SRC is searching for a well-rounded Senior Cyber Security Engineer to test, analyze, evaluate, validate, and verify cybersecurity requirements for United States Space Command (USSPACECOM) systems. These systems consist of an on-premises Nutanix Hyper-Converged Private Cloud utilizing Citrix VDA Hypervisor and associated products. The Private Cloud hosts USSPACECOM Mission Applications and Web Services as well as Program of Record (PoR) Systems 'Information Technology (IT) infrastructure including Windows Server 2022 servers and HPE Endpoints. Endpoints. Evaluating information systems for compliance with Defense Information Security Agency (DISA) Security Technical Implementation Guideline (STIG) and review measures needed to bring systems into compliance Conducting Assured Compliance Assessment Solution (ACAS) scans for STIG compliance checks Reviewing Information Assurance Vulnerability Alerts (IAVA) for applicability and impact to N-NC Developing and/or updating the Plan of Action and Milestones (POA&M) to document all known vulnerabilities to correct or mitigate risks Analyzing changes affecting the organization's Authorization to Connect (ATC) risk level and cybersecurity posture and report findings Ensuring that security design & distribution actions are evaluated, validated, and implemented as required Ensuring that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s) Evaluating development efforts to ensure that baseline security safeguards are planned for and appropriately installed Identifying alternative information security strategies to address organizational security objectivesof cyber taskings Assisting the command ISSM in preparing, distributing, and maintaining plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations and cybersecurity practices Reviewing and recommending policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies Developing, updating, and/or reviewing ATO, IATT, ATC documentation to include, but not limited to, Security Plans, Implementation Plans, Test Plans, Test Results (ACAS, STIGs, etc.), POA&M, and Security Assessment Reports (SAR) Assessing system compliance against NIST and DoD security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) Coordinating with other system SMEs to identify and develop authorization boundary diagrams, architecture diagrams, and hardware and software inventories #LI-LH1 FILLING THIS POSITION IS CONTINGENT UPON FUNDING
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior