Information Assurance Security Engineer - Huntsville AL - TS required to apply

Bow Wave LLC

$100K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10 years of experience in secure design, analysis, and testing of information security systems and products.
  • 10 years of experience ensuring proper implementation and documentation of baseline security safeguards.
  • 10 years of experience creating and updating security test plans for risk mitigation.
  • Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) certification required.
  • Cloud certification preferred.

Responsibilities

  • Lead, mentor, and supervise a team of contractor security professionals through the RMF lifecycle.
  • Oversee activities within the Prepare step of the RMF, defining roles and risk strategies.
  • Guide system categorization to classify systems based on regulatory requirements and impact.
  • Advise on security controls aligned with risks, compliance, and the Bureau's risk appetite.
  • Ensure technical, operational, and management controls are implemented effectively across system lifecycles.
  • Plan and document security control assessments to validate safeguard effectiveness.
  • Direct continuous monitoring and collection of metrics to refine security strategies.

Benefits

  • Technical guidance and training provided to team members and stakeholders.
  • Engagement with leadership on status and improvement of security activities.
  • Opportunity to maintain knowledge of the latest RMF, NIST guidance, and industry best practices.
Full Job Description
OCIO's Cybersecurity Risk Management Unit) with Cloud certification, preferred)
Responsible for leading the implementation of the SAA Program, as defined in section 2.0 and in the SAA PG.
Work Description:
- Lead, mentor, and supervise a team of contractor security professionals responsible for the end-to-end implementation of the RMF lifecycle for FBI IT systems.
- Oversee and coordinate activities within the Prepare step, ensuring roles, responsibilities, and risk management strategies are clearly defined and maintained.
- Guide system categorization efforts to ensure all information systems are appropriately classified based on mission/business impact and regulatory requirements.
- Advise on the selection, tailoring, and documentation of security controls aligned with system categorizations, Bureau risk appetite, and compliance requirements.
- Oversee the implementation of technical, operational, and management controls throughout system and application lifecycles, with a particular focus on quality and completeness of all deliverables.
- Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards.
- Prepare risk management documentation for system authorization and executive decision-making.
- Direct ongoing monitoring and continuous assessment activities, collecting metrics to adjust security strategies and ensure sustained compliance.
- Serve as a principal technical advisor on cybersecurity, bringing subject-matter expertise to risk analysis, incident response, system remediation, and audit support efforts.
- Foster a culture of security awareness, providing technical guidance and training to both team members and stakeholders.
- Track, report, and communicate status, risks, and improvement opportunities related to security engineering activities to leadership and stakeholders.
- Maintain up-to-date knowledge of RMF, NIST guidance, and industry best practices in support of continuous process improvement.
Required Experience/Skills/Certifications:
- 10 years of experience in secure design, analysis, and test of information security systems and products.
- 10 years of experience applying methods, standards and approaches for ensuring the baseline security safeguards are appropriately implemented and documented.
- 10 years of experience creating and updating security test plans for detecting and mitigating risk to information systems.
- Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) certification required
- Cloud certification, preferred.

Similar Jobs

More Jobs at Bow Wave LLC

More Information Technology Jobs

Find similar Information Assurance Security Engineer - Huntsville AL - TS required to apply jobs: