Security Solution Application Support
Location: O’Fallon, Illinois, Scott Air Force Base
Required security clearance: Secret
Position type: Full-time, 40 hours per week
About the role
The United States Transportation Command (USTRANSCOM) located at Scott Air Force Base (AFB), IL, is one of 11 Unified Combatant Commands (UCC). USTRANSCOM provides command and control (C2) for the synchronized transportation, distribution, and sustainment of personnel and assets, making possible the projection and maintenance of national power wherever needed with speed and agility, high efficiency, and a high level of trust and accuracy. USTRANSCOM operates the Common Computing Environment (CCE) surrounded by a network defense infrastructure.
The USTRANSCOM CCE, supported by TCJ6 and USTRANSCOM Component Commands, is comprised of several operating systems on clients and servers, both physical and virtual. The diversity of applications riding on the USTRANSCOM CCE (C2 systems, information management systems, mail/message systems, and security systems) increases the complexity and difficulty to integrate new system requirements. The information security infrastructure operating with the USTRANSCOM CCE is a unique integration of products demanding a high degree of technical skills and understanding.
The Security Solution Application Support position will perform administration, integration, tuning, and optimization of cybersecurity defense tool suite applications supporting network and host-based defense capabilities. This position will support the integration of USTRANSCOM cybersecurity defense tool suites with capabilities provided via the JIE/ Joint Regional Security Stacks (JRSS), DoD Enterprise services and capabilities, and other products that may be directed or procured. This position will also protect and defend USTRANSCOM’s NIPRNet and SIPRNet enclaves, including cloud and on-premises environments, through the application of cybersecurity defense tools and processes.
About us
BTAS is a woman-owned small business founded in 1995, located near Wright-Patterson Air Force Base in Beavercreek, OH. We have earned national and regional awards in the Department of Defense for our proven IT, Engineering, and Program Management capabilities. We are committed to working with exceptional quality and professionalism to deliver excellence to our customers, while providing our employees with a stimulating and satisfying work environment as we collaborate with teammates to achieve common goals.
Responsibilities
- Perform administration, integration, tuning, and optimization of cybersecurity defense tool suite applications supporting network and host-based defense capabilities.
- Support the integration of USTRANSCOM cybersecurity defense tool suites with capabilities provided via the JIE/ Joint Regional Security Stacks (JRSS), DoD Enterprise services and capabilities, and other products that may be directed or procured.
- Protect and defend USTRANSCOM’s NIPRNet and SIPRNet enclaves, including cloud and on-premises environments, through the application of cybersecurity defense tools and processes.
- Provide on-site support at locations other than Scott AFB on an as-needed basis and as directed by the Government.
- Support CSSP security solutions, processes, and procedures IAW DoD policy and USTRANSCOM Government direction.
- Provide cybersecurity solution support, including installation, configuration, operation, and system administration of the Government-furnished cybersecurity solution tool suites.
- Provide support on-site at Scott AFB from 0730 to 1630 local time, Monday through Friday, during scheduled maintenance periods, and on-call after duty hours with a one (1) hour response time to begin work.
- Perform installation of cybersecurity solution tools IAW USTRANSCOM processes (e.g., change management and RMF). This includes:
- Requesting/coordinating hardware/software procurement (including lifecycle upgrades).
- Performing project management using government-provided requirements management tools and schedules.
- Building and configuring systems to be IAVM and STIG compliant.
- Performing functional testing.
- Developing system assessment and authorization documentation.
- Requesting security evaluations and remediating findings.
- Ensuring performance optimization.
- Verifying requisite content and overall visibility is achieved.
- Performing operational deployment.
- Perform day-to-day operation and maintenance of cybersecurity defense tool suites IAW USTRANSCOM Configuration and Change management processes.
- Maintain the existing configuration and integrity of the cybersecurity defense tool suites IAW applicable DOD, USCYBERCOM, JFHQ DODIN, DISA, and USTRANSCOM policies and instructions.
- Perform application support, including troubleshooting, maintenance, updates, testing, customer support, incident resolution, software configuration management IAW USTRANSCOM policies and procedures.
- Implement/enforce whitelisting capabilities, compliance management to differing requirements (DISA, USTRANSCOM, CYBERCOM, etc.), and software problem diagnosis and resolution.
- Create security assessment and authorization documentation, and support system security compliance, remediation, and validation activities (e.g., remediate vulnerability and configuration compliance scan findings; create and submit POA&Ms).
- Utilize the USTRANSCOM tool suites and capabilities to install software or firmware patches and upgrades and ensure application and operating system versions are current and up to date on security vulnerability patches.
- Operate and maintain a service assurance capability for cybersecurity defense service tools.
- Maintain and enhance, where necessary, the security posture of USTRANSCOM’s network environment.
- Provide risk-based recommendations to the government related to change requests for cybersecurity defense configurations (e.g., HBSS/ESS rule exemptions, HBSS/ESS rogue system coverage resolution, Tanium content packs, EDR Agent updates).
- Ensure cybersecurity defense tools are configured IAW USCYBERCOM, JFHQ DODIN, and USTRANSCOM guidance (e.g., HBSS/ESS rule exemptions; Tanium content packs; EDR Agent updates; anti-malware software, engines, and signatures).
- Troubleshoot user and program-related issues associated with cybersecurity defense tools and provide recommendations to the government for resolution.
- Provide compliance data to the government in response to USCYBERCOM/JFHQ DODIN orders; develop and update POA&Ms.
- Submit requests for exemption to policy/direction that cannot be complied with IAW prescribed DoD policy/instruction.
- Ensure changes impacting Ports, Protocols, and Services Management (PPSM) are properly documented IAW USTRANSCOM Configuration and Change management and RMF processes.
Requirements
- 5+ years of experience with Cybersecurity Technology.
- IAT Level II certification, such as CompTIA Security+ (ce), CySA+, etc.
- CSSP-IR certification, such as CompTIA PenTest, EC-Council Certified Ethical Hacker (CEH), etc.
- Tanium/Crowdstrike or other security tool administration experience.
Work environment
This job operates in a professional office environment. This role routinely uses standard office equipment.
Physical demands
- Must be able to operate a computer and other standard office equipment.
- Must be able to remain in a stationary position 80% of the time.
Travel
Minimal travel, 5 – 10%.
Benefits
A comprehensive benefits program, including:
- Paid time off.
- Federal holidays.
- Health coverage.
- 401K plan with generous company match.
- Eligibility for participation in the BTAS Business Development Bonus Program.