Paragon is recruiting for a Security Engineer III to work on the PEO-T contract for USTRANSCOM. A team member assigned as a Security Engineer III provides technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation. Responsible for designing and implementing solutions for protecting confidentiality, integrity, and availability of sensitive information. Provides technical evaluations of IT systems and assists with making security improvements. Participates in design of information system contingency plans that maintain appropriate levels of protection and meet time requirements for minimizing operations impact to customer organization. Conducts security product evaluations, and recommends products, technologies and upgrades to improve the organization’s security posture. Understands Information Security Continuous Monitoring (ISCM) concepts, security automation, and risk dashboarding tools. Must adhere to USTRANSCOM processes and procedures to identify and respond to risk while supporting efficient, accurate Assessment & Authorization reporting to facilitate ongoing authorization(s), secure release deployments, modernizations, migrations, and overall security enhancements. Conducts testing and audit log reviews to evaluate the effectiveness of current security measures. Employees in this role are required to operates with a high-level of autonomy. They should be capable of defining the solution recommendations and working with management to improve efficiencies in processes and procedures. These team members will be involved in supporting teammates learning processes and procedures. These team members will participate in team initiatives including the drafting of deliverables and peer reviews of others’ draft products. They must be capable of communicating technical details effectively within their assigned Program Management Offices (PMOs), translating complex security risks into operational or business impact for leadership and non-technical stakeholders. Effective communication skills and willingness collaborate with peers and management are critical to success. These team members may be asked to provide supplementary support to additional PMOs within the contract purview. Tasks include, but are not limited to, the following: Reviews evolving NIST requirements to support risk assessment activities associated with the affiliated system requirements and specifications (execution, mapping, and compliance tracking). Prepares detailed specifications from which cybersecurity deficiencies identified during risk assessment will be mitigated/remediated and conducts follow-up risk assessment to ensure proper secure coding practices and STIG/SRG implementation are being built-in/enforced to the greatest extent possible. Collaborates closely with government customers to develop appropriate POA&Ms and support risk acceptance activities as needed to support risk management processes.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior