Enterprise Security Engineer
Apply on
Job Description
Job Title: Enterprise Security Engineer
Job Location: Frederick, MD and Norcross, GA
Job Description:
The ESE will be responsible for administering and maintaining the operational security posture for information systems and researching methods to protect our corporate and customer data from cyber threat actors. The ESE shall have experience in supporting infrastructure and cloud operation services and be able to see the big picture while focusing on implementing, monitoring, and administering sensitive and controlled data operations solutions. The ESE shall also have a working knowledge of numerous vendors products such as AWS GovCloud, Unibquity, pfSense, Windows/Unix/Linux environments, and Microsoft GCC-High. The ESE will inform users about security measures, explain potential threats, raise information security awareness, and monitor networks. The ESE will assist the Chief Information Security Advisor (CISA) in the implementation of the RMF process for assessment and accreditation of information systems and serves as the primary advisor on all RMF matters, technical and otherwise, involving the security of systems within the ATG ecosystem. The individual will report to the CISA for issues related to maintaining and improving the security posture for information systems that support ATG s production and development networks.
Job Required Skills:
- In coordination with ATG IT, perform regular audits of Information Systems (IS), including review of system audit logs, verification, and maintenance of regular backups of the IS, and inventorying of IS components. Ensure that system recovery processes are monitored and tested to ensure that all IS components can be restored. Perform patch management of all ISs within the facility.
- Ensure that unauthorized personnel are not granted use of, or access to any IS within the facility.
- Assist the CISA in the management of ISs and maintain security posture through entire lifecycle and adherence to the Risk Management Framework (RMF). Ensure the implementation of security measures in accordance with the SSP and CISA s guidance.
- Perform periodic Risk Assessments of the Information Systems and identify and document any unique threats to the Information Systems. Develop and perform regular vulnerability and security posture tests of the IS, as required by the Security Control Assessor (SCA) and CISA.
- Assist with the evaluation of changes or additions to the IS within the ATG ecosystem, work with the ISSM and CISA to determine security relevance and make recommendations for approval or denial to the CISA.
Job Responsibilities:
- Research, test, and/or verify proper function of software patches and fixes.
- Provide advice on project costs, design concepts, or design changes.
- Perform security analyses of developed or packaged software components.
- Provide technical guidance or support for the development or troubleshooting of cloud systems.
- Document cloud design specifications, installation instructions, and other system-related information.
- Recommend cloud design specifications for adoption within the ATG secure enclave development environment.
- Lead automation efforts for a team advancing a service ownership culture
- Maintain current technical knowledge of rapidly changing technology, remain on the lookout for new technologies, and work with management and development teams to evolve current processes.
Certifications:
- Active DoD IAT/III certification such as CISSP, CASP + CE or higher is required
Required Experience and Skills:
- 7-10 years experience in system administration and cybersecurity. Experience may be concurrent.
- Must have 5+ years of experience in supporting Windows and Linux in a Domain environment. Experience may be concurrent.
- Must have direct experience maintaining and troubleshooting hardware and be familiar with virtualization
- Must have working knowledge of Vulnerability Scanning tools such as NESSUS, OpenVAS, and SIEM solutions
- Must have basic Pen Testing knowledge: to include Kali Linux, Wireshark, BURP Suite, etc.
- Must be a flexible, positive and energetic team player, be able to work in a fast-paced environment and adapt to changes in tasking, be able to work with minimal supervision, be courteous and professional when interacting with colleagues and customers, demonstrate a solid ability to identify and solve problems, plan and prioritize personal tasking, effectively communicate verbally and in writing, and be able to work successfully in a team environment
- Ability to obtain and maintain a Top-Secret Security Clearance