Job Requirements
Aurora, CO
Top Secret/SCI Polygraph
Mid Level Career (5+ yrs experience)
$155,000 - $194,000
Job Description
This position requires onsite work in Aurora, CO and an active TS/SCI w/POLY security Clearance. Candidates who do not hold this clearance are not eligible for hire.
Solidus has an immediate career-growth opportunity for a collaborative and highly skilled Information Systems Security Engineer. The ISSE will join our Tech Ops IV program engineering team in Aurora, CO, supporting a high priority 24x7 operational system. The ISSE performs core activities to include providing certified services and support for Information Assurance/Program Protection efforts for compliance with governing DoD Cybersecurity directives. This position will support activities of the program to target, assess, and report risks and vulnerabilities of Intelligence Community organization systems to provide senior decision makers with actionable data to make strategic decisions. The ISSE shall perform, or review, technical security assessments of computing environments to identify points of vulnerability and non-compliance with established Information Assurance (IA) standards, regulations and recommend mitigation strategies. This position is responsible for the maintenance and administration of multiple domains, including a 24/7 operational system and a test facility. Must be willing to occasionally provide after hour support to the 24/7 operational system.
Day in the Life:
Required Qualifications & Experience:
Preferred Qualifications & Experience:
Benefit selection, customer contractual specifications, relevant work experience, skills, competencies, certifications, and clearance status will influence the final salary.
Full benefits: $155,000 to $194,000 annually
Reduced benefits (no medical, dental, vision): Up to $209,000 annually
What we will bring:
Solidus offers you an exciting opportunity to tackle the nation's greatest challenges applying innovation and expertise to produce cutting-edge results that have a long-lasting impact. We offer outstanding benefits, generous PTO and much more! Apply today to learn why Solidus has a 4.9/5 Star rating on Glassdoor!
Req ID:536
Solidus is an Equal Opportunity Employer and provides equal employment opportunities regarding all terms and conditions of employment to all employees and qualified applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. The Company will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application and interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.
Click to review - Federal Job Notices for Job Applicants
Please Note: Solidus does not accept applications from agencies, 3rd party vendors, or applications with incomplete information.
Solidus has an immediate career-growth opportunity for a collaborative and highly skilled Information Systems Security Engineer. The ISSE will join our Tech Ops IV program engineering team in Aurora, CO, supporting a high priority 24x7 operational system. The ISSE performs core activities to include providing certified services and support for Information Assurance/Program Protection efforts for compliance with governing DoD Cybersecurity directives. This position will support activities of the program to target, assess, and report risks and vulnerabilities of Intelligence Community organization systems to provide senior decision makers with actionable data to make strategic decisions. The ISSE shall perform, or review, technical security assessments of computing environments to identify points of vulnerability and non-compliance with established Information Assurance (IA) standards, regulations and recommend mitigation strategies. This position is responsible for the maintenance and administration of multiple domains, including a 24/7 operational system and a test facility. Must be willing to occasionally provide after hour support to the 24/7 operational system.
Day in the Life:
- Implement Information Assurance (IA) processes, provide guidance, and develop documentation throughout the system development life-cycle via the RMF tool in ServiceNOW
- Develop, implement, and document formal security policies and System Security Plans (SSP) throughout the program and monitor compliance to these policies during all phases of the Risk Management Framework (RMF) process
- Utilize Enterprise Security Services to provide analysis of vulnerabilities and compliance risks in ACAS, Enterprise IT audit logs in ArcSight and Splunk, McAfee Host-Based Security Services (HBSS), User Activity Monitoring (UAM), and Cyber Terrain Mapping (CTM) on 100+ nodes
- Monitor Heat Map Score matrix and evaluate cyber risk data, keeping the score at acceptable risk levels for the security categorization of the asset(s) and their Risk Evaluation Lanes (REL)
- Manage and deliver system authorization and accreditation packages, for 3 assets that span 3 different classification levels
- Review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.)
- Assess/calculate risk based on threats, vulnerabilities, and shortfalls uncovered in routine analyzation of Continuous Monitoring (ConMon) controls and provide those results as Body of Evidence (BoE) to be evaluated in 7, 30, 90 and 365 day increments as the control metrics require
- Direct activities required to remediate system-level information security weaknesses tracked via the FISMA (POA&M) process. Document the elements of the plans, milestones for correcting the weaknesses, and scheduled completion dates for the milestones, periodically reporting remediation progress as necessary
- Brief leadership, as needed, on the status of action items and/or results of activities affecting the security posture of the program
- Able to collaborate and communicate effectively with other system engineers, system administrators, software developers, and information assurance professionals
Required Qualifications & Experience:
- Active TS/SCI w/POLY clearance is required
- Bachelor's Degree
- Bachelor's Degree in Engineering, or related Science, Technology, Engineering, Mathematics (STEM) degree program.
- 10 years' experience in lieu of formal degree.
- Cultural fit amongst a collaborative team environment
- Minimum 5 years' experience, in a security position for the government or government contractor in the Intelligence Community (IC)
- A Bachelor's Degree in Information Technology, Information Systems Security, Cybersecurity, or related field
- DoD 8570.01 IAT level 2 or greater cybersecurity certification per DoD 8570.01
- Experience in security systems engineering involving Linux and CENTOS operation systems and application solutions in both stand-alone and LAN/WAN configurations
- Minimum of 10 years' related experience in Cybersecurity, Systems or Software Engineering, for the government or government contractor, if other than IC position
- Experience developing Security Authorization Requirements, performing vulnerability assessments, and implementing threat mitigation updates on embedded systems and products
- Experience configuring and hardening COTS components with STIGs
- Continuous Monitoring and Network monitoring experience
- Experience with product development including architecture, requirements, design, integration and testing
- Experience with compliance implementation of security requirements (i.e. Risk Management Framework and other A&A processes)
- Experience participating in technical reviews with both external and internal customers
- Coordinate with ISSO/ISSM to update POA&M and reflect open vulnerabilities associated with servers and workstations, develop remediation plans to include milestone completion dates and status updates, and include mitigation process for closed vulnerabilities.
- Participate in Configuration Control Board (CCB)
Preferred Qualifications & Experience:
- Experience using DISA Security Technical Implementation Guides (STIGs)
- Experience onboarding assets to centrally managed Enterprise solutions
- Experience conducting risk analysis on products and system components through review of CVEs, plugins, IAVAs
- Experience in conducting software due diligence with COTS/GOTS and proprietary solutions
- Positive, self-motivated individual who can complete tasks independently
- Experience with multi-level security solutions
- Experience working in Systems Engineering on complex embedded systems
- CISSP (ISC)²
Benefit selection, customer contractual specifications, relevant work experience, skills, competencies, certifications, and clearance status will influence the final salary.
Full benefits: $155,000 to $194,000 annually
Reduced benefits (no medical, dental, vision): Up to $209,000 annually
What we will bring:
Solidus offers you an exciting opportunity to tackle the nation's greatest challenges applying innovation and expertise to produce cutting-edge results that have a long-lasting impact. We offer outstanding benefits, generous PTO and much more! Apply today to learn why Solidus has a 4.9/5 Star rating on Glassdoor!
Req ID:536
Solidus is an Equal Opportunity Employer and provides equal employment opportunities regarding all terms and conditions of employment to all employees and qualified applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. The Company will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application and interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.
Click to review - Federal Job Notices for Job Applicants
Please Note: Solidus does not accept applications from agencies, 3rd party vendors, or applications with incomplete information.
group id: 10121974