Security Operations & Assessment Engineer

Aderas, Inc

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Cybersecurity, or related field
  • 5-6 years of IT experience with a master's degree, or 6+ years with a bachelor's
  • Security certifications preferred (CISSP, CISA, CISM, CAP, CRISC, CCSP)
  • Hands-on experience with FedRAMP and NIST frameworks
  • Operational SOC experience with continuous monitoring and remediation
  • Strong automation and process improvement skills

Responsibilities

  • Coordinate security operations and conduct investigations
  • Perform forensic analysis of digital media related to incidents
  • Support detection and response to insider threats
  • Produce and coordinate quarterly security reporting
  • Provide expertise in security tool testing and operation
  • Develop documentation for SOC systems
  • Conduct vulnerability assessments and simulate attacks

Benefits

  • Hybrid work model
  • Opportunities for professional growth and certifications
  • Collaborative team environment
  • Engagement in innovative security initiatives
  • Involvement in critical cybersecurity missions
Full Job Description
Aderas is seeking a Security Operations & Assessment Engineer to join the team.

Primary Job Duties:
  • Work closely with the organization to coordinate security operations and deliver or request assistance or assist with investigations
  • Perform forensic analysis on various digital media devices and mediums to identify, reverse engineer, and obfuscate content related to an incident, such as malicious content.
  • Provide support to detect, prevent, and respond to threats posed by malicious, negligent, or compromised insiders by maintaining in-depth visibility into the DFC Enterprise and having a means of filtering and prioritizing threat data into concise, actionable intelligence.
  • Coordinate and produce quarterly certification reporting (in alignment with CR26) incorporating significant system updates, vulnerability posture, and incident lessons learned, aligned to required formats/timelines
  • Provide security engineering and subject matter expertise to conduct market research, product evaluation, testing, configuration, deployment, operations, and maintenance support for various SOC software tools and technologies
  • Create procedures and documentation for maintaining all SOC hardware and software
  • Facilitate and perform remediation actions based on the results of ongoing monitoring activities and the outstanding items in the POA&M
  • Provide technical expertise in cyber adversary capabilities and an assessment of the intentions of these groups to conduct Computer Network Exploitation (CNE) and Computer Network Attack (CNA) against U.S. private sector and Government networks and information systems.
  • Provide onsite and remote vulnerability assessment capabilities as a sustained, full-time program independent of incident detection, recovery, or reporting activities.
  • Provide both internal and external security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, and network.
  • Work with the DFC CIRT or any other pertinent parties (including external vendors) at any DFC location to recover from any incident
  • Advise and assist the Chief Information Security Officer (CISO) with SOC architecture activities for all DFC SOC information systems initiatives supporting all SOC tools and capabilities.
  • Determine and document the security impact of proposed or actual changes to the information systems and their environment of operation
  • Assess the technical, management, and operational security controls employed within and inherited by the information systems including support for collaborative continuous monitoring and adaptation to agency-specific continuous monitoring strategies
  • Develop Security Assessment Plans (SAPs) and Rules of Engagement (ROE). Review and provide feedback on the System Security Plan (SSP). Develop Security Assessment Reports (SAR), Plan of Action & Milestones (POA&Ms) and Authorization to Operate (ATO) letters.
  • Reporting must incorporate vulnerabilities, significant changes, and incident lessons learned, and support quarterly certification reporting requirements

Required Experience/Skills
  • Assessment experience and actual technical knowledge.
  • Design/operate automation workflows that produce machine-readable compliance evidence and reporting inputs from SOC/security tools.
  • Maintain structured traceability from requirements/rules 12 control implementation 12 evidence 12 findings 12 POA&M closure validation.
  • Hands-on technical knowledge (FedRAMP, NIST RMF, NIST 800-53, NIST SP 800-37, FISMA, A&A, POA&M management, SSP/SAR updates).
  • Operational SOC experience (continuous monitoring, remediation, change impact analysis).
  • Automation and documentation capability (process improvement, scripting, repeatable procedures).

Required Education & Work Experience:
  • Bachelor's degree or higher in Information Systems Management, Information Technology, Cybersecurity, Computer Science, Business, Management, Engineering, or another related discipline
  • Certification such as CISSP, CISA, CISM, CAP, CRISC, or CCSP preferred
  • Min. Five (5) years of professional IT experience with a master's degree OR six (6) years of experience with a bachelor's degree
  • Clearance/Citizenship: U.S. Citizen with Secret/T3 clearance

    Location: Hybrid in Washington, DC


Similar Jobs

More Jobs at Aderas, Inc

More Information Technology Jobs

Find similar Security Operations & Assessment Engineer jobs: