Information Assurance/Security Engineer
Job Description
The Information Assurance/Security Engineer will support security engineering and information assurance activities for the Government’s Assessment and Authorization (A&A) process, helping maintain Authority to Operate (ATO) and Authority to Connect (ATC) for mission applications and services. The role covers security control design, implementation oversight, and security testing documentation across system and application lifecycles.
Responsibilities
- Provide security engineering and information assurance support to the Government A&A process to maintain ATO and ATC for mission applications and services.
- Design, develop, monitor, and document security controls, security testing, security reporting, and plan of actions and milestones (POA&Ms) across system and application lifecycles.
- Contribute security engineering design inputs, participate in security design reviews, and provide security best-practice guidance for technical and change requests.
- Configure and validate secure systems and physical controls, and test security products and systems to identify security weaknesses.
- Maintain XACTA security records for supported systems.
Requirements
- Clearance: Top Secret security clearance, CI poly eligible.
- Education: Bachelor’s Degree in computer science, engineering, or similar technical field (an additional 4 years of relevant experience may be substituted for the degree).
- Certification: 8570 compliance (IAT Level 2) such as CompTIA Security +.
- Experience: Ideal candidates have 6 years of hands-on experience, including expertise in information assurance and/or ATO support for Classified DoD or IC environments.
- Experience documenting and assessing security controls in CentOS/RHEL Linux environments, along with Cisco Networks and VDI and/or virtual server hosting environments.
- Experience supporting, securing, and delivering hardware and software updates and enhancements through security assessment and authorization, including production readiness reviews.
- Demonstrated documentation writing for security plans, tests, and reports.
- Ability to demonstrate strong teamwork, communication (verbal and written), and presentation skills.
- Demonstrate strong initiative to accept new technical challenges in complex security engineering assignments.
Technologies
- CentOS/RHEL
- Cisco Networks
- VDI
- Virtual server hosting environments
- CompTIA Security +
- XACTA
- NiFi data flows
- Apache Tomcat webservices
Preferred Qualifications
- Master’s Degree.
- Certified Information Systems Security Professional (CISSP).
- Cisco Certified Network Professional (CCNP) certification(s).
- DoD or Intelligence Community (IC) IT and Application service delivery.
- Full lifecycle A&A process for classified infrastructure and application service delivery.
- ATO process management through XACTA.
- Agile software development.
- Supporting NiFi data flows.
- Supporting Apache Tomcat webservices.
- Cross domain solutions.
Benefits
- Generous cost sharing for medical insurance for the employee and dependents.
- 100% company paid dental insurance for employees and dependents.
- 100% company paid long-term and short-term disability insurance.
- 100% company paid vision insurance for employees and dependents.
- 401k plan with generous match and 100% immediate vesting.
- Competitive Pay.
- Generous paid leave and holiday package.
- Tuition and training reimbursement.
- Life and AD&D Insurance.