Information Systems Security Engineer II
Armada LTD
Philadelphia, PA, United States
14 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Configuration Management
Cyber Security
Information Systems
Networking Hardware
Microsoft Office
Windows Servers
Security Content Automation Protocol
Software Vulnerability Management
Computer Networking Systems
Software Troubleshooting
Information Technology
Plan of Action and Milestones
+1 more
Vulnerability Analysis
Job description
- The Information Systems Security Engineer II (ISSE II) shall assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans which include System Categorization Forms, Platform Information Technology (PIT) Determination Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagrams, Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
- The Information Systems Security Engineer II shall execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
- The Information Systems Security Engineer II shall identify and tailor IT and CS security control baselines based on RMF guidelines and categorization of the RMF boundary.
- The ISSE II shall perform Ports, Protocols, and Services Management (PPSM).
- The ISSE II shall perform IT and CS vulnerability-level risk assessments.
- The ISSE II shall execute security control testing as required by a risk assessment or annual security review (ASR).
- The ISSE II shall mitigate and remediate IT and CS system level vulnerabilities for all assets withing the boundary per STIG requirements.
- The ISSE II shall develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
- The ISSE II shall develop and maintain system level IT and CS policies and procedures for respective RMF boundaries and/or guidance provided by the command ISSMs.
- The ISSE II shall implement and assess STIG and SRGs.
- The ISSE II shall perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Evaluate STIG.
- The ISSE II shall deploy security updates to Information System components.
- The ISSE II shall perform routine audits of IT system hardware and software components.
- The ISSE II shall maintain inventory of Information System components.
- The ISSE II shall participate in IT change control and configuration management processes.
- The ISSE II shall upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
- The ISSE II shall image or re-image assets that are part of the assigned RMF boundary
- The ISSE II shall install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries’ assets.
- The ISSE II shall assist with removal of SSD, HDD or other critical components of assets before destruction and removal from the RMF boundary.
- The ISSE II shall provide cybersecurity patching of assets in times of DoD and DoN TASKORDs, FRAGORDs, or even designated by Command ISSM, ACIO, and/or Code 104 management.
- The ISSE II shall support configuration change documentation and control processes and maintaining DOD STIG Compliance.
- The ISSE II shall support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware. This includes assessing vulnerabilities, patching and meeting requirements of the STIG for the hardware.
- The ISSE II shall report compliance issues of network hardware to management.
- Other duties as assigned.
Requirements
- Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance.
- Ability to develop and implement information assurance guidance and execute ISS functions with little to no supervision.
- Ability to travel less than 5%.
Certifications:
- Minimum Certification Requirements: IAT Level II certification (CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND and SSCP)
Minimum/General Experience:
- Three (3) years professional experience capturing and refining information security operational and security requirements, and ensuring those requirements are properly addressed through purposeful architecting, design, development, and configuration; and implementing security controls, configuration changes, software/hardware updates/patches, vulnerability scanning, and securing configurations.
Minimum Education:
- Bachelor’s degree in computer science, information technology, or an equivalent technical degree from an accredited college or university., Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
LM
Luis Minvielle
Top-Paying Tech Jobs (with Salaries)
over 2 years ago
LM
Luis Minvielle
The 12 Best Jobs for Software Engineers
over 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago