Responsibilities
- Develop layered protections and establish cybersecurity SOPs or guidelines for authorization boundaries.
- Apply system development life cycle principles such as Agile (preferred).
- Perform vulnerability management and implement fix actions across Windows, Linux/Unix, and containerized environments.
- Engineer and automate security configurations using tools such as Ansible and scripting in Python.
- Implement and maintain DISA STIGs and CIS Benchmarks across diverse platforms, including RHEL, Ubuntu, Windows operating systems, VMware/ESXi, and 3rd-party applications, as well as network devices such as Cisco (NXOS, ASRs, IOS-XE, ASA) and Juniper.
- Manage Linux administration and package management, as well as Windows Domain Controller compliance.
- Support container security engineering with Docker and related technologies.
- Conduct vulnerability scans using ACAS, interpret results, and drive remediation efforts.
- Collaborate with developers to ensure secure coding practices and integrate security into CI/CD pipelines.
- Generate and interpret vulnerability scans, implement STIGs and CIS Benchmarks, and support RMF Continuous Monitoring activities, including remediating and/or mitigating findings on system POA&Ms.
Requirements
- Intermediate to advanced knowledge of NIST SP 800-53 security controls and CNSSI 1253.
- Strong security engineering principles and hands-on technical expertise.
- Experience in system hardening, automation, and vulnerability remediation.
- Ability to select, tailor, and implement NIST SP 800-53 security controls for RMF Assessment and Authorization (A&A).
- Experience implementing and maintaining DISA STIGs and CIS Benchmarks across diverse platforms including RHEL, Ubuntu, Windows, VMware/ESXi, and third-party applications.
- Experience with network devices such as Cisco (NXOS, ASRs, IOS-XE, ASA) and Juniper.
- Linux administration and package management skills.
- Windows Domain Controller compliance management experience.
- Container security engineering experience with Docker and related technologies.
- Vulnerability scanning and remediation using ACAS.
- Scripting in Python and use of automation tools such as Ansible.
- Application of Agile methodology in system development life cycle.
- Delineation of physical and logical security boundaries for systems and networks.
- Guidance on encryption techniques and tools as part of system security engineering.
- Training software developers on secure software development practices.
- Support for RMF Continuous Monitoring and POA&M remediation.
Nice to Have
- Agile methodology experience (preferred).
Work Arrangement
Hybrid — San Antonio, TX, Augusta, GA, Fort Meade, MD
Additional Information
- Must support Department of Defense (DoD), Risk Management Framework (RMF), and Intelligence Community Directive (ICD) 503.
- Requires intermediate to advanced knowledge of NIST SP 800-53 security controls and CNSSI 1253.
- Must have hands-on technical expertise in system hardening, automation, and vulnerability remediation.
- Must be able to delineate physical and logical security boundaries for systems and networks.
- Must provide guidance on encryption techniques and tools as part of system security engineering.
- Must ensure software developers are trained on secure software development practices.
- Must support RMF Continuous Monitoring activities, including remediating and/or mitigating findings on system POA&Ms.