Information Systems Security Engineer 3
Role details
Job location
Tech stack
Requirements
· Bachelor of Science in Computer Science, Information Technology or a directly related technical discipline is highly preferred.
o With an applicable Bachelor's Degree, 15 years of experience is required
o Without an applicable Bachelor's degree, 20 years of experience is required.
· Experience must include the following:
o Hands on technical implementation of networks and systems;
o Experience evaluating various different technical, operational and management solutions to security problems, using written language and various media to present alternatives and recommendations;
o Proven ability to develop documentation sufficient to arrive at logical and comprehensive conclusions and recommendations. The documentation must be of a sufficient professional level to stand as an artifact for reuse as part of the security architecture;
o Experience evaluating the adequacy and existence of IT security controls as is conforms to security architectures.
o Experience having properly documented evidence of security architecting, design and cyber-security activities sufficient for a third-party reviewer to arrive at the conclusion the Security control Assessor has reached in the work.
o 3+ years previous experience effectively performing security control implementation on networks, servers and systems and/or vulnerability assessments.
Required Technical Skills & Experience (required on matrix):
· One or more of the following networking or security certifications:
· Certified Information Systems Security Professional (CISSP)
· Certified Information Systems Auditor (CISA)
· Certified Information Security Manager (CISM)
· 5+ years of experience performing security control evaluation and testing.
· 8+ years of experience with North American Electric Reliability Corporation, Critical Infrastructure Protection (NERC CIP) regulatory standards and requirements.
· 10+ years of experience with the Risk Management Framework and the 800 series of National Institute of Standards & Technology (NIST) Special Publications (in particular 800-37, 800-39, 800-53, 800-53A, and 800-115)