Senior Information Assurance Engineer
GovCIO · San Antonio, TX · 3 days ago
On-siteInformation Technology$125k/yrFull-time
This position is located in San Antonio, TX and is an on-site only role supporting the Air Force AFSCI network.
Responsibilities
- Design, test, and implement secure operating systems, networks, and database products.
- Conduct risk assessments and provide recommendations for application design.
- Address a wide range of computer security issues, including architectures, firewalls, electronic data traffic, and network access.
- Utilize encryption technology, penetration and vulnerability analysis, and information technology security research.
- Prepare security reports for government agencies.
- Participate in certification and accreditation processes; perform technical vulnerability assessments of computer security.
- Provide business continuity and disaster recovery support.
- Engage in intrusion detection and prevention; provide incident reporting and response support.
- Conduct ongoing monitoring of computer security requirements and compliance; maintain system security plans and risk mitigation plans.
- Train clients in proper computer security measures and prevention.
- Support all vulnerability and compliance scan tool applications and modules (pre-built and customized).
- Develop workflows and customize, implement, and maintain security applications.
- Develop and update standard operating procedures (SOPs) and provide informal office training on existing and new technologies to Government personnel.
- Provide process and operations guides.
- Provide technical support in the daily operations and evaluation of existing security tools, products, and future capabilities, including:
- Security Log Management
- Account Management
- Asset Management
- Vulnerability Management
- End Point Security
- Network security tools
- Maintain operational oversight and manage Command-level and privileged user accounts for the Enterprise using provided Enterprise tools.
- Prepare for and conduct customer briefings, attend and provide minutes for Technical Exchange Meetings (TEMs), and provide status reports on cybersecurity activities, including leadership briefs.
- Develop information systems security studies and reports addressing areas of concern.
- Ensure cybersecurity requirements are incorporated in system development and sustainment activities.
- Provide consultant services in all areas of information system security, including physical, administrative, personnel, computer, operations, and industrial security.
- Provide security documentation and reports within specified timeframes.
- Monitor and report, in accordance with IC Directives and AFSCI policy, the status of security measures protecting information and information systems.
- Maintain cybersecurity, system security, and sustainment programs following applicable ICD and NIST guidance.
- Create, edit, and review security accreditation and authorization packages for the AFSCI Enterprise, adhering to the RMF process and using XACTA.
- Review logical network drawings, configurations, and control parameters to ensure they are current.
- Review documentation required to certify new hardware and software systems for deployment.
- Monitor and administer the vulnerability and compliance scan tool.
- Review AFSCI change proposals for security, interoperability, accreditation, and authorization issues or vulnerabilities.
- Perform vulnerability and compliance assessments; conduct security tests and evaluations.
- Monitor and review Information Assurance Vulnerability Alerts (IAVA) and Information Assurance Vulnerability Bulletins (IAVB).
- Track and provide results to appropriate Government entities for review in accordance with standard operating procedures.
- Monitor and report mandated Federal Information Security Management Act (FISMA) statistics for the AFSCI Enterprise.
- Provide quarterly reports to appropriate Government entities in accordance with IC Directives and AFSCI policy.
Requirements
- High School diploma or equivalent with 9+ years of relevant experience (or commensurate experience).
- Current TS/SCI clearance required.
- Must possess one of the following certifications: CISSP, CISSP-ISSMP, CISM, FITSP-M, GCIA, GCIG, GICSP, GSLC.
- Strong understanding of RMF workflow tools like eMASS or Xacta.
- Strong working knowledge of programs operating within AFSCI network rules and guides.
- Experience with network management tools, network engineering principles, and network analysis.
- Expert understanding of the A&A process.
- Expert understanding of current computer security requirements and compliance.
- Expert ability to maintain System Security and Risk Mitigation plans.
- Excellent written and verbal communication skills.
Pay
USD $125,000.00 - USD $130,000.00 per year.