Cyber Security Engineer - TS/SCI
VMD Corp · Bethesda, MD · Yesterday
On-siteInformation TechnologyFull-time
About the role
Domex Technology Platform (DTP) contract supporting NMEC. Mission focused, solutions oriented, and adaptive team that values innovation, collaboration, and professional development.
Responsibilities
- Support the secure architecture, design, and implementation of DoD systems in accordance with DoDI 8510.01, NIST SP 800-53, and other DoD security guidance.
- Lead the integration of RMF activities into the system development lifecycle (SDLC), including selecting, implementing, and validating security controls.
- Develop and maintain key security documentation such as System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessments, and Plan of Action and Milestones (POA&Ms).
- Collaborate with ISSOs, ISSMs, developers, and system owners to ensure systems are developed and maintained with approved security configurations.
- Apply Security Technical Implementation Guides (STIGs) to systems and validate compliance using tools such as SCAP, STIG Viewer, and ACAS.
- Maintain application, network, and database scanning infrastructure (application/product updates, database maintenance, benchmark/audit files, application/server builds, rule pack/content updates, scanner, or agent deployment etc.).
- Analyze vulnerability scans and ensure timely mitigation or acceptance of risks based on DoD policies.
- Provide technical input to support and maintain system authorization.
- Participate in system reviews, architecture assessments, and engineering design reviews to embed cybersecurity from the outset.
- Develop and implement automation or security tools to improve the compliance and monitoring of systems.
- Support security incident response and forensics analysis in coordination with ISSMs and Security points of contact.
Requirements
- BS degree and 8+ years of experience in cybersecurity. Additional relevant years of experience in lieu of degree is accepted.
- An active TS/SCI clearance with ability to obtain a Poly.
- One of the following DoD 8570.01-M IASAE Level II certifications: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.
Qualifications
- Developer experience is preferred in a least one scripting / programming language.
- Experience with reviewing cybersecurity vulnerabilities for risk and relevance as well as in vulnerability mitigations/remediation planning, for identified systems, network, application and database vulnerabilities.
- Experience with architecting, designing, troubleshooting, maintaining, and deploying vulnerability scanning solutions such as (OWASP, Fortify, Sonarqube, Tenable, etc.).
- Experience with middleware / web technologies (Apache, tomcat, IIS, etc.).
- Experience with Databases (Postgres, MS SQL, MySQL, ElasticSearch, etc.).
- Understanding of TCP/IP networking.
- Experience with Continuous Integration and Continuous Delivery Platforms (Jenkins, Bamboo, GitlabCI TFS, etc.).
- Familiar with NIST 800-171, 800-172, NIST SSDF, and CMMC requirements. Experience with NIST Special Publications e.g. NIST SP 800-27, 30, 37, 53, 60, 171, NIST SSDF, CMMC requirements, and CNSS publication CNSSI 1253.
- Experience supporting DoD/IC systems through the entire Risk Management Framework Plus (RMF) process.
- Experience establishing a System Security Engineering management process to integrate security and privacy controls into complex hardware and software systems.
- Experience developing and reviewing security concept of operations, systems security plans, security risk assessments, contingency plans, configuration management plans.
- Experience with incident response plans, plan of actions and milestones, risk management plans, and vulnerability management plans.
- Strong communication skills; able to successfully communicate with management personnel, technical personnel and third parties.
Benefits
Hybrid 3 days on-site location: Bethesda, MD. Flexible schedule. Occasionally, some tasks may be performed remotely. Percentage of remote work will vary based on client requirements/deliverables.
Pay
TBD
Schedule
Hybrid 3 days on-site location: Bethesda, MD. Flexible schedule. Occasionally, some tasks may be performed remotely. Percentage of remote work will vary based on client requirements/deliverables.