Lead Cybersecurity Engineer/Scientist w/Secret Clearance

TekSynap Corporation
North Charleston, SC, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

User Authentication Cyber Security Information Systems Computer Networks Identity and Access Management Package Development Process SAP (Applications) SC Clearance Information Technology Vulnerability Analysis

Job description

TekSynap is seeking a Lead Cybersecurity Engineer / Scientist to join our team at D efense Health Agency to provide technical leadership for cybersecurity assessment and authorization activities supporting DHA systems and enclaves. Responsibilities include RMF implementation, IV&V testing, vulnerability assessment, STIG validation, and development of authorization packages for NIWC Atlantic managed cybersecurity efforts., * Serve as Lead Technical Engineer for cybersecurity assessment and authorization execution

  • Lead implementation of RMF controls across systems, enclaves, and sites
  • Develop and maintain Security Assessment Plans (SAP)
  • Develop cybersecurity test procedures aligned to NIST and DoD guidance
  • Conduct security control assessments across technical, operational, and management controls
  • Perform Independent Verification & Validation (IV&V) testing activities
  • Conduct vulnerability assessments using ACAS, HBSS, and related tools
  • Analyze vulnerability scan results and identify remediation actions
  • Develop Security Assessment Reports documenting findings and recommendations
  • Perform reassessment of remediated controls and update test results
  • Provide technical leadership for RMF package development
  • Support creation of SSP, SAR, POA&M, and supporting artifacts
  • Conduct system security architecture reviews
  • Evaluate enclave and system boundary definitions
  • Perform risk assessments and residual risk analysis
  • Support development of authorization packages in eMASS
  • Provide technical validation of RMF artifacts
  • Support validation readiness review activities
  • Support IV&V test event planning and execution
  • Provide technical oversight of STIG implementation
  • Develop cybersecurity test matrices and validation procedures
  • Support automated tool development for cybersecurity testing
  • Analyze ACAS data and generate vulnerability reports
  • Support automation of STIG assignment and test planning
  • Provide cybersecurity engineering support for DHA toolsets
  • Support development of dashboards and reporting metrics
  • Provide technical guidance to cybersecurity analysts and engineers
  • Support network, server, and application security testing
  • Support encryption, authentication, and boundary security reviews
  • Participate in technical review boards and working groups
  • Support continuous monitoring and risk scoring activities
  • Support remediation tracking and POA&M closure validation
  • Provide technical briefings to Government stakeholders
  • Support CONUS and OCONUS site cybersecurity assessments
  • Support cybersecurity documentation and reporting deliverables, * Location:North Charleston, SC area (contractor facility within 15 miles of NIWC Atlantic). Remote/telework may be approved
  • Type of environment:Officeenvironment
  • Noise level: Medium
  • Work schedule:Core hours (0800-1700), Monday through Friday. Occasional extended hours during testing events
  • Amount of Travel:Minimal (10 - 20%). CONUS primarily, limited OCONUS

Requirements

  • 15 years DoD engineering/cybersecurity; managerial experience required
  • RMF lifecycle implementation experience
  • STIG validation experience
  • IV&V cybersecurity testing experience
  • eMASS experience
  • Vulnerability assessment experience
  • Enterprise network security experience
  • Demonstrated experience supporting government agencies, customers, or contracts within federal environments. This includes the Intelligence Community (IC), Department of Defense (DoD), Federal Civil agencies, and military organizations. Prior experience supporting the same or similar contract, with an in-depth understanding of the customer environment, requirements, and operational landscape, is highly desirable.

Certifications

  • IAM Level III Certification preferred (e.g., CISSP, CISM, CASP, GSLC, CCISO)

Education

  • Bachelor’s degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related discipline.

Clearance

  • Secret clearance (ability to obtain TS preferred), * Cybersecurity engineering
  • RMF implementation
  • Risk assessment
  • Vulnerability analysis
  • System security architecture
  • Technical leadership
  • Problem solving
  • Documentation development, The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.

Benefits & conditions

We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:18 min

Evaluating distributed computation networks for AI model execution

Idan Gazit · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

54 sec

Detecting smart devices and experimenting with biological computing networks

Chris Heilmann +2 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all