Security Engineer III
Paragon Technology Group, Inc Scott AFB, Illinois, United States · $85K–$90K/yr
IT Services and IT Consulting · 51-200 employees
About the role
The Security Engineer III provides technical support for vulnerability and risk assessments, network security, and security implementation for USTRANSCOM. They are responsible for designing security solutions, conducting product evaluations, and ensuring compliance with RMF and NIST requirements.
What they look for
Requirements
Candidates must have at least 4 years of relevant security engineering experience and hold an active IAM II certification. A bachelor's degree in a relevant field and an active Secret or higher security clearance are required.
Full description
Paragon is recruiting for a Security Engineer III to work on the PEO-T contract for USTRANSCOM.
A team member assigned as a Security Engineer III provides technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation. Responsible for designing and implementing solutions for protecting confidentiality, integrity, and availability of sensitive information. Provides technical evaluations of IT systems and assists with making security improvements. Participates in design of information system contingency plans that maintain appropriate levels of protection and meet time requirements for minimizing operations impact to customer organization. Conducts security product evaluations, and recommends products, technologies and upgrades to improve the organization’s security posture. Understands Information Security Continuous Monitoring (ISCM) concepts, security automation, and risk dashboarding tools. Must adhere to USTRANSCOM processes and procedures to identify and respond to risk while supporting efficient, accurate Assessment & Authorization reporting to facilitate ongoing authorization(s), secure release deployments, modernizations, migrations, and overall security enhancements. Conducts testing and audit log reviews to evaluate the effectiveness of current security measures. Employees in this role are required to operates with a high-level of autonomy. They should be capable of defining the solution recommendations and working with management to improve efficiencies in processes and procedures. These team members will be involved in supporting teammates learning processes and procedures. These team members will participate in team initiatives including the drafting of deliverables and peer reviews of others’ draft products. They must be capable of communicating technical details effectively within their assigned Program Management Offices (PMOs), translating complex security risks into operational or business impact for leadership and non-technical stakeholders. Effective communication skills and willingness collaborate with peers and management are critical to success. These team members may be asked to provide supplementary support to additional PMOs within the contract purview.
Tasks include, but are not limited to, the following:
· Reviews evolving NIST requirements to support risk assessment activities associated with the affiliated system requirements and specifications (execution, mapping, and compliance tracking).
· Prepares detailed specifications from which cybersecurity deficiencies identified during risk assessment will be mitigated/remediated and conducts follow-up risk assessment to ensure proper secure coding practices and STIG/SRG implementation are being built-in/enforced to the greatest extent possible.
· Collaborates closely with government customers to develop appropriate POA&Ms and support risk acceptance activities as needed to support risk management processes.
Qualifications:
4+ years relevant experience in security engineering [or equivalent job role(s) such as ISSO, ISSM, SCA, etc.]:
· Expertise to develop and/or review system authorization documentation (family plans and supplementary artifacts) in accordance with Department of War (DoW) implementation of the Risk Management Framework (RMF)
· Experience participating in Technical Interchange Meetings (TIMs) on a wide range of Program Management Office (PMO) security engineering topics
· Experience participating in Acquisition program Engineering Milestone Reviews
· Experience coordinating and collaborating with Development contract personnel in Security, System Administration, System Engineering, and other supporting roles to identify, document, and plan for security enhancement requirements and to resolve program security issues
· Experience coordinating and collaborating with inheritance providers (i.e., enterprise teams in USTRANSCOM, SDDC, AMC, Defense Information Systems Agency (DISA) Security Office, etc) to determine hybrid security requirements and established appropriate inheritance relationships using tools provided
· Expertise performing security activities to maintain authorization of the PMO programs (i.e., Categorization, Control Selection, Evidence Collection and Audit, Risk Assessments, Reporting, Security Impact Assessments affiliated with Change Management practices, IR/CP Exercise Support, FISMA Reporting, Continuous Monitoring, etc.)
· Experience using DoW Enterprise Mission Assurance Support Service (eMASS) system
· Experience providing support to ensure PMO systems are designed, developed, and deployed in accordance with applicable Executive Orders, Federal Policy, DoW regulations, USTRANSCOM requirements, and commercial best practice
· Experience reviewing vulnerability results documented using the government approved Static Application Security Testing (SAST) solution [i.e., OpenText (Fortify) SCA], analyzing outputs to identify vulnerabilities, and recommend mitigation and remediation actions
· Experience reviewing vulnerability scans using ACAS/Nessus, analyzing outputs to identify vulnerabilities, recommending mitigation and remediation actions, ingest actions in eMASS
· Expertise supporting the Customer through critical review of documented DISA STIG/SRGs, providing technical feedback and recommendations to customer for areas of improvement in reporting accurate qualitative results, and ingesting final product in the government-supplied tool (eMASS) to support risk assessment of the NIST controls.
· Experience generating, sustaining, extending (when appropriate), and reporting status associated with POA&M requirements
· Expertise conducting and evaluating security testing activities including security assessments and audits
· Experience supporting operational security activities (e.g., risk mitigation, host security, encryption, intrusion detection, Virtual Private Network [VPN] implementations, and viral detections)
· Experience with security lockdown and/or hardening of servers and network devices
· Ability to coordinate overall security strategy with multiple agencies, Authorizing Official (AO) representatives
· Ability to coordinate with developers, vendors, and other government organizations/agencies to assess security engineering issues
· Experience recommending changes to network and security architecture to improve security posture and meet operational performance requirements
Required Education/Certification:
· Bachelor’s degree in Computer Science, Cybersecurity, or equivalent Information Technology academic studies
· Active IAM II Certification in Good Standing (e.g., ISC2 CGRC [formerly CAP], CompTIA Security X [formerly CASP+CE], ISACA CISM, ISC2 CISSP (or associate), GIAC GSLC, EC-Council CCISO)
· Must be a US Citizen with an active DoW Secret, or higher, clearance
Similar roles
-
Cloud Security Engineer
Gifthealth Inc Columbus, Ohio, United States · $115K–$150K/yr
-
Senior Cybersecurity Engineer (Identity and Access Management)
Open Dealer Exchange Southfield, Michigan, United States
-
Cybersecurity Engineer
Open Dealer Exchange Southfield, Michigan, United States
-
Senior Information Security Engineer
Zscaler United States · $134K–$168K/yr
-
Cybersecurity Analyst
Smiths Group Pune, Maharashtra, India
-
Staff Product Security Engineer
Affirm Canada · CA$181K–CA$241K/yr