Security Engineer/ICS Specialist (Cybersecurity Engineering)

SECURESOFT TECHNOLOGIES LLC
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$120,000.0 - $135,000.0
Working hours
Regular working hours
Job source

Tech stack

Systems Engineering Cyber Security Information Systems Security Architecture Professional Software Vulnerability Management Information Technology Tenable Nessus CIS Benchmarks Vulnerability Analysis

Job description

SecureSoft Technologies is seeking a Security Engineer to support cybersecurity engineering activities for the U.S. Coast Guard Waterways Commerce Cutter (WCC) Program. The Security Engineer will assist with implementing secure architectures, hardening systems, supporting RMF activities, and ensuring compliance with federal cybersecurity requirements., * Design, implement and support secure ICS system architectures supporting ATO objectives.

  • Develop and maintain ICS security engineering documentation.
  • Determine, select and perform DISA Security Technical Implementation Guides (STIG) implementation and system hardening for ICS components of the WCC program.
  • Conduct vulnerability assessments and coordinate remediation efforts.
  • Implement and Support OT and ICS Cybersecurity configurations
  • Review system configurations for compliance with security baselines.
  • Implement all relevant STIG security controls in ICS environments
  • Support vulnerability management using enterprise scanning tools.
  • Collaborate with infrastructure, network, and application teams.
  • Support continuous monitoring activities.
  • Participate in RMF documentation development.

Requirements

This role is ideal for professionals with strong systems engineering, security architecture, and vulnerability management experience., * Bachelor’s degree in information technology, Engineering, Cybersecurity, or related field.

  • Minimum experience of 6 years supporting RMF Assessment & Authorizations (A&A), and cybersecurity engineering in ICS environments.
  • Considerable experience implementing secure OT/ICS architecture
  • Considerable experience with DISA STIG implementation.
  • Familiarity with vulnerability management tools.
  • Experience implementing security controls including ICS and OT controls
  • Considerable experience with NIST SP 800-53 Revision 5, and federal cybersecurity standards including, * Strong Experience supporting DHS, Navy, or USCG ICS/OT programs.

Benefits & conditions

$120,000 - $135,000 a year - Full-time, Pulled from the full job description

  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Paid holidays, Compensation: Annual W2 of $120K - 135K or 1099 hourly rate of $60 - $67.5, depending on experience, o NIST SP 800-82, NIST SP 800-172 and NIST SP 800-171

o DoDI 8510.01 (RMF) and DoDI 8500.01

o DHS 4300A and relevant USCG cybersecurity guidance

o Identification of Applicable DOD STIGs/SRGs, and IAVM Support

  • DoDI 8551.01 - PPSM
  • COMDTINST 5500.13I- Cybersecurity policies for the Coast Guard including guidance and requirements for CG Systems and technologies below the system level in alignment with the Department of Defense (DoD) Risk Management Framework (RMF) and the references.
  • Strong understanding of Operating Systems and ICS/OT Applications security.
  • Excellent troubleshooting skills
  • US Citizenship

Required Certification

  • DoD 8140 Series 631 or 652 Advanced-Level Certification
  • CISSP-ISSAP, CISSP-ISSEP, or CISSP-ISSMP, * Competitive salary
  • Health, dental, and vision insurance
  • Paid time off and federal holidays
  • 401(k) with company match (if applicable)
  • Professional development and certification support
  • Opportunities to work on mission-critical federal cybersecurity programs

Pay: $120,000.00 - $135,000.00 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all