Jr Cyber Security Eng
GovCIO · San Antonio, TX · 1 wk ago
On-siteInformation Technology$105k/yrFull-time
GovCIO is hiring a Jr Cyber Security Engineer to support the Air Force SCI network in San Antonio, TX. This is an on-site position.
Responsibilities
- Conducts risk assessments and provides recommendations for application design.
- Involved in a wide range of computer security issues including architectures, firewalls, electronic data traffic, and network access.
- Uses encryption technology, penetration and vulnerability analysis of various security technologies, and information technology security research.
- Prepares security reports for government agencies.
- Correlates threat data from various sources to establish the identity and modus operandi of hackers active in client's networks and posing a potential threat.
- Provides the customer with assessments and reports facilitating situational awareness and understanding of current cyber threats and adversaries.
- Develops cyber threat profiles based on geographic region, country, group, or individual actors.
- Produces cyber threat assessments based on entity threat analysis.
- Provides computer forensic and intrusion support to high technology investigations in the form of computer evidence seizure, computer forensic analysis, data recovery, and network assessments.
- Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding, and network security and encryption.
- Performs a wide range of computer security duties, including architectures, firewalls, electronic data traffic, and network access.
- Participates in the certification and accreditation processes; performs technical vulnerability assessments of computer security.
- Engages in incident reporting and response support.
- Conducts ongoing monitoring of computer security requirements and compliance, maintains system security plans and risk mitigation plans.
- Trains clients in proper computer security measures and prevention.
- Provides support for all vulnerability and compliance scan tool applications and modules (pre-built and customized).
- Develops workflows and customizes, implements, and maintains the aforementioned applications.
- Develops and updates standard operating procedures (SOPs) and provides training on existing and new technologies to Government personnel.
- Provides process and operations guides.
- Provides technical support in the daily operations and evaluation of existing security tools, products, and future capabilities, including:
- Security Log Management
- Account Management
- Asset Management
- Vulnerability Management
- End Point Security
- Related network security tools
- Maintains operational oversight and manages Command-level and privileged user accounts for the Enterprise using provided Enterprise tools.
- Prepares for and conducts customer briefings, attends and provides minutes on Technical Exchange Meetings (TEMs), and provides status reports on cybersecurity activities.
- Develops information systems security studies and reports that address areas of information system security concerns.
- Ensures cybersecurity requirements are incorporated in system development and sustainment activities.
- Provides consultant services in all areas of information system security, including physical, administrative, personnel, computer, operations, and industrial security.
- Provides security documentation and reports within specified timeframes.
- Monitors and reports, in accordance with IC Directives and AF BluSCI policy, the status of security measures established by the Director of National Intelligence (DNI) and related authorizing officials.
- Maintains cybersecurity, system security, and sustainment programs following all applicable ICD and National Institute of Standards and Technology (NIST) guidance.
- Creates, edits, and reviews security accreditation and authorization packages for the AF SCI Enterprise, adhering to the RMF process and inputting data into XACTA.
- Reviews logical network drawings, configurations, and control parameters to ensure they are current.
- Reviews documentation required to certify new hardware and software systems for deployment.
- Monitors and administers the vulnerability and compliance scan tool.
- Reviews AF SCI change proposals for security, interoperability, accreditation, and authorization issues or vulnerabilities.
- Performs vulnerability and compliance assessments, conducts security tests and evaluations.
- Monitors and reviews Information Assurance Vulnerability Alerts (IAVA) and Information Assurance Vulnerability Bulletins (IAVB).
- Tracks and provides results to the appropriate Government entity for review in accordance with standard operating procedures.
- Monitors and reports mandated Federal Information Security Management Act (FISMA) statistics for the AF SCI Enterprise.
- Provides quarterly reports to the appropriate Government entity in accordance with IC Directives and AF SCI policy.
Requirements
- High School diploma with 6-9 years of relevant experience (or commensurate experience).
- Current TS/SCI clearance.
- Current ITAM Level 2 Certification.
- Strong understanding of RMF workflow tools like eMASS or Xacta.
- Knowledge of programs working within AF SCI network rules and guides.
- Experience with network management tools, network engineering principles, and network analysis.
- Expert understanding of the A&A process.
- Expert understanding of current computer security requirements and compliance.
- Expert ability to maintain System Security and Risk Mitigation plans.
- Excellent written and verbal communication skills.
Pay
USD $105,000.00 - USD $110,000.00 per year.