Senior Information Systems Security Engineer (ISSE)
Summary
Senior Information Systems Security Engineer designing, developing, and integrating secure network and system architectures, focusing on building cybersecurity defenses, mitigating risks, and ensuring compliance with government standards like RMF for classified programs and Special Access Programs.
Description of Task to be Performed:
AnaVation is seeking an experienced cyber professional to join our team and support our mission critical customer in Reston, VA.As an ISSE, you will design, develop, and integrate secure network and system architectures. The role focuses on building technical cybersecurity defenses, mitigating life-cycle risks, and ensuring systems comply with government and industry standards like the Risk Management Framework (RMF)
Duties include but are not limited to:
- Provides technical expertise to ensure the network systems meet DIA C&A and IA requirements and are properly certified and accredited
- Responsibilities are full-time on customer’s onsite and will cover classified programs and Special Access Programs (SAP). No Telework.
- Designs, develops, and recommends integrated security system and physical control solutions that will ensure proprietary/confidential data and systems are protected
- Assist team in DIA’s Authorization and Accreditation (A&A) process using RMF across the design lifecycle for classified systems obtaining and maintaining Interim Authorization to Test (IATT), Authority to Connect (ATC) and Authorization to Operate (ATO)
- Offers technical engineering services for the support of integrated security systems and solutions, managing information-related risks effectively
- Works closely with the client during the strategic design process to translate security and business requirements into actionable technical designs
- Configures and validates secure systems and physical controls, and tests security products and systems to detect security weakness
- Develop comprehensive system test plans (STP) to assess the security posture of the information systems
- Analyze scan results and security findings to prioritize remediation efforts and implement corrective measures
- Participate in incident response activities and assist in the resolution of security incidents as needed
Required Qualifications:
- Clearance: Active TS/SCI Clearance with CI Polygraph
- Education & Years of Experience: Bachelor’s degree and 4 years of experience related to specific functional area (may substitute master’s degree in lieu of 2 years of experience along with substitute Bachelor’s degree for 4 years of experience.)
- Certifications: Hold or attain a CySA+ or equivalent IAT Level II certification.
- Experience and knowledge on:
- Exhibits advanced Windows administration capabilities and Linux proficiency for optimal system management
- Security credentials, certifications, and experience commensurate with the job description
- Practical experience deploying, maintaining, and troubleshooting security tools
- Demonstrates the ability to critically assess current practices, identify deficiencies, propose innovative solutions and effectively implement these improvements
- Thrives in a fast-paced, complex environment; displays exceptional poise and an unwavering commitment to hard work
- Displays excellent problem-solving abilities and attention to detail
- Experience with each of the following security tools: Assured Compliance Assessment Solution (ACAS), Trellix, Splunk, and Security Technical Implementation Guide (STIG)’s
- Collaborate with stakeholders to identify security requirements and ensure alignment with organizational objectives
- Stay abreast of the latest security trends, technologies, and best practices to continually enhance the security posture of the information systems
Preferred Qualifications:
- Familiar with tiered security environments (U, S, TS)
- Deep understanding of Trellix antivirus suite of products
- Knowledge of Splunk architecture and experience structuring multi-level queries
- Windows expert – capable of advanced Powershell scripting and general administrative functions
- Experience with one or more commercial government cloud service provider’s system accreditation process
- Experience as a Cybersecurity Control Assessor for SAP
- Experience with Ongoing Authorizations and Assessments
- Experience with C2S Cloud, or DevOpsSec
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance