Cybersecurity Engineer

  • $110–$115 Per Hour
  • Contractor

Highlights

Utilize Enterprise Security Services to provide analysis of vulnerabilities and compliance risks in ACAS, Enterprise IT audit logs in ArcSight and Splunk, McAfee Host-Based Security Services (HBSS), User Activity Monitoring (UAM), and Cyber Terrain Mapping (CTM) on 100+ nodes. Assess/calculate risk based on threats, vulnerabilities, and shortfalls uncovered in routine analyzation of Continuous Monitoring (ConMon) controls and provide those results as Body of Evidence (BoE) to be evaluated in 7, 30, 90 and 365 day increments as the control metrics require.

Numbers & Facts

LocationAurora, CO
Job TypeContractor
Salary$110–$115 Per Hour

Description

JOB TITLE: Cybersecurity Engineer
JOB LOCATION: Aurora, CO
WAGE RANGE*: 110-115/hr
JOB NUMBER: RTXCJP00001607

 

JOB DESCRIPTION
 

Implement Information Assurance (IA) processes, provide guidance, and develop documentation throughout the system development life-cycle via the RMF tool in ServiceNOW.
Develop, implement, and document formal security policies and System Security Plans (SSP) throughout the program and monitor compliance to these policies during all phases of the Risk Management Framework (RMF) process.
Utilize Enterprise Security Services to provide analysis of vulnerabilities and compliance risks in ACAS, Enterprise IT audit logs in ArcSight and Splunk, McAfee Host-Based Security Services (HBSS), User Activity Monitoring (UAM), and Cyber Terrain Mapping (CTM) on 100+ nodes.
Monitor Heat Map Score matrix and evaluate cyber risk data, keeping the score at acceptable risk levels for the security categorization of the asset(s) and their Risk Evaluation Lanes (REL).
Manage and deliver system authorization and accreditation packages, for 3 assets that span 3 different classification levels.
Review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.).
Assess/calculate risk based on threats, vulnerabilities, and shortfalls uncovered in routine analyzation of Continuous Monitoring (ConMon) controls and provide those results as Body of Evidence (BoE) to be evaluated in 7, 30, 90 and 365 day increments as the control metrics require.
Direct activities required to remediate system-level information security weaknesses tracked via the FISMA (POA&M) process. Document the elements of the plans, milestones for correcting the weaknesses, and scheduled completion dates for the milestones, periodically reporting remediation progress as necessary.
Brief leadership, as needed, on the status of action items and/or results of activities affecting the security posture of the program.
Able to collaborate and communicate effectively with other system engineers, system administrators, software developers, and information assurance professionals.

 

Equal opportunity employer as to all protected groups, including protected veterans and individuals with disabilities 

 

* While an hourly range is posted for this position, an eventual hourly rate is determined by a comprehensive salary analysis which considers multiple factors including but not limited to: job-related knowledge, skills and qualifications, education and experience as compared to others in the organization doing substantially similar work, if applicable, and market and business considerations. Benefits offered include medical, dental and vision benefits; dependent care flexible spending account; 401(k) plan; voluntary life/short term disability/whole life/term life/accident and critical illness coverage; employee assistance program; sick leave in accordance with regulation. Benefits may be subject to generally applicable eligibility, waiting period, contribution, and other requirements and conditions. Benefits offered are in accordance with applicable federal, state, and local laws and subject to change at TCM's discretion.

Qualifications

REQUIRED EXPERIENCE:

Minimum of 10 years' related experience in Cybersecurity, Systems or Software Engineering, for the government or government contractor, if other than IC position.
Experience developing Security Authorization Requirements, performing vulnerability assessments, and implementing threat mitigation updates on embedded systems and products.
Experience configuring and hardening COTS components with STIGs.
Continuous Monitoring and Network monitoring experience.
Experience with product development including architecture, requirements, design, integration and testing.
Experience with compliance implementation of security requirements (i.e. Risk Management Framework and other A&A processes).
Experience participating in technical reviews with both external and internal customers.
Coordinate with ISSO/ISSM to update POA&M and reflect open vulnerabilities associated with servers and workstations, develop remediation plans to include milestone completion dates and status updates, and include mitigation process for closed vulnerabilities.
Participate in Configuration Control Board (CCB).


Required Education (including Major):

Bachelor's Degree in Engineering, or related Science, Technology, Engineering, Mathematics (STEM) degree program.
10 years' experience in lieu of formal degree.

 

Desired Skills:

Experience using DISA Security Technical Implementation Guides (STIGs).
Experience onboarding assets to centrally managed Enterprise solutions.
Experience conducting risk analysis on products and system components through review of CVEs, plugins, IAVAs.
Experience in conducting software due diligence with COTS/GOTS and proprietary solutions.
Positive, self-motivated individual who can complete tasks independently.
Experience with multi-level security solutions.
Experience working in Systems Engineering on complex embedded systems.
CISSP (ISC)2

 

Skills

  • Cybersecurity
  • COTS

Similar Jobs