Principal Information Systems Security Engineer (ISSE)
KBR Careers · Beavercreek, OH · 1 mo ago
Information TechnologyFull-time
Position Summary
The selected candidate will serve in a Senior ISSE role and perform tasks related to Assessment & Authorization (A&A) and cybersecurity under Direct Hire Authority (DHA) to obtain and maintain Authorizations to Operate (ATOs) for assigned DoD medical systems (i.e., applications, networks, devices).
Key Responsibilities
- Serve as Subject Matter Expert (SME) on one or more technologies/skills related to A&A activities
- Conduct risk and vulnerability assessments of information systems to identify vulnerabilities, risks, and protection needs
- Provide solutions to complex problems that require the regular use of expertise and creativity
- Lead and participate in regular A&A status meetings with senior government and contract personnel to facilitate progress and address potential issues of RMF system efforts
- Participate in sessions aimed at identifying, planning, and executing strategies in response to emerging cybersecurity/RMF policies
- Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes
- Lead and/or attend meetings with SDD stakeholders to discuss statuses of efforts
- Assess system compliance against NIST, DoW, and DHA security requirements to include the NIST 800-53 controls, DISA Security Technical Implementation Guides (STIGs), and DISA Security Requirements Guides (SRGs)
- Produce evidence as necessary to support compliance status of NIST, DoW, and DHA security requirements
- Analyze vulnerability scans of information systems and assist in remediation tasks
- Submit weekly reports to DHA leadership regarding system/program status
- Develop, update, and/or review RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
- Cook up with other system SMEs to identify and develop authorization boundary diagrams, architecture diagrams, and hardware and software inventories
Qualifications
- Required: Bachelor’s Degree and fifteen (15) years of experience with Cybersecurity / Information Technology, or in lieu of a degree eighteen (18) years of hands-on experience with Cybersecurity / Information Technology
- Active TS/SCI clearance is required
- Must have experience working with Special Access Programs (SAPs)
- DoD 8570-compliant
- Demonstrated expert-level experience with Risk Management Framework (RMF) policy development, process improvement, and strategy implementation
- Demonstrated expert-level experience with DISA STIGs and SRGs
- Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes
- Experience with Assured Compliance Assessment Solution (ACAS)
- Experience in assessing systems using NIST 800-53, DISA STIGs/SRGs, and ACAS
- Deep familiarity and experience with the DoW tool eMASS
- Experience working within DoW (experience under DHA a plus)
- Excellent customer service and organization skills
- Excellent oral and written communication skills
- Familiarity with NIST publications
Desired Experience
- Experience working under DHA
- Knowledge in Continuous Monitoring and Risk Scoring (CMRS)
- Experience with Fortify, WebInspect, and/or AppDetective