Info Security Associate Apply
Description:
- Perform or review technical security assessments of computing environments to identify points of vulnerability, and non-compliance with Cybersecurity standards, and recommend mitigation strategies.
- Validate and verify system security requirements definitions and analysis, and establish system security designs.
- Design, develop, implement, and/or integrate Cybersecurity systems and components, including those for networking, computing, and multi-enclave environments with varying data protection/classification requirements.
- Build Cybersecurity measures into systems deployed to operational environments.
- Assist architects and systems developers in implementing appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
- Support security architecture development and enforce trusted relationships among external systems and architectures.
- Assess and mitigate security threats/risks throughout the system development life cycle.
- Contribute to security planning, assessment, risk analysis, risk management, certification, and awareness activities for system and networking operations.
- Review certification and accreditation (C&A) documentation and provide feedback on content completeness and compliance.
- Support security authorization activities in compliance with NSA/CSS Information System Certification and Accreditation Process (NISCAP), DoD Risk Management Framework (RMF), NIST RMF, and NSA/CSS business processes for security engineering.
Position Responsibilities:
- Act as the primary security engineering representative on engineering teams for designing, developing, implementing, evaluating, and/or integrating secure networking, computing, and enclave environments.
- Apply Cybersecurity policy, procedures, and workforce structure knowledge to design, develop, and implement secure environments.
- Interact with customers and project team members.
- Represent security engineering in designing, developing, implementing, evaluating, and integrating Cybersecurity architectures, systems, or components.
- Support the Government in enforcing trusted relationships among external systems and architectures.
- Support security planning, assessment, risk analysis, and risk management.
- Identify overall security requirements for proper Government data handling.
- Provide security planning, assessment, risk analysis, and risk management.
- Perform system or network designs covering multiple enclaves, including those with varying data protection/classification needs.
- Recommend system-level solutions to address security requirements.
Job Requirements:
Requirements:
- Twelve (12) years of experience as an ISSE on programs/contracts of similar scope, type, and complexity, with recent experience within the last five (5) years in Cybersecurity principles and technology (e.g., access/control, authorization, identification/authentication, PKI, network/enterprise security architecture).
Education/Experience:
- Bachelor's degree in Computer Science, Information Assurance, Information Security System Engineering, or related field.
- In lieu of a Bachelor's degree, four (4) additional years of ISSE experience may be substituted.
- DoD 8570.01-M compliance with IASAE Level 2 required.
Clearance:
- TS/SCI with FS Poly
Work Environment:
- Operates in a professional office environment, routinely using standard office equipment (computers, phones, photocopiers, scanners, filing cabinets, and fax machines).
Physical Demands:
- Primarily sedentary role with occasional filing; requires the ability to move files/boxes, open filing cabinets, bend or stand as necessary.
- Ability to lift up to 40 lbs.
Mental Demands:
- Reading, effective verbal and written communication, maintaining emotional control and professionalism.