Job Requirements
San Antonio, TX
Top Secret/SCI Polygraph Unspecified
Career Level not specified
$105,000 - $110,000
Job Description
GovCIO is currently hiring for a Jr Cyber Security Engineer i n support of the Air Force SCI network. This position will be located in San Antonio TX and will be an on-site position.
Responsibilities
Conducts risk assessments and provides recommendations for application design. Involved in a wide range of computer security issues including architectures, firewalls, electronic data traffic, and network access. Uses encryption technology, penetration and vulnerability analysis of various security technologies, and information technology security research. Prepares security reports for government agencies.
Correlates threat data from various sources to establish the identity and modus operandi of hackers active in client's networks and posing a potential threat. Provides the customer with assessments and reports facilitating situational awareness and understanding of current cyber threats and adversaries. Develops cyber threat profiles based on geographic region, country, group, or individual actors. Produces cyber threat assessments based on entity threat analysis. May provide computer forensic and intrusion support to high technology investigations in the form of computer evidence seizure, computer forensic analysis, data recovery, and network assessments. Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption.
Specifically, this position will:
Qualifications
High School with 6 - 9 years (or commensurate experience)
Required Skills and Experience
Posted Salary Range
USD $105,000.00 - USD $110,000.00 /Yr.
Responsibilities
Conducts risk assessments and provides recommendations for application design. Involved in a wide range of computer security issues including architectures, firewalls, electronic data traffic, and network access. Uses encryption technology, penetration and vulnerability analysis of various security technologies, and information technology security research. Prepares security reports for government agencies.
Correlates threat data from various sources to establish the identity and modus operandi of hackers active in client's networks and posing a potential threat. Provides the customer with assessments and reports facilitating situational awareness and understanding of current cyber threats and adversaries. Develops cyber threat profiles based on geographic region, country, group, or individual actors. Produces cyber threat assessments based on entity threat analysis. May provide computer forensic and intrusion support to high technology investigations in the form of computer evidence seizure, computer forensic analysis, data recovery, and network assessments. Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption.
- Performs a wide range of computer security duties, including architectures, firewalls, electronic data traffic, and network access.
- Participates in the certification and accreditation processes; performs technical vulnerability assessments of computer security.
- Engages in incident reporting and response support.
- Conducts ongoing monitoring of computer security requirements and compliance, maintains system security plans and risk mitigation plans.
- Trains clients in proper computer security measures and prevention.
Specifically, this position will:
- Provide support for all vulnerability and compliance scan tool applications and modules (pre-built and customized).
- Develop workflows and customize, implement, and maintain the aforementioned applications.
- Develop and update standard operating procedures (SOPs) and provide training on existing and new technologies to Government personnel. This is informal office training.
- Provide process and operations guides.
- Provide technical support in the daily operations and evaluation of existing security tools, products, and future capabilities. Tools shall include, but are not limited to: Security Log Management, Account Management, Asset Management, Vulnerability Management, End Point Security, and any related network security tools. Current tool sets are: Directory Resource Administration (DRA), Automated Compliance Assessment Solution (ACAS), System Center Configuration Manager (SCCM), Tanium, Host Base Security System (HBSS) and Service Now.
- Maintain operational oversight and manage Command-level and privileged user accounts for the Enterprise using provided Enterprise tools.
- Prepare for and conduct customer briefings, attend, and provide minutes on Technical Exchange Meetings (TEMs), and provide status reports on cybersecurity activities.
- Develop information systems security studies and reports that address areas of information system security concerns. Ensure cybersecurity requirements are incorporated in system development and sustainment activities. Provide consultant services in all areas of information system security, including: physical, administrative, personnel, computer, operations, and industrial security. Provide security documentation and reports within specified timeframes.
- Monitor and report, IAW IC Directives and AF BluSCI policy, the status of security measures established by the Director of National Intelligence (DNI) and related authorizing officials that protect and defend information and information systems, web-based services, remote hosted applications, discovery, storage, operating systems, public key infrastructure (PKI), and other information technology components and applications for the Enterprise.
- Maintain cybersecurity, system security, and sustainment programs. The contractor shall follow all applicable ICD and National Institute of Standards and Technology (NIST) guidance in performing day-to-day duties.
- Create, edit, and review security accreditation and authorization packages for the AF SCI Enterprise. Adhere to the RMF process. Input data into appropriate A&A tool. The current toolset used is XACTA. Review logical network drawings, configurations, and control parameters to ensure they are current. Review documentation required to certify new hardware and software systems for deployment.
- Monitor and administer the vulnerability and compliance scan tool.
- Review AF SCI change proposals for security, interoperability, accreditation and authorization issues or vulnerabilities.
- Perform vulnerability and compliance assessments. Conduct security tests and evaluations. Monitor and review Information Assurance Vulnerability Alerts (IAVA) and Information Assurance Vulnerability Bulletins (IAVB).
- Track and provide results to appropriate Government entity for review IAW standard operating procedures.
- Monitor and report mandated Federal Information Security Management Act (FISMA) statistics for the AF SCI Enterprise.
- Provide quarterly report to appropriate Government entity in accordance with IC Directives and AF SCI policy.
Qualifications
High School with 6 - 9 years (or commensurate experience)
Required Skills and Experience
- Clearance Required: Current TS/SCI
- Current ITAM Level 2 Cert
- Strong understanding of RMF workflow tools like eMASS or Xacta
- Knowledge of programs working within AF SCI network rules and guides
- Experience with network management tools, network engineering principles, network analysis
- Expert understanding of A&A process
- Possess an expert understanding of current computer security requirement and compliance
- Expert ability to maintain System Security and Risk Mitigation plans
- Excellent written/verbal communications skills
Posted Salary Range
USD $105,000.00 - USD $110,000.00 /Yr.
group id: 10384469
After the acquisition of Salient CRGT, we're excited to introduce the new GovCIO. As we evolve towards our next phase as a company, we’ve refreshed our brand to better position ourselves in the government marketplace.