Cyber Security Engineer (100% On-Site)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
- HBSS / McAfee ePO Engineering: Hands-on experience building and maintaining HBSS/ePO infrastructure, including Windows servers, McAfee module deployment, policy configuration, patching, Rogue Sensors, and troubleshooting.
- RHEL Security Hardening & Vulnerability Remediation: Experience supporting Red Hat Enterprise Linux, applying DISA STIGs, running SCAP scans, managing RPM updates/offline YUM repositories, and remediating vulnerabilities in classified DoD environments.
Full Req:
Agensys is seeking an Information Systems Security Engineer (ISSE) to support the Air Force National Capital Region Information Technology Services (AFNCR ITS) program within the National Military Command Center (NMCC) at the Pentagon.
The ISSE will provide hands-on cybersecurity and security engineering support for mission-critical systems, with a significant focus on building, deploying, maintaining, patching, and troubleshooting ACAS and HBSS infrastructure. This role also supports system security engineering, cybersecurity risk assessments, vulnerability management, security architecture, and technical security assessments.
Responsibilities:
- Build, deploy, maintain, and patch ACAS Red Hat Linux 7.9 and 8 servers.
- Build, maintain, patch, and troubleshoot Tenable Security Center and Nessus servers/scanners.
- Build, deploy, maintain, and patch HBSS Windows servers.
- Build and support McAfee ePO environments.
- Deploy and patch McAfee modules through ePO.
- Configure McAfee policies for supported environments and applicable security benchmarks.
- Obtain HBSS and ACAS kickstart ISOs from DISA.
- Configure Red Hat YUM local RPM repositories to support offline ACAS server patching.
- Update Red Hat 7.9 and 8 RPMs as releases become available.
- Apply DISA STIGs to HBSS Windows operating systems and ACAS RHEL servers.
- Run SCAP scans against Windows and RHEL servers.
- Provide Security Center accounts for Vulnerability Managers to perform ACAS scans.
- Analyze ACAS scan results and support remediation of vulnerability findings.
- Support licensing processes for HBSS ePO and Tenable Security Center environments.
- Deploy Rogue Sensors across network subnets and identify rogue subnets and endpoints.
- Troubleshoot Tenable Security Center and Nessus scanner issues.
- Perform and review technical security assessments to identify vulnerabilities and non-compliance with established cybersecurity standards.
- Recommend mitigation strategies for identified security risks and vulnerabilities.
Requirements
- ACAS Engineering - Build & Deployment: Must have hands-on experience building ACAS environments, including standing up/configuring Tenable Security Center, Nessus scanners, and ACAS RHEL servers. Candidates who have only run ACAS scans, reviewed results, or administered an existing environment are not sufficient., * Active TS/SCI security clearance.
- Security+ CE certification.
- 5+ years of Systems Engineering experience.
- Hands-on experience building and deploying ACAS environments.
- Experience with Tenable Security Center and Nessus scanners.
- Experience with HBSS and McAfee ePO.
- Experience with Red Hat Enterprise Linux (RHEL).
- Experience implementing DISA STIGs and security hardening.
- Experience identifying security risks across information systems, networks, operating systems, hardware, and data transfer protocols.
- Strong troubleshooting and technical problem-solving skills.
- Strong communication, planning, and organizational skills.
- Ability to work independently and take initiative.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Where To Find Software Engineering Jobs
Fully Remote Software Engineer Jobs
Understanding and Mitigating Common Web Vulnerabilities