Procession Systems
Procession Systems

60 Procession Systems Information Security Engineer Jobs Hiring Near You

... Information Security Modernization Act (FISMA) compliance, execution of the Risk Management ... The result of these efforts will be that the systems meet all the requirements for ATO approval ...

4272 Senior Security Engineer

Quantico, VA · On-site

$121K - $166K/yr

4272 Senior Security Engineer 4272 | Top Secret OVERVIEW: We are seeking a highly skilled Senior ... Industry security certification such as Certified Information Systems Security Professional (CISSP ...

We are seeking a dedicated Information System Security Engineer (ISSE) to join our team. This position is part of a talented technical team responsible for the ongoing development, operations, and ...

... and security of the underlying infrastructure that supports the forensic and investigative ... Active Top Secret (TS) clearance with eligibility for Sensitive Compartmented Information (SCI ...

next page

Showing results 1-20

4193 Information Systems Security Engineer (ISSE)

Huntsville, AL • On-site

Procession Systems
Recruiting and Staffing Services • 11 - 50 employees

Full-time

Re-posted 12 days ago


Key responsibilities

  • Develop and maintain security documentation such as Configuration Management Plans, Incident Response Plans, and Security Assessment and Authorization packages.

  • Review vulnerability scans and compliance reports to ensure patching and configuration adherence for on-premises and cloud systems.

  • Coordinate security incident responses and work with teams to address vulnerabilities and security findings.


Job description

4193 Information Systems Security Engineer (ISSE)
4193 | Top Secret
Job Description:
OVERVIEW:
We are looking for a dedicated Information System Security Engineer (ISSE) to join our team. This position is part of a talented technical team responsible for the ongoing development, operations and maintenance of several networked systems supporting digital forensic investigations running primarily on Windows and utilizing virtual and cloud environments. The ideal candidate must be a self-starter with strong work habits, is able to complete task independently while working as part of a team and have demonstrated career experience as an ISSO or ISSE and with the Federal ATO process.
GENERAL DUTIES:
  • Senior level capabilities regarding Information system security. Knowledgeable of current Information Assurance (IA) technologies to the architecture, design, development, evaluation, and integration of applications, systems, and networks to maintain the system security posture. Develops compliancy and standardization within the customer's policies regarding various information systems. Work closely with Government customers to ensure the confidentiality, integrity, and availability of systems, applications, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information systems security programs; infrastructure; application; Security Assessment and Authorization (SAA), IA policy directives (PD) and guides (PG); and IA Security tools (e.g., Tenable.io, Nessus Pro, NMap, etc.).
  • Have excellent verbal and written communication skills to be able to accurately relate requirements and document all within the appropriate security document and/or within the RMF system and coordinate with program, other system(s), and security personnel.
  • Prepare documentation from templates such as, but not limited to, Configuration Management Plan (CMP), Incident Response Plan (IRP), Information System Contingency Plan (ISCP), and Plan of Action and Milestones (POA&M) to ensure compliance with customer PDs and PGs and Federal IA requirements as well as coordinate review(s) and approvals.
  • Must be able to discern the program policies and procedures, identify areas that need work and bring up to management for resolution.
  • Identify IA vulnerabilities and coordinate with the Infrastructure and Development teams to correct, mitigated or apply for an exception via the POA&M processes.
  • Review vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance (on-premises and in the cloud (Azure preferred))
  • Prepares SAA package(s) to obtain and maintain an authority-to-operate (ATO), authority-to-test (ATT), or other SAA authority types for all systems and applications.
  • Attend Configuration Control Board (CCB) meetings and review all change requests for impact to the system/application security posture(s) and applicable Federal and customer PD and PG compliance requirements; and document decisions within the CMP.
  • Coordinate security incident and high priority compliance responses with the Enterprise Security Operations Center (ESOC).
  • Represent program security interests in various meetings within and outside of the program.
  • Schedule and conduct meetings with pertinent program personnel to address findings to determine appropriate path forward and document within the CMP and, if necessary, POA&M.
  • Coordinates with other system Information System Security Officers (ISSO) to ensure that their requirements for interconnection, policy and procedures are met and all documentation is provided and updated as necessary.
  • Ability to assess current and evolving security threats in an operational environment.
  • With an appropriate amount of Government PM guidance, works independently to carry out all technical requirements as directed by the Government PM, Information System Security Representative, Information System Security Manager, and Authorizing Official in a timely manner.

REQUIRED QUALIFICATIONS:
  • Ten (10) years of experience or more assessing and documenting results for system(s), infrastructure(s) and applications (on-premises and cloud (i.e., AWS GovCloud and/or Azure GovCloud)) against NIST SP 800-53 security controls and SP 800-171 Risk Management Framework (RMF) processes.
  • Bachelor of Science (B.S.) Degree in Computer Security or related field of study; (ISC)2 Information Security Certification(s) (e.g., CISSP, CAP, etc.); or in lieu of education, an additional five (5) years of relevant experience that addresses all requirements of the position.
  • Requires an Active Top Secret clearance and the ability to obtain an CI polygraph
  • Day to Day Expectations:
    • Experience working on an Agile team
    • Experience working with a federal law enforcement organization
    • Willingness to implement Lean principles, Agile engineering and DevSecOps
    • Desire longevity on the project.
    • Technical background desired, knowledge broader in scope.
    • Have an understanding of taclans, basic coding, and scripts.
    • Splunk and Tenable experience desired.
    • Need to be able to read technical diagrams, dataflows, create workflows, read network diagrams. Understand JRC and the 6 steps of the Risk Management Framework.
    • Have a team perspective, invite collaboration, the personality needs to be one of investment. Need to connect and to learn. Be function driven. They need to have an accountability to the program, be on time, personable, positive

DESIRED QUALIFICATIONS:
  • Experience in a cyber-risk and compliance management system (e.g., Xacta, RiskVision, etc.).
  • One (1) year experience or more configuring, performing, scheduling, reviewing, and assessing vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance on-premises and in the cloud (Azure preferred).
  • Technical background that will assist in assessing the NIST SP 800-53 security controls and gather evidence to support conclusions.
  • Knowledge of operating systems, network and application security to aid implementation of information security and assurance principles.
  • Knowledge of SPLUNK software and tools.
  • Knowledge of Taclane, encryption devices and COMSEC technology.

CLEARANCE:
  • Top Secret minimum

Job Details
City : Huntsville
State : Alabama

Procession Systems logo

About Procession Systems

Sourced by ZipRecruiter

Procession Systems, based in Reston, Virginia, United States, is an industry leader operating in the Information Technology Services sector. Established to address complex business and technology challenges, the company delivers innovative tech solutions for government entities, primarily focusing on systems integration and software development. Procession Systems takes pride in their commitment to quality, responsiveness, and results, geared towards improving public sector services and saving taxpayer dollars.

Industry

Recruiting and staffing services

Company size

11 - 50 Employees

Headquarters location

Reston, VA, US

Year founded

2016

Social media