OverviewThe Cybersecurity Team under SPA’s Information Technology Department establishes and maintains a robust cybersecurity posture and policy architecture across SPA's information systems. The team manages cyber policy, develops control implementations and system security plans, continuously monitors SPA systems, and performs routine cyber operations including patching, auditing, and incident response. Cybersecurity is critical to SPA's mission, therefore we strive to offer secure solutions that ensure data is protected while meeting the needs of the business.
In this role, you will serve as the Information Systems Security Engineer (ISSE) for multiple classified systems operating at SPA's Headquarters in Alexandria, VA and nearby satellite office locations. This requires the individual to operate with autonomy as the lead operator for many of SPA's defensive cyber tools. This role also serves as the primary point of contact between SPA and government Cybersecurity Service Providers (CSSPs) that support SPA's classified infrastructure.
SPA has an immediate or near-term need for an ISSE.
Responsibilities
The Information System Security Engineer (ISSE) handles daily security operations and continuous monitoring for classified networks, with a heavy focus on ACAS and Trellix ESS tools. In this role, you will run regular reviews and technical inspections to find and fix security vulnerabilities. You will perform system audits, handle incident response tasks, and track technical security guidance across the network. You will collaborate with networking teams to build accurate asset lists, configure ACAS policies using current best practices, and run daily vulnerability scans on SIPR networks. Daily tasks include checking dashboards for login failures, high vulnerability counts, or highly exploitable vulnerabilities. You will troubleshoot credential issues, work with system and network admins to resolve authentication problems within a week, and send compliance reports to leadership every two weeks. You will also run weekly discovery and compliance scans, manually upload monthly DoD audit files, and set up Nessus agents. Additionally, you will maintain the latest Trellix point products on Windows and Linux systems, perform DISA STIG reviews, and manage compliance dashboards. You will coordinate with the CSSP to ensure ACAS and ESS tools are working properly, resolve data reporting issues, and help the team prepare for DCSA Technical Reviews, incident response reviews, and Cyber Operational Readiness Assessments (CORA).
Qualifications
Required Qualifications:
- Bachelor’s degree in an Information Technology related field or equivalent work experience and certifications.
- Four (4) or more years of related work experience in information system security with at least one (1) year directly supporting classified systems.
- Must meet DoD 8140 certification requirements at IAM Level I or higher (such as Security+ CE, CAP, or GSLC).
- Ability to work independently and handle tasks with minimal supervision.
- Active DoD Top Secret security clearance.
- Solid understanding of networking basics, including IP routing, subnets, firewalls, VLANs, ports, and protocols.
- Practical knowledge of the Risk Management Framework (RMF) and NIST 800-53 controls.
Desired Qualifications:
- Hands-on experience installing, configuring, and troubleshooting Trellix Endpoint Security (ESS) products.
- Experience performing vulnerability management using tools like ACAS, Nessus, or Tanium.
- Experience reviewing EventLogs, Syslogs, and Splunk logs to troubleshoot technical errors.
- Experience configuring systems using DISA Security Technical Implementation Guides (STIGs) and STIG Viewer.
- Linux and Windows administration experience, specifically for solving credential and Trellix installation issues.
- Prior experience with DCSA reviews or direct involvement with Cyber Operational Readiness Assessments (CORA).
Many jobs at SPA require obtaining, holding, and maintaining eligibility for a designated clearance based on the company and/or client contract requirements. Should it be required, an individual must be able to obtain the appropriate clearance within a reasonable amount of time based on the needs of the client. In some cases, the individual may need the requisite clearance before being able to be actively employed. Additionally, due to the protected nature of the work process and product at SPA, all positions require the execution of the SPA Non-Disclosure Agreement (NDA). Some employees may be required to sign additional documents or complete other pre-employment or ongoing testing.
SPA employees typically work in a variety of office settings, some at an SPA office and some at designated client locations, where daily activities may include, but are not limited to, walking, standing, or sitting for extended periods, using computers and other technology, and being sequestered in SCIFs or other secured areas with limited access to outside resources or privacy. Other security requirements may inform dress code, personal accessories permitted, or technology usage. When applicable, employees are required to comply with the terms and conditions of client contracts as specified by SPA in its sole discretion, including, but not limited to, hours, location, timing, and technology usage, that meet logistical and security work requirements.
Pay Range InformationAt SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Virginia, Pay Transparency Salary range: USD $110,000.00/Yr. - USD $155,000.00/Yr.