Information Systems Security Engineer

Absolute Business Solutions Corp
Arlington, VA, United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$120,000.0 - $206,000.0
Working hours
Shift work
Job source

Tech stack

Microsoft Windows Computing Platforms Systems Engineering CompTIA Security+ Cyber Security Information Systems McAfee VirusScan Windows Servers Network Architecture Red Hat Enterprise Linux Security Content Automation Protocol Information Technology
+5 more
Transport Protocols Nessus Network Server McAfee EPolicy Vulnerability Analysis

Job description

The Information Systems Security Engineer will:

  • Provide cybersecurity and security-engineering services, including system security engineering, cybersecurity risk assessments, and security architecture support.
  • Perform and review technical security assessments of computing environments.
  • Identify system vulnerabilities, cybersecurity risks, and instances of noncompliance with established security standards and regulations.
  • Develop and recommend mitigation strategies and corrective courses of action.
  • Build, deploy, maintain, and patch HBSS Windows servers and ACAS Red Hat Enterprise Linux 7.9 and 8 servers.
  • Build, maintain, secure, and patch McAfee ePolicy Orchestrator, Tenable SecurityCenter, and Nessus servers.
  • Create and manage SecurityCenter accounts for vulnerability managers conducting ACAS scans.
  • Analyze ACAS scan results and support the remediation of identified vulnerabilities.
  • Obtain and manage required licenses for HBSS ePO and Tenable SecurityCenter environments.
  • Obtain HBSS and ACAS Kickstart ISO images from the Defense Information Systems Agency.
  • Build and administer virtual servers supporting cybersecurity operations.
  • Deploy, configure, and patch McAfee modules through ePolicy Orchestrator.
  • Develop and configure McAfee policies appropriate to each supported environment.
  • Apply Security Technical Implementation Guides to HBSS Windows operating systems, McAfee policies, and ACAS Red Hat Enterprise Linux servers.
  • Configure McAfee policies to comply with applicable security benchmarks.
  • Run Security Content Automation Protocol scans on Windows and Red Hat Enterprise Linux servers.
  • Update Red Hat Enterprise Linux 7.9 and 8 RPM packages as releases become available.
  • Establish and maintain local YUM repositories to patch offline ACAS servers.
  • Deploy Rogue System Detection sensors across applicable network subnets.
  • Identify rogue subnets and endpoints and support appropriate remediation actions.
  • Troubleshoot Tenable SecurityCenter and Nessus scanner issues.
  • Document technical solutions, assessment results, cybersecurity risks, and recommended courses of action.
  • Communicate complex technical findings clearly to technical teams, government stakeholders, and leadership.
  • Work independently, exercise sound judgment, and initiate appropriate action without requiring continuous direction.

Requirements

  • Active TS/SCI security clearance.
  • Current CompTIA Security+ certification.
  • At least five years of relevant systems-engineering experience.
  • Demonstrated understanding of systems engineering, including system design and architecture.
  • Hands-on experience administering and securing HBSS, ACAS, ePO, Tenable SecurityCenter, or Nessus environments.
  • Experience building, deploying, maintaining, and patching Windows and Red Hat Enterprise Linux servers.
  • Experience applying STIGs and other cybersecurity benchmarks to operating systems, security tools, and enterprise environments.
  • Ability to interpret vulnerability scan results and develop or implement appropriate remediation actions.
  • Demonstrated ability to identify cybersecurity risks across information-system and network architectures, including operating systems, hardware, and data-transfer protocols.
  • Strong planning, organizational, prioritization, and time-management skills.
  • Effective written, verbal, briefing, and presentation skills.
  • Ability to communicate technical information effectively in both formal and informal settings.
  • Demonstrated initiative and ability to work independently.
  • Ability to work full-time onsite in the NMCC environment.

Education and Experience

Candidates must meet one of the following combinations:

  • Bachelor’s degree: At least five years of relevant experience.
  • Master’s degree: At least three years of relevant experience.
  • No degree: At least 12 years of intensive and progressive experience demonstrating the required technical proficiency.

Qualifying degrees should be in computer science, information technology, cybersecurity, engineering, or a closely related discipline.

Benefits & conditions

Salary is commensurate with education, experience, knowledge, skills, abilities, and qualifications. The anticipated salary range for this requisition is $120,000 - $206,000 annually. This range represents the anticipated compensation for the position and is not a guarantee of compensation or an offer amount. The actual salary offered will depend on factors including the position’s responsibilities, relevant education and certifications, years and depth of experience, specialized technical expertise, security clearance, internal equity, contractual labor-category requirements, applicable market data, and other applicable laws or requirements., Some of our benefits include:

  • Generous PTO plus 11 federal holidays
  • 401(k) retirement plan with company match and immediate vesting
  • Annual health and wellness allowance
  • Annual professional-development funding for education, training, certifications, and technology tools
  • Eight hours of paid volunteer time annually
  • Charitable-donation matching
  • Internal and external employee referral bonuses
  • Living Our Values recognition and bonus awards

About the company

Absolute Business Solutions Corp (ABSC) is not just another technology company. We’re a community of innovators, engineers, cybersecurity professionals, analysts, and business leaders working together to solve some of the nation’s most complex security challenges. For more than 20 years, we have supported critical Department of Defense (DoD), Intelligence Community (IC), and Federal Civilian missions. As we continue to grow, we’re looking for exceptional professionals ready to make a meaningful mission impact.

AFNCR ITS-2 delivers and protects the enterprise IT infrastructure supporting some of the nation’s most critical defense, command-and-control, and senior-leader operations. This is more than routine cybersecurity support: it is an opportunity to help secure the systems and networks that must remain available, resilient, and trusted when the mission matters most.

ABSC is seeking an experienced Information Systems Security Engineer (ISSE) to support the Air Force within the National Military Command Center (NMCC).

The ISSE will provide cybersecurity and security-engineering expertise for the NMCC, including technical security assessments, vulnerability management, system hardening, security architecture support, and cybersecurity risk mitigation. The successful candidate will bring hands-on expertise with Host-Based Security System (HBSS), Assured Compliance Assessment Solution (ACAS), Tenable SecurityCenter, Nessus, Windows, and Red Hat Enterprise Linux environments., ABSC is a technology and services company that combines the agility of a small business with proven processes refined over more than two decades. We specialize in supporting public-sector clients across the Intelligence, Defense, Health, and Safety mission areas. Our team delivers the next generation of people, programs, and technical solutions needed to advance innovation, agility, resilience, and security across the federal government.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all