Empower AI Inc.

Security Engineer and IT Systems Admin.

Empower AI Inc. · Jefferson City, Missouri, United States

IT Services and IT Consulting · 501-1,000 employees

2 h ago
Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer and IT Systems Administrator will perform system operations, maintenance, and support Risk Management Framework (RMF) activities to ensure compliance. They will also analyze user requirements, manage system changes, and conduct vulnerability assessments using tools like ACAS and Nessus.

What they look for

Security Engineering IT Systems Administration Risk Management Framework RMF Cybersecurity NIST SP 800-53 STIG Compliance ACAS Nessus eMASS Vulnerability Assessment Configuration Management System Architecture Information Assurance Windows Administration Security Control Assessment

Requirements

Candidates must possess an active Secret security clearance and a bachelor's degree in a relevant technical field. A CompTIA Security+ certification or higher is required, along with at least two years of experience in cybersecurity or IT systems administration.

Full description

Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.

Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.

Responsibilities

As a Security Engineer and IT Systems Administrator, you will perform IT systems administration, support system operations and maintenance, and assist the Subject Matter Expert (SME) and Cybersecurity Engineers with Risk Management Framework (RMF) activities, including Security Control Assessments (SCAs) and supporting system owners in achieving and maintaining RMF compliance. In assuming this position, you will be a critical contributor to meeting Empower AI’s mission: To deliver innovative, cost-effective solutions and services that enable our customers to rapidly adapt to dynamic environments. This position is located in St. Louis, Missouri; relocation assistance, while not guaranteed, may be available. An active Secret clearance is required.

Highlights of Responsibilities:

  • Working independently with minimal supervision, performs a variety of relatively routine project tasks applied to specialized technology problems (e.g. logic design, circuit design, I/O design, firmware development, computer architecture analysis and design, network structure design, etc.)
  • May be responsible for program coding, testing, debugging, patching, and documentation
  • Document and track all system changes, deliver weekly Change Control Board (CCB) Change Requests and patch lists, update baseline artifacts/VM images, and evaluate impacts against system authorizations.
  • Analyzes user requirements, concept of operations documents, and high-level system architecture to develop system requirement specifications
  • Guides users in formulating requirements, advises alternative approaches and conducts feasibility studies
  • Typical assignments may involve integration of software, systems, and electronic processes or methodologies to resolve total system problems or applications
  • Processes may range from simple to moderately complex use of computers or other electronic technology and equipment
  • Assess Department of War Information Systems against the RMF security controls in accordance with Department of Defense Instruction (DoDI) 8500, DoDI 8510, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 5
  • Develop and review RMF documentation and artifacts such as Configuration Management Plans, Network Infrastructure Plans, Business Continuity and Disaster Recovery Plans, Plan of Action and Milestones (POA&Ms), topology diagrams and all supporting policies in support of RMF Assess and Authorize (A&A) activities
  • Interview technical SMEs as well as non-technical management personnel to ascertain the security posture of an Information Technology (IT) system
  • Evaluate a wide array of IT devices for Security Technical Implementation Guide (STIG) compliance using Assured Compliance Assessment Solution (ACAS)/ Nessus, Security Content Automation Protocol (SCAP) Compliance Checker (SCC), and manual checklist reviews.
  • Ensure Security Technical Implementation Guides (STIG’s) are in compliance with NIST SP-800-53 by providing thorough technical written explanations and proof
  • Manage packages in Enterprise Mission Assurance System (eMASS) based on a strong understanding of the NIST SP-800-53 requirements and the application of Control Correlation Identifiers (CCI) outlined in the Committee on National Security Systems Instruction (CNSSI) 1253 to achieve system compliance
  • Review, test, and apply updates, patches, and IAVM/As. Perform automated (via approved ISEC-MED tools) and manual vulnerability checks, conduct monthly ACAS scans, and submit required reporting.
  • Review and apply DISA STIGs quarterly to ensure compliance, deliver required quarterly reports, maintain eMASS records, and provide real-time tracking and updates via the Plan of Action and Milestones (POAM).
  • Support A&A activities, Security Control Assessor-Validator (SCA-V) audits, and continuous monitoring tasks by preparing documentation, architecture diagrams, and hardware/software lists.
  • Assess new IT capabilities, devices, or trusted components, deliver Security Impact Analyses (SIA), and securely integrate approved items into the enclave.
  • Execute security incident tracking, backups, contingency operations, recovery actions, and impromptu cybersecurity assessments following cyberattacks.

Qualifications

Requirements:

Active Secret security clearance required.

Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field, or an equivalent combination of education and relevant experience.

CompTIA Security+ certification required (DoD 8570/8140 compliant), or a higher-level certification such as CASP+ (SecurityX) or CISSP.

Minimum of 2 years of experience in cybersecurity, information assurance, system administration, IT operations, or a related technical field.

Experience supporting and administering Windows-based information systems, implementing security controls, and maintaining compliance with cybersecurity requirements is preferred.

Physical Requirements:

  • Sitting for long periods
  • Standing for long periods
  • Ambulate throughout an office
  • Ambulate between several buildings
  • Stoop, kneel, crouch, or crawl as required
  • Travel by land or air transportation 25 %

About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.