ArlingtonVARecruiter Since 2001
the smart solution for Arlington jobs

Senior - Information Systems Security Engineer (ISSE) (TS/SCI)

Company: KaylaTek -
Location: Arlington
Posted on: March 18, 2023

Job Description:

Come join our growing team with a 21st Century Vision! At KaylaTek, we understand that the key to our success is the quality of the people we employ. Our focus is not just on jobs, but on building and enhancing your career through ongoing professional development, training, and high quality of life. Our team members choose KaylaTek for a number of reasons including our competitive compensation and benefit packages, dedication to education, as well as our outstanding service. Our Grow Strong Vision encompasses a place for employees to grow, learn and feel a sense of belonging, not just a place to work.

Employee Benefit Offerings

Medical, Dental, Vision, 401(k) with company matching, Short-Term and Long-Term Disability, Life and AD&D Insurance, Paid Time Off, 11 Paid Holidays, Employee Assistance Program (EAP), Professional Development Program and much more.

Annual Salary Range

$158,030.69 - $161,012.41

The pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities.

KaylaTek is seeking an experienced Senior Information Systems Security Engineer (ISSE) to support the AFNCR IT support contract's Cyber Risk Reduction Effort.

Job Site: Pentagon - 100% onsite

Shift Hours: Day-Shift; core support hours are 0600 -1800. This is a 24/7/365 support environment; off-hours response/support may be required, however only standard M-F core hours working time for current position.

Overview: Seeking high-level IT Professionals to provide cyber security and security engineering services for the National Military Command Center (NMCC) customer including system security engineering, cybersecurity risk assessments, and security architecture support.

The ISSE shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established cybersecurity standards and regulations and recommended mitigation strategies within the NMCC.

Roles and Responsibilities:

  • Participate as the primary security engineering representative on engineering teams for the design, development, implementation, evaluation, and/or integration of secure networking, computing, and enclave environments
  • Support security planning, assessment, risk analysis, and risk management
  • Experience with Risk Management Framework (RMF), NIST SP 800-53, Security Technical Implementation Guides (STIGs) and Security Content Automation Protocol (SCAP) Compliance Checker.
  • Prepare and review program documentation to include Risk Assessment Reports, Accreditation Packages, and security policy guides
  • Continuous Monitoring - Plan of Action & Milestones (POAMs) - Working with engineers to resolve formal security findings from the security assessment and/or the scans, and maintain the POAM.
  • Knowledge of SIPR and JWICS Assessment & Authorization (A&A) process.
  • Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation
  • Interact with the customer and other project team members
  • Support security planning, assessment, risk analysis, and risk management
  • Identify overall security requirements for the proper handling of Government data
  • Develop and implement security designs for new or existing network system(s). Ensure that the design of hardware, operating systems, and software applications adequately address cybersecurity requirements for the IS and Network Environment
  • Identify information protection needs for an IS and Network Environment
  • Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements
  • Develop approaches to mitigate IS and Network Environment vulnerabilities and recommend changes to network or network system components as needed
  • Work closely with system administrators to validate patching, AV definitions and other security tools are updated/not vulnerable
  • Review requests for software installation and conduct technical risk assessment on implementation of the software
  • Applies system security engineering expertise in one or more of the following:
    • Responsible for building, deploying and Patching HBSS Windows and ACAS RedHat Linux 7.9 and 8 servers.
    • Responsible for building, maintaining, and patching all ePO, Security Center, and Nessus servers.
    • Provides Security Center accounts for Vulnerability Managers to scan devices within ACAS.
    • Experience with ACAS scan results and how to remediate vulnerability findings.
    • Knowledge of the process of obtaining license for all HBSS ePO's and Tenable Security Centers.
    • Expertise in the process of obtaining HBSS and ACAS kick start ISO's from DISA.
    • Extensive knowledge of building virtual servers, deploying and patching all McAfee modules via the ePO, configuring McAfee policies for each environment
    • STIG'ing HBSS Windows OS, McAfee policies to comply with benchmarks (Not reviewing or confirming) ,STIG'ing ACAS RHEL servers
    • Ability to Run SCAP scans on Windows and RHEL servers.
    • Displays knowledge of updating RedHat 7.9 and 8 rpm's as they are released,
    • Setup RedHat yum local rpm repositories to patch offline ACAS servers.
    • Deploying Rogue sensors on each subnet, Identifying Rogue subnets and, rogue endpoints.
    • Able to troubleshoot Security Center and Nessus scanner issues. Required Qualifications:
      • Qualified candidates must possess a TS//SCI security clearance
      • Security + CE Certification Required
      • 7+ years of experience in understanding of all aspects of systems engineering, including design and architecture.
      • Demonstrated capability to identify security risks throughout information system network structures to include the Operating Systems, hardware, and various data transfer protocols.
      • Effective communication and presentation skills (i.e., ability to present ideas effectively in formal and informal situations in group and individual settings).
      • Strong planning, organizational, and time management skills (i.e., ability to effectively plan, organize, and prioritize work, and to control and follow up to assure work completion).
      • Demonstrated initiative (i.e. initiate appropriate action without being directed) and ability to work independently.
      • Strong interpersonal skills (e.g., ability to work effectively on teams, communicate effectively, work/interact effectively and amicably with people from diverse backgrounds and cultures and with diverse personal attributes).
        MUST BE A US CITIZEN

        The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified.

        COVID-19 RESPONSE

        All KaylaTek employees must be fully vaccinated (2 weeks past final dose) unless they are entitled to a legal accommodation. If you are not vaccinated, please consider getting your COVID-19 vaccination as soon as possible. If you have any questions, please contact your Talent Acquisition point of contact.

        COMMITMENT TO DIVERSITY

        KaylaTek is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.

        E-VERIFY AND BACKGROUND CHECKS

        In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. KaylaTek participates in the DHS e-Verify program. KaylaTek also conducts a background check on all candidates post offer though PROScreening LLC.

Keywords: KaylaTek -, Arlington , Senior - Information Systems Security Engineer (ISSE) (TS/SCI), IT / Software / Systems , Arlington, Virginia

Click here to apply!

Didn't find what you're looking for? Search again!

I'm looking for
in category
within


Log In or Create An Account

Get the latest Virginia jobs by following @recnetVA on Twitter!

Arlington RSS job feeds