Information Systems Security Engineer

Ingenium Consulting, LLC
Herndon, VA, United States
about 1 month ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Plan of Action and Milestones Vulnerability Analysis

Job description

  • Identify security control requirements
  • Audit application, system, and security logs and take required actions
  • Support the Authorization and Accreditation (A&A) process across the system life cycle
  • Remediate and mitigate identified vulnerabilities by developing plan of action and milestones (POA&Ms).
  • Perform system scans using vulnerability assessment tools such as Rapid7
  • Maintain documentation consistent with the A&A package

Requirements

  • Must have an active TS/SCI with Polygraph to be considered for this role.
  • Demonstrated experience with navigating the Assessment and Authorization (A&A) process
  • Experience in developing and implementing information security controls, procedures, and documentation for the operations of systems.
  • Experience with Ongoing Authorizations and Assessments
  • Assess/calculate risk based on threats, vulnerabilities, and shortfalls uncovered in testing Identify mitigating solutions
  • Experience with the NIST Risk Management Framework (RMF) and/or ICD503

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:17 min

Embedding automated vulnerability analysis within CircleCI workflows

Milecia Mcgregor · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Flaws in vague supply chain security advice

Adrian Mouat Adrian Mouat · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all