Information System Security Engineer
Anavation
Job Summary
AnaVation is seeking a dedicated Information System Security Engineer (ISSE) to join their team, responsible for the development, operations, and maintenance of networked systems for digital forensic investigations. The role involves ensuring system security posture through planning, analysis, development, and implementation of security programs, infrastructure, applications, and Security Assessment and Authorization (SAA). The ISSE will develop compliance and standardization within customer policies, work with government clients to maintain confidentiality, integrity, and availability of systems, and prepare documentation for compliance. Key responsibilities include identifying IA vulnerabilities, coordinating with teams for mitigation, reviewing vulnerability and compliance scans, preparing SAA packages for authority-to-operate (ATO), attending Configuration Control Board meetings, coordinating security incident responses, and assessing current and evolving security threats. The position requires strong communication skills, ability to work independently and as part of a team, and demonstrated experience with the Federal ATO process.
Must Have
- 10+ years experience assessing systems against NIST SP 800-53
- Experience with Risk Management Framework (RMF)
- Bachelor's degree in Computer Security or related field
- Active Top Secret clearance
- Ability to obtain CI polygraph
Good to Have
- Experience working on an Agile team
- Experience with federal law enforcement organization
- Willingness to implement Lean principles, Agile engineering, DevSecOps
- Technical background knowledge
- Understanding of taclans, coding, and scripts
- Splunk and Tenable experience
- Ability to read technical diagrams and dataflows
- Understanding of JRC and RMF steps
- Team-oriented and collaborative personality
- Experience with cyber-risk and compliance management systems
- Experience configuring and assessing vulnerability scans
- Knowledge of operating systems and network security
- Knowledge of SPLUNK software
- Knowledge of Taclane, encryption devices, and COMSEC
Perks & Benefits
- Generous cost sharing for medical insurance
- 100% company paid dental insurance
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance
- 401k plan with generous match
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance
Job Description
- Ten (10) years of experience or more assessing and documenting results for system(s), infrastructure(s) and applications (on-premises and cloud (i.e., AWS GovCloud and/or Azure GovCloud)) against NIST SP 800-53 security controls and SP 800-171 Risk Management Framework (RMF) processes.
- Bachelor of Science (B.S.) Degree in Computer Security or related field of study; (ISC)2 Information Security Certification(s) (e.g., CISSP, CAP, etc.); or in lieu of education, an additional five (5) years of relevant experience that addresses all requirements of the position.
- Requires an Active Top Secret clearance and the ability to obtain an CI polygraph
- Experience working on an Agile team
- Experience working with a federal law enforcement organization
- Willingness to implement Lean principles, Agile engineering and DevSecOps
- Desire longevity on the project.
- Technical background desired, knowledge broader in scope.
- Have an understanding of taclans, basic coding, and scripts.
- Splunk and Tenable experience desired.
- Need to be able to read technical diagrams, dataflows, create workflows, read network diagrams. Understand JRC and the 6 steps of the Risk Management Framework.
- Have a team perspective, invite collaboration, the personality needs to be one of investment. Need to connect and to learn. Be function driven. They need to have an accountability to the program, be on time, personable, positive
Desired Qualifications:
- Experience in a cyber-risk and compliance management system (e.g., Xacta, RiskVision, etc.).
- One (1) year experience or more configuring, performing, scheduling, reviewing, and assessing vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance on-premises and in the cloud (Azure preferred).
- Technical background that will assist in assessing the NIST SP 800-53 security controls and gather evidence to support conclusions.
- Knowledge of operating systems, network and application security to aid implementation of information security and assurance principles.
- Knowledge of SPLUNK software and tools.
- Knowledge of Taclane, encryption devices and COMSEC technology.
Benefits
· Generous cost sharing for medical insurance for the employee and dependents
· 100% company paid dental insurance for employees and dependents
· 100% company paid long-term and short term disability insurance
· 100% company paid vision insurance for employees and dependents
· 401k plan with generous match and 100% immediate vesting
· Competitive Pay
· Generous paid leave and holiday package
· Tuition and training reimbursement
· Life and AD&D Insurance