Responsibilities
- Assist developing layered protections and establish cybersecurity SOPs or guidelines for authorization boundaries.
- Perform vulnerability management and implement fix actions across Windows, Linux/Unix, and containerized environments.
- Engineer and automate and deploy security remediation configurations using tools such as Ansible and scripting in Python and Bash.
- Implement and maintain DISA STIGs and CIS Benchmarks across diverse platforms, including RHEL, Ubuntu, Windows operating systems, VMware/ESXi, and 3rd-party applications, as well as network devices such as Cisco (NXOS, ASRs, IOS-XE, ASA) and Juniper.
- Support container security engineering with Docker and related technologies.
- Conduct vulnerability scans using ACAS, interpret results, and drive remediation efforts.
- Collaborate with developers to ensure secure coding practices and integrate security into CI/CD pipelines.
- Delineate physical and logical security boundaries for systems and networks.
- Ensure software developers are trained on secure software development practices.
- Generate and interpret vulnerability scans, implement STIGs and CIS Benchmarks, and support RMF Continuous Monitoring activities, including remediating and/or mitigating findings on system POA&Ms.
Requirements
- Intermediate to advanced knowledge of NIST SP 800-53 security controls and CNSSI 1253
- Experience with system hardening, automation, and vulnerability remediation
- Ability to provide systems security engineering and architecture principles in support of RMF
- Experience in specification, design, development, implementation, and modification of information system components
- Ability to select, tailor, and implement NIST SP 800-53 security controls for RMF Assessment and Authorization (A&A)
- Hands-on technical expertise in cybersecurity
- Experience applying security engineering principles
Work Arrangement
Hybrid — San Antonio, Augusta, Fort Meade area
Additional Information
- Support for Department of Defense (DoD), Risk Management Framework (RMF), and Intelligence Community Directive (ICD) 503
- Must be able to work in hybrid mode with possible locations in San Antonio, Augusta, and the Fort Meade area