Secure Computing Engineer (Level 3, 4) - HAC - Colorado Springs, CO - Open Rank
GTRI is the nonprofit, applied research division of the Georgia Institute of Technology (Georgia Tech). Founded in 1934, GTRI has grown to more than 2,900 employees, supporting eight laboratories in over 20 locations and performing over $940 million of problem-solving research annually for government and industry. GTRI's researchers combine science, engineering, economics, policy, and technical expertise to solve complex problems for the U.S. federal government, state, and industry.
About the role
The Special Secure Computing Division (S2CD) fills the Information System Security Engineer (ISSE) and Common Control Provider (CCP) roles for GTRI Special Programs in accordance with the Joint SAP Implementation Guide (JSIG). S2CD works closely with Research Security’s Special Cyber Security division, GTRI project directors, and lab computer support representatives to provide secure computing resources for GTRI projects.
This role involves architecting, designing, implementing, and maintaining classified computer systems/networks and cybersecurity solutions for classified networks, including government enclaves. Responsibilities include identifying and defining cybersecurity objectives and controls, developing automated security validation toolsets, conducting risk assessments, performing vulnerability analysis, integrating architectural features, and providing incident response using advanced forensic tools.
Responsibilities
- Architect, design, implement, and maintain classified computer systems/networks and cybersecurity solutions.
- Identify and define new cybersecurity objectives and controls; develop and maintain automated security validation toolsets.
- Conduct system, network, or software risk assessments; perform vulnerability analysis of open source software.
- Integrate new architectural features into existing infrastructures; create cybersecurity architectural artifacts.
- Provide architectural analysis of cybersecurity features and relate existing systems to future needs and trends.
- Leverage advanced forensic tools and techniques for incident response; provide engineering recommendations.
- Resolve integration and testing issues; serve in a consultative role on GTRI systems and projects.
- Define cybersecurity controls for different systems and networks; monitor and respond to alerts.
- Interact, advise, and counsel internal staff, project directors, and external stakeholders on cybersecurity needs.
- Ensure cybersecurity needs are established and maintained for operations, including security requirements definition, risk assessment, and systems analysis.
- Support and maintain virtual infrastructure, servers, workstations, storage fabrics, heterogeneous operating systems, and networking infrastructure.
- Maintain backups, disaster recovery, and business continuity plans; perform routine maintenance and upgrades.
- Deploy new classified information systems to enhance GTRI’s capabilities.
- Design system architecture (compute, hardware/virtual, OS, storage, networking, security).
- Translate researcher IT needs into robust and scalable IT solutions/infrastructure.
- Contribute to Continuous Integration and Continuous Development (CI/CD) processes using DevOps and DevSecOps principles.
- Implement cross-domain data exchange and systems integration; use Infrastructure as Code.
- Manage virtual machines; validate security control configurations (e.g., STIGS, CMMC).
- Actively collaborate with customers and external teams; derive tasks from detailed requirements.
- Provide tasking to team members; conduct software and merge request code reviews.
- Act as the primary gatekeeper for infrastructure as code merges; ensure software adheres to coding standards.
- Support the creation and enhancement of organizational policies, standards, and procedures.
- Establish, assess, and oversee security and technical specifications for projects across Agile and traditional frameworks.
- Deliver expert cybersecurity guidance through requirement interpretation and risk-informed recommendations.
- Create project plans, execute tasks, monitor progress, and develop risk mitigation strategies.
- Maintain adherence to NIST Risk Management Framework (RMF) control requirements.
- Establish security protocols for development and testing phases, including network devices, databases, and OS components.
- Communicate technical information in business-friendly language; conduct vendor negotiations.
- Utilize project management platforms (e.g., Jira, Microsoft Project) and requirements management solutions.
- Convert strategic goals into actionable integration roadmaps; coordinate among engineering teams and external collaborators.
- Orchestrate multi-disciplinary initiatives to integrate project elements, ensuring conformance with specifications and timelines.
Requirements
- Experience with deploying and administering software applications.
- Experience with Active Directory management, Group Policy Management, and Windows Server Update Services.
- Experience managing, administering, and updating systems under the Risk Management Framework.
- Experience with system hardening techniques, including Security Technical Implementation Guidelines.
- Ability to obtain and maintain DoD Directive 8570.1 IAT Level II compliance within 6 months of hire.
- Ability to obtain Top Secret, SCI, and SAP access.
- U.S. Citizenship required due to federal government research contracts.
Qualifications
- 5 years of related experience with a Bachelor’s degree in Information Technology, Cybersecurity, or related field.
- 3 years of related experience with a Master’s degree in Information Technology, Cybersecurity, or related field.
- 0 years of related experience with a Ph.D. in Information Technology, Cybersecurity, or related field.
Preferred Qualifications
- Active Top Secret Clearance.
- Knowledge of Active Directory management, PowerShell scripting, Group Policy Management, and Windows Server Update Services.
- Knowledge of Windows 11 & Windows Server management, Red Hat Enterprise Linux, Cisco IOS management.
- Knowledge of the Risk Management Framework.
- Knowledge of system hardening techniques, including Security Technical Implementation Guidelines.
Pay
$119,790 - $166,100
Benefits
Comprehensive benefits include Health & Welfare, Retirement Plans, Tuition Reimbursement, Time Off, and Professional Development. More details can be found at GTRI Benefits.