Jobs · Information Technology · Ohio

Principal Information Systems Security Engineer (ISSE)

KBR Careers · Beavercreek, OH · 1 mo ago
Information TechnologyFull-time

Position Summary

The selected candidate will serve in a Senior ISSE role and perform tasks related to Assessment & Authorization (A&A) and cybersecurity under Direct Hire Authority (DHA) to obtain and maintain Authorizations to Operate (ATOs) for assigned DoD medical systems (i.e., applications, networks, devices).

Key Responsibilities

  • Serve as Subject Matter Expert (SME) on one or more technologies/skills related to A&A activities
  • Conduct risk and vulnerability assessments of information systems to identify vulnerabilities, risks, and protection needs
  • Provide solutions to complex problems that require the regular use of expertise and creativity
  • Lead and participate in regular A&A status meetings with senior government and contract personnel to facilitate progress and address potential issues of RMF system efforts
  • Participate in sessions aimed at identifying, planning, and executing strategies in response to emerging cybersecurity/RMF policies
  • Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes
  • Lead and/or attend meetings with SDD stakeholders to discuss statuses of efforts
  • Assess system compliance against NIST, DoW, and DHA security requirements to include the NIST 800-53 controls, DISA Security Technical Implementation Guides (STIGs), and DISA Security Requirements Guides (SRGs)
  • Produce evidence as necessary to support compliance status of NIST, DoW, and DHA security requirements
  • Analyze vulnerability scans of information systems and assist in remediation tasks
  • Submit weekly reports to DHA leadership regarding system/program status
  • Develop, update, and/or review RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
  • Cook up with other system SMEs to identify and develop authorization boundary diagrams, architecture diagrams, and hardware and software inventories

Qualifications

  • Required: Bachelor’s Degree and fifteen (15) years of experience with Cybersecurity / Information Technology, or in lieu of a degree eighteen (18) years of hands-on experience with Cybersecurity / Information Technology
  • Active TS/SCI clearance is required
  • Must have experience working with Special Access Programs (SAPs)
  • DoD 8570-compliant
  • Demonstrated expert-level experience with Risk Management Framework (RMF) policy development, process improvement, and strategy implementation
  • Demonstrated expert-level experience with DISA STIGs and SRGs
  • Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes
  • Experience with Assured Compliance Assessment Solution (ACAS)
  • Experience in assessing systems using NIST 800-53, DISA STIGs/SRGs, and ACAS
  • Deep familiarity and experience with the DoW tool eMASS
  • Experience working within DoW (experience under DHA a plus)
  • Excellent customer service and organization skills
  • Excellent oral and written communication skills
  • Familiarity with NIST publications

Desired Experience

  • Experience working under DHA
  • Knowledge in Continuous Monitoring and Risk Scoring (CMRS)
  • Experience with Fortify, WebInspect, and/or AppDetective

Similar jobs