Education: Bachelor's degree or related field
- Overseeing the security and coordinating risk management by identifying requirements for documentation with system categorization, the System Security Plan (SSP), and systems risk assessment as required under NIST 800-53/53A.
- Function as the go-to person for security questions and needs while supporting the customer in-house as well as external stakeholders.
- Assessing system compliance with NIST requirements and identifying vulnerabilities in systems and evaluating planned remedial actions based upon those requirements.
- Participating in change management by reviewing change requests and assessing the security impact of proposed changes and coordinating those changes with the ISSM.
- Work closely with stakeholders, developers, and external teams including customer security managers (ISSMs), organizational leadership, and key personnel to maintain security posture.
- Knowledge in assessing security considerations for Artificial Intelligence (AI) solutions, including secure deployment, risk management, data protection, and compliance with enterprise cybersecurity requirements.
- Lead comprehensive technical evaluations of cloud-based applications and systems, focusing on secure configurations across PaaS, SaaS, and IaaS environments.
- Strong understanding of cloud providers implementing Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud technologies to implement cloud security best practices.
- Utilize audit tools such as Elasticsearch or Splunk SIEMs, and IDS/IPS for monitoring and alerting.
- Utilize industry-standard vulnerability assessment tools such as Rapid7, Nessus, and Web Inspect to identify, analyze, and remediate system and application vulnerabilities
- Work closely with Common Control Provider (CCP)
requirements and methodology.
- Bachelors degree in computer engineering, compute science, cybersecurity, or a similar degree, or 5-8 years of relevant work experience.
- 5 years of demonstrated cybersecurity expertise.
- Experience assisting the customer with decisions impacting the security posture and compliance of their systems and networks with requirements as documented in NIST 800-53 and its revisions.
- Verbal and written communication skills that demonstrate technical cybersecurity concepts in a clear and concise manner.
- Support control implementation assessment and reporting and monitoring process using cybersecurity and assessment management systems.
- Ability to work both independently and in a team environment.
- Demonstrated history of technical aptitude with vulnerability and risk assessment tools
- Strong understanding of methodologies for researching and documenting software and hardware vulnerabilities
- Demonstrated skill documenting process and procedures in CONOPS, system security, contingency, configuration management and other plans
- Knowledge of the customer's organization, network systems, processes and procedures
*A candidate must be a US Citizen and requires an active/current TS/SCI with Polygraph clearance.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Search ISSO/Security Engineer (TS/SCI with Poly Required) jobs near Chantilly, VA → Browse all live jobs
This posting was published by GCI on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.