Cyber Security Specialist IV
VT Group (VTG) · Herndon, VA · 2 days ago
On-siteEngineering$175k–$220k/yrFull-time
Overview
Byte Systems, a subsidiary of VTG, is seeking a seasoned Information Systems Security Engineer (ISSE) to join the diverse Information Assurance team supporting the Intelligence Community at the Herndon, VA office.
Responsibilities
- Design and implement safety measures and controls.
- Monitor network activity to identify vulnerable points and provide early warning of abnormalities.
- Address privacy breaches and malware threats.
- Support Assessment and Authorization (A&A) processes and Information Assurance documentation for multiple analytic and mission systems across all CLINs.
- Generate and maintain the complete security Body of Evidence (BoE) while leading A&A activities according to the Risk Management Framework (RMF) processes (ICD 503, CNSSI‑1253, NIST 800‑37, NIST 800‑53, etc.) for all information systems.
- Author, complete and maintain the System Security Plan (SSP) within XACTA.
- Develop Security Controls Traceability Matrices (SCTM) and Security Test Plan (STP) procedures within XACTA.
- Analyze existing security systems and recommend changes or improvements.
- Prepare reports and action plans in the event of a security breach.
- Communicate system status and keep users informed of downtime or changes.
- Collaborate with software developers and architects to understand and guide security requirements.
- Provide technical guidance to application developers on security policy and requirements.
- Create and manage Plans of Action and Milestones (POA&Ms) and work with project managers and engineers to develop schedules and engineering actions that mitigate open findings.
- Support continuous monitoring of operational systems, including monitoring and auditing for proper use.
- Perform log review/analysis using SIEM tools (e.g., Splunk).
- Conduct vulnerability analysis and review using tools such as ACAS, Prisma, SonarQube, JFrog X‑Ray, GitLab Code Quality.
- Utilize DISA STIGs and STIG Viewer.
Required Qualifications
- 9+ years supporting Assessment and Authorization (A&A) and information assurance processes and documentation using RMF.
- BS degree (or 7 years of experience with a master’s degree, or an additional 4 years of experience in lieu of a degree).
- Hands‑on experience validating control implementations and test procedures.
- Knowledge of current security risks and protocols.
- Willingness to work outside standard hours when required.
- DoD‑approved 8140 baseline certifications (e.g., Security+).
- RMF and Xacta experience.
- TS/SCI clearance with polygraph.
- Ability to work 100% onsite in a secure environment and be inducted at start.
Desired Qualifications
- Experience with AWS or Google Cloud‑hosted information systems or applications.
- Experience with containerized systems or applications.
- Experience with Red Hat or CentOS Linux operating systems.
- Experience working in a DevSecOps environment and tool chain.
Pay Range
VTG’s estimated starting pay range is $175,000‑$220,000 annually. Final offers consider work experience, education, skill level, market considerations, and possible contractual requirements.