
Cyber Sec Engineer II
Scientific Research Corporation
- Peterson Air Force Base, CO
- $87,000 per year
- Permanent
- Full-time
- Providing risk management and IT security services--Information Assurance (IA) support, and RMF Assessment & Authorization (A&A)
- Serving as a technical liaison between senior management, technical experts/engineers, and other stakeholders for Cybersecurity to facilitate: Plans of Action and Milestones (POA&M) maintenance and milestone tracking (mitigation statements), creation of diagrams, software and hardware lists, POA&Ms, Risk Assessment Reports (RARs), Special Publication (SP), System Security Plan (SSP), Ports, Protocols, and Services Management (PPSM), and A&A packages
- Assisting RMF accreditation process from cradle to grave, developing RMF package(s) for legacy and modernized IT architecture pursuant to Authorizations to Operate (ATO) for designated DoD systems
- Validating system security settings, risk monitoring, IA controls and countermeasures are in accordance with DoD standards
- Performing RARs, vulnerability assessments, analyzing/interpreting results from Assured Compliance Assessment Solution (ACAS) Scans, Security Content Automation Protocol (SCAP) scans
- Collaborating with engineers, and developers to create or modify authorization boundary diagrams, as well as hardware and software lists
- Conducting vulnerability assessments of information systems and mitigate/remediate the results
- Building trust with customers and fostering a focus on Cybersecurity with team members/stakeholders
- Seven plus (7+) years combined cybersecurity experience holding one or more of the following roles: ISSE, Network Engineer, or Systems Engineer
- Minimum of five (5) years of IT-related experience demonstrating competency with
- Attention to detail
- Customer service
- Oral communication
- Engineering
- Problem solving
- Bachelors Degree (e.g. Cybersecurity, Engineering, Computer Science, or related IT fields) and Active DoD 8570 Level II Certification (e.g. Security+ CE, CCNA Security, etc.)
- Knowledgeable with demonstrated cybersecurity experience in Risk Management Framework (RMF)
- Experience with RHEL and Windows/Windows Server
- Experience with ACAS, SCAP, and DISA STIGs/SRGs
- Experience with Splunk, Trellix HBSS, Config OS, Nessus ACAS, and WSUS a plus
- Experience with automation and/or scripting
- Experience with Citrix and Cisco
- Assessment & Authorization (A&A)
- Skilled in the use of Enterprise Mission Assurance Support Service (eMASS) and XACTA
- Skilled in compliance reporting with known vulnerabilities from alerts, advisories, errata, and bulletins
- Skilled in network security architecture concepts including topology, protocols, components, and principles with focus on producing deliverables in accordance with PPSM registration requirements and RMF processes
- Skilled with automation and systems engineering with a cybersecurity perspective
- Knowledge of cybersecurity principles and DoD requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Knowledge of IT security principles and methods (e.g., firewalls, demilitarized zones, encryption, zero trust)
- Knowledge of DoD cybersecurity tools i.e. Spunk, Trellix HBSS, Config OS, ACAS, etc.
- None