Description:
This position is for the NCRC Range Modernization (RM) Senior Security Engineer position providing senior-level development, testing, and security support associated with their designated NCRC product scrum teams.
Responsibilities
- Vulnerability Management
- Implementing patching procedures for multiple Operating Systems (Linux, Windows, VMware, Cisco)
- Running and reviewing vulnerability scans and STIGs
- Prioritizing vulnerability remediation efforts across endpoints, networks, and applications
- Automating patching process for multiple Operating Systems (Linux/Windows)
- Responsible for securing and hardening hardware and software systems.
- Governance, Risk & Compliance
- Supporting tracking resolution and milestones for program's Plan of Action and Milestones (POA&M) items
- Developing and maintaining security policies, procedures, and standards
- Ensuring compliance with relevant standards, directives and regulations
- Conducting risk assessments and supporting audit activities
- Remaining abreast of emerging technologies, cyber threats and security tools
- Security Architecture & Engineering
- Designing, implementing, and managing security solutions (e.g., SIEM, EDR, firewalls, IDS/IPS, IAM, VPN)
- Evaluating and integrating new security technologies and tools
- Advising ISSO and ISSM on issues related to securing and monitoring classified DoD networks
- Creating and maintaining of data flow and system boundary diagrams
- Agile/Scrum process
Requirements
- Must be a U.S. citizen and have an active clearance
- Bachelor’s (BS) degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
- Strong understanding of network protocols, security architecture, and security practices
- Experience with Linux-based and Windows-based systems
- Proficient in scripting (e.g., Python, PowerShell, Bash)
- Experience with automation tools (e.g., Ansible, Terraform, Chef, Puppet)
- Understanding of CI/CD
- In-depth knowledge of modern threat landscapes, vulnerabilities, mitigation techniques, and security tools and processes
- Familiarity with NIST 800-53, NIST 800-171, SOC 2 and/or ISO 27001
- Ability to write clear and concise cybersecurity guidance, procedures and documentation
- Security+ Certified
Desired Skills
- DoD RMF security practices and regulations
- Virtualization (preferably VMware)
- Familiarity with open-source security tools
- Familiarity with ACAS, Tenable Security Center, and Tenable Nessus