GovCIO

Senior Information Assurance Engineer

GovCIO$125K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • High School diploma with 9+ years of relevant experience.
  • Current TS/SCI clearance required.
  • Relevant certifications such as CISSP, CISM, or GCIA are mandatory.
  • Strong understanding of RMF workflow tools like eMASS or Xacta.
  • In-depth knowledge of AFSCI network protocols and guidelines.
  • Expertise in A&A processes and computer security compliance.
  • Excellent communication skills, both written and verbal.

Responsibilities

  • Design, test, and implement secure operating systems and networks.
  • Conduct risk assessments and recommend application design improvements.
  • Engage in intrusion detection and prevention, as well as incident response support.
  • Maintain compliance with security requirements and prepare reports for government agencies.
  • Develop workflows for vulnerability scan tools and provide client training.
  • Monitor implementation of security tools and ensure they meet specifications.
  • Review and track information assurance vulnerability alerts and proposals for security compliance.

Benefits

  • Comprehensive health insurance options.
  • Flexible work scheduling opportunities.
  • Ongoing training and professional development programs.
  • Support for certifications and continuing education.
  • Retirement savings plans with company matching.
Full Job Description
Overview

GovCIO is currently hiring a Senior Information Assurance Engineer in support of the Air Force AFSCI network. This position will be located in San Antonio TX and will be an on-site only position.

Responsibilities

Designs, tests, and implements state-of-the-art secure operating systems, networks, and database products. Conducts risk assessments and provides recommendations for application design. Involved in a wide range of computer security issues including architectures, firewalls, electronic data traffic, and network access. Uses encryption technology, penetration and vulnerability analysis of various security technologies, and information technology security research. Prepares security reports for government agencies.

  • Performs a wide range of computer security duties, including architectures, firewalls, electronic data traffic, and network access.
  • Participates in the certification and accreditation processes; performs technical vulnerability assessments of computer security.
  • Provides business continuity and disaster recovery support.
  • Engages in intrusion detection and prevention; provides incident reporting and response support.
  • Conducts ongoing monitoring of computer securityrequirements and compliance, maintains system security plans and risk mitigation plans.
  • Trains clients in proper computer security measures and prevention

Specifically, this position will:

    • Provide support for all vulnerability and compliance scan tool applications and modules (pre-built and customized).
    • Develop workflows and customize, implement, and maintain the aforementioned applications.
    • Develop and update standard operating procedures (SOPs) and provide training on existing and new technologies to Government personnel. This is informal office training.
    • Provide process and operations guides.
    • Provide technical support in the daily operations and evaluation of existing security tools, products, and future capabilities. Tools shall include, but are not limited to: Security Log Management, Account Management, Asset Management, Vulnerability Management, End Point Security, and any related network security tools. Current tool sets are: ArcSight, Directory Resource Administration (DRA), Automated Compliance Assessment Solution (ACAS), System Center Configuration Manager (SCCM), Tanium, Host Base Security System (HBSS) and Service Now.
    • Maintain operational oversight and manage Command-level and privileged user accounts for the Enterprise using provided Enterprise tools.
    • Prepare for and conduct customer briefings, attend, and provide minutes on Technical Exchange Meetings (TEMs), and provide status reports on cybersecurity activities.
    • Add so,ething about leadership briefs
    • Develop information systems security studies and reports that address areas of information system security concerns. Ensure cybersecurityrequirements are incorporated in system development and sustainment activities. Provide consultant services in all areas of information system security, including: physical, administrative, personnel, computer, operations, and industrial security. Provide security documentation and reports within specified timeframes.
    • Monitor and report, IAW IC Directives and AFSCI policy, the status of security measures established by the Director of National Intelligence (DNI) and related authorizing officials that protect and defend information and information systems, web-based services, remote hosted applications, discovery, storage, operating systems, public key infrastructure (PKI), and other information technology components and applications for the Enterprise.
    • Maintain cybersecurity, system security, and sustainment programs. The contractor shall follow all applicable ICD and National Institute of Standards and Technology (NIST) guidance in performing day-to-day duties.
    • Create, edit, and review security accreditation and authorization packages for the AFSCI Enterprise. Adhere to the RMF process. Input data into appropriate A&A tool. The current toolset used is XACTA. Review logical network drawings, configurations, and control parameters to ensure they are current. Review documentationrequired to certify new hardware and software systems for deployment.
    • Monitor and administer the vulnerability and compliance scan tool.
    • Review AFSCI change proposals for security, interoperability, accreditation and authorization issues or vulnerabilities.
    • Perform vulnerability and compliance assessments. Conduct security tests and evaluations. Monitor and review Information Assurance Vulnerability Alerts (IAVA) and Information Assurance Vulnerability Bulletins (IAVB).
    • Track and provide results to appropriate Government entity for review IAW standard operating procedures.
    • Monitor and report mandated Federal Information Security Management Act (FISMA) statistics for the AFSCI Enterprise.
    • Provide quarterly report to appropriate Government entity in accordance with IC Directives and AFSCI policy.
Qualifications

High School with 9+ years (or commensurate experience)

  • Clearance Required: Current TS/SCI

Required Skills and Experience

  • MUST have current one of these certifications: CISSP, CISSP-ISSMP, CISM, FITSP-M, GCIA, GCIG, GICSP, GSLC
  • Strong understanding of RMF workflow tools like eMASS or Xacta
  • Strong working knowledge of programs working within AFSCI network rules and guides
  • Experience with network management tools, network engineering principles, network analysis
  • Expert understanding of A&A process
  • Possess an expert understanding of current computer securityrequirement and compliance
  • Expert ability to maintain System Security and Risk Mitigation plans
  • Excellent written/verbal communications skills

#NSS #TM #DL

Posted Salary RangeUSD $125,000.00 - USD $130,000.00 /Yr.

About GovCIO

GovCIO is a technology and consulting firm that provides IT solutions to government agencies. The company specializes in cloud computing, cybersecurity, and digital transformation. GovCIO's mission is to help government agencies improve their IT infrastructure and enhance their services to the public. The company was founded in 2015 and is headquartered in Washington, DC.
Learn more about GovCIO
Size
50 employees
Industry
Founded
2015

Similar Jobs

More Jobs at GovCIO

More Information Technology Jobs

Find similar Senior Information Assurance Engineer jobs: