Sr Cyber Security Engineer

Scientific Research Corp

Huntsville, AL

JOB DETAILS
SKILLS
(XSS) Cross Site Scripting, Analysis Skills, Application Hosting, Applications Security, Authentication, Business Strategy, CCNA - Cisco Certified Network Associate, Citrix Product Family, CompTIA Security+, Computer Science, Computer Security, Cryptography, Customer Support/Service, Defense Information Systems Agency (DISA), DoD Directive 8140, DoD Directive 8570, Documentation, Firewalls, Government, Hardware Architecture, Hypervisors, Information Systems Security Engineering (ISSE), Information Technology & Information Systems, Information/Data Security (InfoSec), Injections, Internet Application, Internet Security, Leading Edge Technology, Maintain Compliance, Malware, Microsoft Windows Operating System, Microsoft Windows Server, Network Security, Oracle PL-SQL, Policy Implementation, Private Cloud, Red Hat Linux Operating System, Risk, Risk Management, Scientific Research, Security Analysis, Security Attacks, Security Compliance, Security Design, Standard Operating Procedures (SOP), Standards Strategy, Supply Chain Management, Systems Administration/Management, Systems Analysis, Test Plan/Schedule, Testing, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD), Web Services, Willing to Travel
LOCATION
Huntsville, AL
POSTED
2 days ago

Description

SRC is searching for a well-rounded Senior Cyber Security Engineer to test, analyze, evaluate, validate, and verify cybersecurity requirements for United States Space Command (USSPACECOM) systems. These systems consist of an on-premises Nutanix Hyper-Converged Private Cloud utilizing Citrix VDA Hypervisor and associated products. The Private Cloud hosts USSPACECOM Mission Applications and Web Services as well as Program of Record (PoR) Systems ''Information Technology (IT) infrastructure including Windows Server 2022 servers and HPE Endpoints. Endpoints.

  • Evaluating information systems for compliance with Defense Information Security Agency (DISA) Security Technical Implementation Guideline (STIG) and review measures needed to bring systems into compliance
  • Conducting Assured Compliance Assessment Solution (ACAS) scans for STIG compliance checks
  • Reviewing Information Assurance Vulnerability Alerts (IAVA) for applicability and impact to N-NC
  • Developing and/or updating the Plan of Action and Milestones (POA&M) to document all known vulnerabilities to correct or mitigate risks
  • Analyzing changes affecting the organization''s Authorization to Connect (ATC) risk level and cybersecurity posture and report findings
  • Ensuring that security design & distribution actions are evaluated, validated, and implemented as required
  • Ensuring that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s)
  • Evaluating development efforts to ensure that baseline security safeguards are planned for and appropriately installed
  • Identifying alternative information security strategies to address organizational security objectivesof cyber taskings
  • Assisting the command ISSM in preparing, distributing, and maintaining plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations and cybersecurity practices
  • Reviewing and recommending policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies
  • Developing, updating, and/or reviewing ATO, IATT, ATC documentation to include, but not limited to, Security Plans, Implementation Plans, Test Plans, Test Results (ACAS, STIGs, etc.), POA&M, and Security Assessment Reports (SAR)
  • Assessing system compliance against NIST and DoD security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)
  • Coordinating with other system SMEs to identify and develop authorization boundary diagrams, architecture diagrams, and hardware and software inventories

#LI-LH1

FILLING THIS POSITION IS CONTINGENT UPON FUNDING

Requirements

  • 1-2 years combined cybersecurity experience holding one or more of the following roles: ISSE, ISSO, and/or Security Control Assessor (SCA)
  • Two plus years of experience working with Windows and/or Red Hat Enterprise Linux (RHEL) systems administration
  • Bachelors degree (Cybersecurity, Engineering, Computer Science, or related IT fields)
  • Active DoD 8570 Level II Certification (e.g. Security+ CE, CCNA Security, etc.)

Desired Skills

  • Skilled in the use of Enterprise Mission Assurance Support Service (eMASS)
  • Knowledgeable with Supply Chain Cyber Risk Management (SCRM)
  • Knowledge of cybersecurity principles and DoD requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
  • Knowledge of IT security principles and methods (e.g., firewalls, demilitarized zones, encryption, zero trust)
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code)

Clearance Information

SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE SECRET LEVEL WITH TOP SECRET / SCI ELIGIBILITY

Travel Requirements

  • Some travel up to 25% yearly

About Us

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

EEO

Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.

All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.

Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

About the Company

S

Scientific Research Corp

Scientific Research Corporation is an advanced engineering company that was founded in 1988 to provide innovative solutions to the U.S. Government, private industry, and international markets. Since its inception, SRC has continued to successfully meet em
COMPANY SIZE
2,500 to 4,999 employees
INDUSTRY
Aerospace and Defense
FOUNDED
1988
WEBSITE
http://www.scires.com