Security Engineer

Calista Brice Holding Company

$100K — $120K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, information security, computer science, or related field.
  • 5+ years of experience in cybersecurity engineering or similar roles.
  • Knowledge of Federal cybersecurity requirements and risk management processes.
  • Experience with security assessments and vulnerability remediation.
  • Familiarity with NIST RMF and security controls.

Responsibilities

  • Support design and implementation of security controls for applications and systems.
  • Collaborate with various stakeholders to integrate security throughout the development lifecycle.
  • Identify and document security vulnerabilities and assist with remediation.
  • Conduct security assessments and vulnerability scanning.
  • Support identity and access management and role-based access controls.
  • Assist in security configuration and hardening of applications and infrastructure.
  • Develop and maintain security-related documentation and compliance materials.

Benefits

  • Work with a prestigious Federal agency on impactful cybersecurity initiatives.
  • Opportunity for professional growth in enterprise application modernization.
  • Collaborate with multi-disciplinary teams, enhancing your technical breadth.
  • Engagement with cutting-edge technologies in cybersecurity and cloud environments.
Full Job Description
StraitSys Inc

Regular

PRIMARY FUNCTION

The Security Engineer provides cybersecurity engineering and technical security support for enterprise application modernization efforts supporting the Executive Office for Immigration Review (EOIR). This individual is responsible for supporting the design, implementation, configuration, testing, and ongoing security of applications, systems, and supporting environments.

The Security Engineer works closely with project management, solution architects, developers, system administrators, testing personnel, and Government stakeholders to ensure security requirements are incorporated throughout the system development lifecycle. This individual supports the identification and remediation of security vulnerabilities, implementation of security controls, and development and maintenance of security documentation necessary to support Department of Justice (DOJ) and Federal cybersecurity requirements.

This position is contingent upon contract award

ESSENTIAL FUNCTIONS

  • Support the design, implementation, configuration, and maintenance of security controls for applications, systems, and supporting environments.
  • Collaborate with solution architects, developers, system administrators, and Government stakeholders to incorporate security requirements throughout the system development lifecycle.
  • Review system designs, configurations, interfaces, and technical implementations to identify potential security risks and vulnerabilities.
  • Support security assessments, vulnerability scanning, remediation activities, and validation of corrective actions.
  • Identify, document, track, and assist with the remediation of security findings and vulnerabilities.
  • Support implementation and maintenance of identity and access management, authentication, authorization, least privilege, and role-based access controls.
  • Assist with security configuration and hardening of applications, cloud resources, databases, integrations, and supporting infrastructure.
  • Support security testing throughout development, integration, testing, deployment, and ongoing operations.
  • Collaborate with development and operations personnel to incorporate secure development and DevSecOps practices into application development and deployment processes.
  • Support security monitoring and assist with the identification, analysis, response, and remediation of security incidents as required.
  • Develop and maintain security-related technical documentation, procedures, configuration information, and supporting artifacts.
  • Support the preparation and maintenance of documentation required for system security, authorization, assessment, and ongoing compliance activities.
  • Monitor security risks and vulnerabilities and communicate potential impacts and recommended mitigation actions to technical and project leadership.
  • Support compliance with applicable DOJ and Federal cybersecurity policies, standards, and requirements.
  • Participate in technical reviews, security reviews, project meetings, and other activities necessary to support secure system implementation and operations.

SUPERVISORY RESPONSIBILITIES: No

DESIRED KNOWLEDGE, SKILLS, & ABILITIES:

  • Experience supporting the Department of Justice (DOJ), EOIR, or other Federal civilian agencies.
  • Experience providing cybersecurity engineering support for enterprise application modernization or digital transformation initiatives.
  • Experience securing cloud-based, hybrid, and Microsoft technology environments.
  • Knowledge of Federal cybersecurity requirements, security controls, risk management, and system authorization processes.
  • Familiarity with the NIST Risk Management Framework (RMF) and NIST security controls.
  • Experience with vulnerability assessment, security scanning, remediation, and security configuration management.
  • Knowledge of identity and access management, authentication, authorization, least privilege, and role-based access controls.
  • Familiarity with application security, database security, API and integration security, and secure software development practices.
  • Familiarity with Microsoft Azure, Microsoft 365, and related enterprise technologies.
  • Experience working within Agile software development and DevSecOps environments.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to effectively communicate cybersecurity risks and technical information to technical and non-technical stakeholders.

QUALIFICATIONS:

  • Must be a US Citizen.
  • Must be able to successfully obtain and maintain the appropriate Department of Justice (DOJ) Public Trust Investigation (PTI) as required for the position.
  • Bachelor's degree from an accredited college or university and relevant professional experience in cybersecurity, information security, systems security engineering, information technology, computer science, or a related discipline.
  • Ability to successfully pass a pre-employment drug test and background check.

PLACE OF PERFORMANCE

The principal place of performance will be EOIR Headquarters located in Falls Church, VA.

PREFERENCE STATEMENT
Preference will be given to Calista shareholders and their descendants and to spouses of Calista shareholders, and to shareholders of other corporations created pursuant to the Alaska Native Claims Settlement Act, in accordance with Title 43 U.S. Code 1626(g).

Similar Jobs

More Jobs at Calista Brice Holding Company

  • Senior IT Project Manager - AI
    $120K — $145K *
    Quantico, VA 22134 (Prince William County)
    Aerospace & Defense
    In-Person
  • Project Manager
    $150K — $180K *
    Lompoc, CA 93436 (Santa Barbara County)
    Real Estate & Construction
    In-Person
  • Testing Engineer
    $80K — $95K *
    Falls Church, VA 22042 (Fairfax County)
    Information Technology
    In-Person
  • Microsoft 365 Integration Developer
    $100K — $120K *
    Falls Church, VA 22042 (Fairfax County)
    Information Technology
    In-Person
  • ITCET Program Manager
    $110K — $130K *
    Quantico, VA 22134 (Prince William County)
    Education, Government & Non-Profit
    In-Person

More Education, Government & Non-Profit Jobs

Find similar Security Engineer jobs: