user avatar

Information Security Systems Engineer

By Light Professional IT Services

Today
Top Secret/SCI
Unspecified
CI Polygraph
IT - Software
Fort Meade, MD (On-Site/Office)

By Light Professional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide.

Cole Engineering Services (CESI), a By Light company, is recognized as a premier provider of modeling and simulation (M&S) training solutions to the Federal Government and industry. Since 2004, CESI has been at the forefront of developing, maintaining, and integrating simulation-based training, serious gaming, technical services, training and other support in live, virtual, constructive, and gaming (LVCG) domains. CESI also designs, builds and runs infrastructure, platforms, applications and processes that enable cyber training for the integrated multi-domain force. Our vision is to become a worldwide full spectrum LVCG and cyber training/analysis developer, integrator and services provider.

Position Overview

The ISSE will conduct information system security engineering activities for new and existing systems to ensure cyber security and maintain compliance with all applicable Government cyber security requirements.

This position is located onsite, Annapolis Junction, MD.

Responsibilities

  • Defines information security requirements and their integration into information systems and its technology component through purposeful security design.
  • Develop and implement security designs ensurse the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM).
  • Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.
  • Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects.
  • Develops Security Test Procedure (STP), conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs.
  • Conducts risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborating with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed.
  • Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements.
  • Participates in Agile Planning Events to provide technical input.
  • Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering.
  • Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
  • Perform other duties as assigned.


Required Experience/Qualifications

  • 5+ years of information security experience as a contractor in the DoD and IC community.
  • Demonstrated experience in Liunx, Windows Server, and/or Networking Appliances.
  • Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage.
  • Demonstrated experience performing Systems Security tasks including Security Information and Event Monitoring, Endpoint Security, and Compliance and vulnerability scanning.
  • Demonstrated experience with creating and validating evidence for NIST security controls.
  • Bachelor's degree in a technical field or relevant experience.
  • DoD 8570 IAT Level III certification or ability to achieve certification within 6 months of start of employment.


Preferred Experience/Qualifications

  • Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems.
  • Possess a working knowledge of administrating servers, system and application security threats and vulnerabilities.
  • Experience extending existing applications in areas such as security, monitoring, task automation, continuous integration, deployment, and performance optimization.
  • Scripting in a Linux or Windows environment to support the various Cyber Security tools and applications required.
  • Experience providing guidance on vulnerability and malware remediation.
  • Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future.


Special Requirements/Security Clearance

Please note that pursuant to a Government contract, this specific position requires U. S. Citizenship status and a TS/SCI security clearance and ability to successfully pass a CI polygraph if requested by customer.

Occasional travel may be required up to 10% of the time.

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. The above is intended to describe the general contents of and requirements for the performance of this job

Salary Range

Based on the roles, responsibilities, and requirements, the projected pay range for this position is: $120,000 - $155,000.

The annual base salary provided is a guideline for this position and is not a guarantee of compensation or salary. When extending an offer, CESI also considers other variables such as (but not limited to) work experience, education, training, skill set, internal peer equity, clearance level, and market conditions. In addition, CESI provides an extensive selection of benefits and offerings to our employees.

Benefits Overview

CESI recognizes that our strength is our people. We support every employee as an individual to build strong teams across the enterprise. Our benefit package includes:
  • Medical, Dental & Vision Coverage
  • Wellness Program
  • 401(k) Matching
  • Employee Assistance Program
  • Life Insurance
  • Education & Training
  • Generous Leave Policy (11 Federal Holidays, PTO, Military Leave, Bereavement and Jury Duty)

Cole Engineering Services, Inc. is an equal opportunity employer. We consider qualified applicants without regard to race, color, creed, religion, national origin, sex, sexual orientation, gender identity and expression, political affiliation, age, marital status, disability, genetic information, veteran status, membership in an employee organization, or any other basis prohibited by federal, state, or local laws.
group id: RTX15e409
job ad image
Find By Light Professional IT Services on Social Media
Network Employers
user avatar
About Us
Founded in 2002 as a small family business, By Light has expanded to a large, diverse organization with more than 2,000 employees working with numerous Government and Commercial clients at locations around the world. Driven by a management team steeped in practical experience from Defense, Intelligence, Federal Healthcare, and Commercial sectors, we are trusted to provide reliable, cost-effective IT and Cyberspace Operations solutions to each customer on every project.
job ad2 image

By Light Professional IT Services Jobs


Job Category
IT - Software
Clearance Level
Top Secret/SCI