Security Engineer and Oracle DBA
Empower AI Inc. · Jefferson City, Missouri, United States
IT Services and IT Consulting · 501-1,000 employees
About the role
The role involves administering and securing Oracle database environments while supporting RMF compliance and cybersecurity assessments. You will collaborate with technical teams to perform vulnerability scans, manage system patches, and ensure adherence to DISA STIGs and NIST standards.
What they look for
Requirements
Candidates must hold an active Secret clearance and possess at least 2 years of experience in cybersecurity, IT administration, or RMF support. A bachelor's degree and a Security+ certification are required, with preference given to those holding CASP+ or CISSP certifications.
Full description
Overview
Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.
Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.
Responsibilities
As a Security Engineer and Oracle Database Administrator, you will support the administration, maintenance, and security of database environments while assisting the Subject Matter Expert (SME) and Cybersecurity Engineers with Risk Management Framework (RMF) related activities including Security Control Assessments (SCAs) and assisting system owners in the transition to RMF compliance. In assuming this position, you will be a critical contributor to meeting Empower AI’s mission: To deliver innovative, cost-effective solutions and services that enable our customers to rapidly adapt to dynamic environments. This position is located in St. Louis, Missouri; relocation assistance, while not guaranteed, may be available. An active Secret clearance is required.
Highlights of Responsibilities:
- Administer, monitor, and maintain relational databases to ensure high availability, performance, security, and data integrity across production and non-production environments.
- Perform database installation, configuration, backup, recovery, patching, and upgrades while implementing disaster recovery and business continuity strategies.
- Optimize database performance by analyzing query execution plans, indexing strategies, and system resource utilization to improve efficiency and reduce downtime.
- Collaborate with application developers and infrastructure teams to troubleshoot database issues, enforce security policies, automate routine administrative tasks, and support system deployments.
- Working independently with minimal supervision, performs a variety of relatively routine project tasks applied to specialized technology problems (e.g. logic design, circuit design, I/O design, firmware development, computer architecture analysis and design, network structure design, etc.)
- Document and track all system changes, deliver weekly Change Control Board (CCB) Change Requests and patch lists, update baseline artifacts/VM images, and evaluate impacts against system authorizations.
- Analyzes user requirements, concept of operations documents, and high-level system architecture to develop system requirement specifications
- Guides users in formulating requirements, advises alternative approaches and conducts feasibility studies
- Typical assignments may involve integration of software, systems, and electronic processes or methodologies to resolve total system problems or applications
- Processes may range from simple to moderately complex use of computers or other electronic technology and equipment
- Assess Department of War Information Systems against the RMF security controls in accordance with Department of Defense Instruction (DoDI) 8500, DoDI 8510, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 5
- Develop and review RMF documentation and artifacts such as Configuration Management Plans, Network Infrastructure Plans, Business Continuity and Disaster Recovery Plans, Plan of Action and Milestones (POA&Ms), topology diagrams and all supporting policies in support of RMF Assess and Authorize (A&A) activities
- Interview technical SMEs as well as non-technical management personnel to ascertain the security posture of an Information Technology (IT) system
- Evaluate a wide array of IT devices for Security Technical Implementation Guide (STIG) compliance using Assured Compliance Assessment Solution (ACAS)/ Nessus, Security Content Automation Protocol (SCAP) Compliance Checker (SCC), and manual checklist reviews.
- Ensure Security Technical Implementation Guides (STIG’s) are in compliance with NIST SP-800-53 by providing thorough technical written explanations and proof
- Manage packages in Enterprise Mission Assurance System (eMASS) based on a strong understanding of the NIST SP-800-53 requirements and the application of Control Correlation Identifiers (CCI) outlined in the Committee on National Security Systems Instruction (CNSSI) 1253 to achieve system compliance
- Review, test, and apply updates, patches, and IAVM/As. Perform automated (via approved ISEC-MED tools) and manual vulnerability checks, conduct monthly ACAS scans, and submit required reporting.
- Review and apply DISA STIGs quarterly to ensure compliance, deliver required quarterly reports, maintain eMASS records, and provide real-time tracking and updates via the Plan of Action and Milestones (POAM).
- Support A&A activities, Security Control Assessor-Validator (SCA-V) audits, and continuous monitoring tasks by preparing documentation, architecture diagrams, and hardware/software lists.
- Assess new IT capabilities, devices, or trusted components, deliver Security Impact Analyses (SIA), and securely integrate approved items into the enclave.
- Execute security incident tracking, backups, contingency operations, recovery actions, and impromptu cybersecurity assessments following cyberattacks.
Qualifications
Requirements:
Current/active Secret clearance.
Bachelor's degree or equivalent combination of education and related work experience.
Security+ certification required; CASP+ (SecurityX) or CISSP preferred.
Minimum of 2 years of experience in cybersecurity, IT systems administration, RMF support, or related technical disciplines.
Experience supporting, maintaining, or administering Oracle database environments.
Physical Requirements:
- Sitting for long periods
- Standing for long periods
- Ambulate throughout an office
- Ambulate between several buildings
- Stoop, kneel, crouch, or crawl as required
- Travel by land or air transportation 25 %
About Empower AI
All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.