Cyber Security Engineer Fairfax, VA
Rampant Technologies · Fairfax, VA · 3 wk ago
Information TechnologyFull-time
About the Role
A Rampant Technologies Cybersecurity Engineer (CSE) is a key resource on the Rampant team, reporting to the Principal Engineer overseeing the CSE team to deliver innovative cybersecurity solutions aligned with the company’s goals.
Responsibilities
- Serve as a subject-matter expert (SME) on problem identification, diagnosis, and resolution of cybersecurity issues.
- Develop best practices for processes and standards to improve system security.
- Perform vulnerability assessments using standardized tools (e.g., Nessus, DISA STIGs) and implement configuration updates to comply with security requirements.
- Track and fulfill liens associated with Assessment & Authorization (A&A) activities as documented in the Plan of Actions and Milestones (POA&M).
- Perform hardening of operational systems, COTS, and open-source products.
- Validate best practices in penetration testing, configuration analysis, and security controls.
- Prepare comprehensive security assessment testing documentation to validate applied security controls in support of A&A testing.
- Generate and maintain security accreditation artifacts associated with the Risk Management Framework (RMF) process, including Security Requirements Traceability Matrix, Security Plans, Certification Test Plans, and Continuous Monitoring Plans.
- Perform timely updates in accreditation databases.
- Provide technical guidance focused on information security architecture.
Requirements
- Minimum of three (3) years’ relevant experience as a Cybersecurity Engineer in programs and contracts of similar scope, type, and complexity; ideally three (3+) years of direct experience in the same level/grade for a like role.
- Technical and functional knowledge of/experience in executing the Assessment & Authorization (A&A) process in accordance with government requirements (e.g., ICD-503).
- Experience with information systems security and continuous monitoring practices, including assessing their effectiveness per NIST SP 800-53 and NIST SP 800-53A.
- Familiarity with DCID 6/3, ICD 503, CNSSI 1253, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37, and security controls assessment criteria/procedures.
- Understanding of integrity, availability, authentication, and non-repudiation concepts.
- Knowledge of IT security principles and methods (e.g., firewalls, demilitarized zones, encryption).
- Experience with network access, identity, and access management (e.g., public key infrastructure [PKI]).
- Proficiency in security system design tools, methods, and techniques.
- Understanding of relevant laws, policies, procedures, or governance related to critical infrastructure.
- Experience with TCP/IP networking technologies, Linux account administration, Linux folder permissions, patch management best practices for operating systems and applications, and known vulnerabilities associated with Windows and Linux platforms.
- Knowledge of continuous monitoring processes as outlined in NIST SP 800-137, leveraging existing tools and incorporating new automation techniques.
- Experience with virtualization technologies (e.g., VMWare, Docker).
- Understanding of the OSI model and how specific devices and protocols interoperate, including knowledge of protocols and services for common network traffic.
- Familiarity with DoD/IC system security control requirements.
- Hands-on experience with security testing and penetration tools, including Assured Compliance Assessment Solution (ACAS), Wireshark, Retina, Tripwire, etc.
- Proficiency with the full Microsoft Office Suite and tools such as Microsoft Project and Microsoft Visio.
Qualifications
- Active TS/SCI with Polygraph clearance required.
- Current certification compliant with DoD 8570 IAM or IAT Level III or obtain certification within 6 months of hire and maintain it throughout employment.
- Must meet DoD 8570 IAT Level III requirements.
- IAT Level II Certifications (e.g., Security+ or equivalent).
- Self-starter and motivator.