Information System Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Support the Lifecycle Assessment and Authorization (A&A) process.
- Develop a Systems Security Plan (SSP).
- Assist and maintain a formal Information Security Program that includes recommendations on continuous improvement of the processes and architectures.
- Maintain and make accessible documentation of all operational and business process activities in the form of Standard Operating Procedures (SOPs).
- Monitor and track projects in the A&A queue.
- Analyze SSPs to develop an understanding of the customer’s systems and applications.
- Coordinate A&A actions and system testing with appropriate security personnel.
- Develop risk assessments, recommend mitigating countermeasures, and write short, succinct risk assessments, and certification reports for submission to the Chief Information Officer (CIO).
- Monitor and track projects in the A&A queue.
- Maintain a document repository where A&A project documentation is stored and recorded and register actions concerning project approvals to operate in the A&A database.
- Assemble and submit A&A packages to the Principal Accreditation Authority or Designated Accreditation Authority.
- Review and approve product requests for procurements.
- Provide security guidance in terms of policy and technical implementation of those policies.
- Produce and assist with production of technical artifacts required for A&A packages such as a System Security Plan, Audit Strategy.
- Configuration Management Plan, Security Controls Traceability Matrix, Project Plan of Action and Milestones.
- Monitor and address cyber risks such as malware, zero-day attacks, denial of service attacks, as well as associated mitigations regarding computer and network devices.
Requirements
- Active TS/SCI with Polygraph.
- Bachelor’s degree and 14 years or more experience; Master’s degree and 12 years or more experience; PhD and 9 years or more experience.
- CISSP Certification.
- Demonstrated experience with:
- Computer networking in Windows AND Linux.
- Website configuration.
- Basic software development knowledge.
- Eliciting information on complex technical problems from non-technical personnel for use in diagnosis, analysis, resolution of problems.
- Customer regulations and standards, including Information Security (INFOSEC) and Communications Security (COMSEC).
- Managing security aspects of deployed infrastructure and technical solutions.
Desired Skills:
- Demonstrated experience with Rapid7, WebInspect, AppDetective, CIS-CAT, and other vulnerability assessment tools and processes.
- Information security certifications such as CISSP, CISSE, CISA, CEH, CCSP, etc.
- Demonstrated experience with computer and network vulnerabilities (e.g., malware, zero-day attacks, denial of service attacks, etc.).
About the company
SAIC is a premier technology integrator, solving our nation’s most complex modernization and systems engineering challenges across the defense, space, federal civilian, and intelligence markets. Our robust portfolio of offerings includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and simulation; and training. We are a team of 23,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $6.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see Working at SAIC. EOE AA M/F/Vet/Disability
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dejobs.orgGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks
Best Paying Jobs in Technology