with PowerShell expertise.
  • Bachelor's degree in Computer Science or related field, or equivalent experience.

Responsibilities

  • Draft security policies and review agreements for compliance.
  • Manage multi-agency information security sharing and integration.
  • Conduct system design assessments and evaluate security systems.
  • Document and investigate security incidents, proposing corrective actions.
  • Ensure compliance with information system security procedures and policies.
  • Facilitate and conduct security training for system users.
  • Perform maintenance and advanced configuration to safeguard network from cyber threats.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • 401(k) plan with company match.
  • Generous paid time off policy.
  • Company-paid life and disability insurance.
  • Tuition reimbursement and professional development opportunities.
  • Employee recognition programs and wellness benefits.
Full Job Description
Job Description

What You Will Be Doing:

  • Writing information security policy drafts.
  • Writing and reviewing Memorandum of Agreements and coordinating and managing all aspects of the Certification and Accreditation.
  • Advising and assessing system design/architecture as well as defining, designin, and evaluating information security systems.
  • Managing multi-agency information sharing and integration security.
  • Maintaining affiliations with high-level personnel at multiple agencies and organizations involved in Information Security. Tasking includes incident response, system access approval, audit log review, Configuration Control Board, and daily consultations/consulting on a wide variety of security issues.
  • Reporting, documenting, and investigating all security-related incidents; assisting with development and implementation of corrective measures.
  • Acting as the representative of the Information System Security Manager ensuring compliance with IS security procedures.
  • Supporting efforts to operate, maintain, and dispose of information system materials in accordance with security directives, policies, and practices and as annotated in Systems Security Plans.
  • Generating and implementation of requisite security training, ensuring user security awareness of responsibilities prior to system access.
  • Initiating protective and corrective measures when incident or vulnerabilities are discovered.
  • Ensuring IA hardware and software complies with security configuration guides.
  • Implementing and enforcing IA policies and procedures as defined by A&A documentation.
  • Ensuring users are aware of their IA responsibilities.
  • Working on multiple projects/tasks at once and operating in a dynamic, fast-paced, team-oriented environment.
  • Performing Operations & Sustainment (O&S) functions for the NCE network security infrastructure (firewalls, web gateways, mail gateways, ids, load balancers, performance monitoring tools, mgt systems, etc.).
  • Performing maintenance and/or advanced configuration of equipment in order to protect the network from emerging cyber threats.
  • Conducting forensic traffic/log analysis to isolate issues or respond to analyst alerts.
  • Responding to escalated troubleshooting requests.
  • Maintaining and administering network infrastructure standards, documentation, and fault tolerance.
  • Presenting Monitoring/Test Results and Reports as required.
  • Performing/supporting integration testing as required.
  • Participating in special projects as required.
  • Reviewing Plan of Action and Milestones (POA&Ms) and conducting a technical decomposition categorization, remediation, and lien resolution.
  • Executing remediation process to implement technical solutions to address vulnerability findings via ACAS security scan.
  • Defining, planning, designing, and evaluating information security systems.
  • Assessing architecture and current hardware limitations; defining and designing system specifications, input/output processes, and working parameters for hardware/software compatibility.
  • Performing a variety of complex tasks associated with information security ranging from the design of security components to complex architectures.
  • Supervising the work of other engineers performing a variety of information security tasks.


Required Skills

Must Have:

  • MUST HAVE a Current and Active Top Secret SCI with Polygraph, as the customer is NOT sponsoring clearances.
  • Knowledge of and experience with ICD 503 and familiarity with Cloud Infrastructure/AWS-based solutions.
  • IAM II certification in accordance with DOD 8570.1M. Understanding of how customer's RMF process works and how systems security requirements will be met.
  • Experience with Cloud Infrastructure/AWS-based technology.
  • Experience using security tools such as ACAS, HBSS, Carbon Black, Tanium, RedSeal, and EMET.
  • Experience installing, hardening, deploying, documenting, and troubleshooting network perimeter security technologies.
  • Experience and scripting ability on Unix and/or RHEL OS.
  • Experienced with complex Microsoft macros, and PowerShell scripts.
  • Basic understanding of Windows Enterprise AD architecture and VMWare Virtualization.
  • Proficiency in network routing/vlan technology.
  • Bachelor's Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training, or work experience.
  • 10-15 years of related experience in data security administration.


Desired Skills

Nice to Have:

  • CISSP certification or equivalent (CAP, GSLC, CISM).
  • System administration experience.
  • Network engineering experience.
  • System design and development experience.


Additional Details

Compensation & Benefits: This position has an anticipated salary range of $116,150 - $164,382 per year. Actual compensation will be determined based on factors including experience, qualifications, skills, education, certifications, and business needs. Crimson Phoenix offers a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) with company match, generous paid time off, company-paid life and disability insurance, tuition reimbursement, professional development opportunities, employee recognition programs, and additional wellness and work-life benefits.

U.S. citizenship and the ability to obtain or maintain a security clearance may be required for certain positions.

Similar Jobs

More Jobs at Crimson Phoenix

More Information Technology Jobs

Find similar Information Assurance Security Engineer jobs: