Jobs · Information Technology · Maryland

Cyber Security Engineer - TS/SCI

VMD Corp · Bethesda, MD · Yesterday
On-siteInformation TechnologyFull-time

About the role

Domex Technology Platform (DTP) contract supporting NMEC. Mission focused, solutions oriented, and adaptive team that values innovation, collaboration, and professional development.

Responsibilities

  • Support the secure architecture, design, and implementation of DoD systems in accordance with DoDI 8510.01, NIST SP 800-53, and other DoD security guidance.
  • Lead the integration of RMF activities into the system development lifecycle (SDLC), including selecting, implementing, and validating security controls.
  • Develop and maintain key security documentation such as System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessments, and Plan of Action and Milestones (POA&Ms).
  • Collaborate with ISSOs, ISSMs, developers, and system owners to ensure systems are developed and maintained with approved security configurations.
  • Apply Security Technical Implementation Guides (STIGs) to systems and validate compliance using tools such as SCAP, STIG Viewer, and ACAS.
  • Maintain application, network, and database scanning infrastructure (application/product updates, database maintenance, benchmark/audit files, application/server builds, rule pack/content updates, scanner, or agent deployment etc.).
  • Analyze vulnerability scans and ensure timely mitigation or acceptance of risks based on DoD policies.
  • Provide technical input to support and maintain system authorization.
  • Participate in system reviews, architecture assessments, and engineering design reviews to embed cybersecurity from the outset.
  • Develop and implement automation or security tools to improve the compliance and monitoring of systems.
  • Support security incident response and forensics analysis in coordination with ISSMs and Security points of contact.

Requirements

  • BS degree and 8+ years of experience in cybersecurity. Additional relevant years of experience in lieu of degree is accepted.
  • An active TS/SCI clearance with ability to obtain a Poly.
  • One of the following DoD 8570.01-M IASAE Level II certifications: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.

Qualifications

  • Developer experience is preferred in a least one scripting / programming language.
  • Experience with reviewing cybersecurity vulnerabilities for risk and relevance as well as in vulnerability mitigations/remediation planning, for identified systems, network, application and database vulnerabilities.
  • Experience with architecting, designing, troubleshooting, maintaining, and deploying vulnerability scanning solutions such as (OWASP, Fortify, Sonarqube, Tenable, etc.).
  • Experience with middleware / web technologies (Apache, tomcat, IIS, etc.).
  • Experience with Databases (Postgres, MS SQL, MySQL, ElasticSearch, etc.).
  • Understanding of TCP/IP networking.
  • Experience with Continuous Integration and Continuous Delivery Platforms (Jenkins, Bamboo, GitlabCI TFS, etc.).
  • Familiar with NIST 800-171, 800-172, NIST SSDF, and CMMC requirements. Experience with NIST Special Publications e.g. NIST SP 800-27, 30, 37, 53, 60, 171, NIST SSDF, CMMC requirements, and CNSS publication CNSSI 1253.
  • Experience supporting DoD/IC systems through the entire Risk Management Framework Plus (RMF) process.
  • Experience establishing a System Security Engineering management process to integrate security and privacy controls into complex hardware and software systems.
  • Experience developing and reviewing security concept of operations, systems security plans, security risk assessments, contingency plans, configuration management plans.
  • Experience with incident response plans, plan of actions and milestones, risk management plans, and vulnerability management plans.
  • Strong communication skills; able to successfully communicate with management personnel, technical personnel and third parties.

Benefits

Hybrid 3 days on-site location: Bethesda, MD. Flexible schedule. Occasionally, some tasks may be performed remotely. Percentage of remote work will vary based on client requirements/deliverables.

Pay

TBD

Schedule

Hybrid 3 days on-site location: Bethesda, MD. Flexible schedule. Occasionally, some tasks may be performed remotely. Percentage of remote work will vary based on client requirements/deliverables.

Similar jobs

Cybersecurity Analyst - TS/SCI

Spry Squared, Inc. - Cybersecurity and Managed IT ServicesArlington, VA· 8 mo ago
Information Technology$90k–$140k/yrapply on careers-page.com

Cyber Technical Engineer

Technomics, Inc.Arlington, VA· 6 mo ago
Information Technologyapply on technomics.clearcompany.com