Responsibilities
- Supporting the response for planned and unplanned security assessments including documentation collection and review, documentation creation and maintenance, and artifact/evidence review and validation.
- Analyzing and investigating potential security threats against technologies in use as well as those planned for future use.
- Performing an ongoing review of industry/government best practices for system security to provide expert technical guidance for translating NIST, DHS, and TSA cybersecurity standards, policies and procedures into actionable tasks.
- Determining the security impact of new technologies or policies on the TSA information security program.
- Developing and presenting recommendations for changes to improve security posture.
- Implementing security improvements as needed for protecting mission critical systems.
- Leveraging existing government-provided security scan tools such as Tenable Security Center, Nessus, DbProtect, Venafi, Burp Suite Pro and others.
- Providing security engineering subject matter expertise in coordination with enterprise architecture and technical review boards.
- Developing and maintaining information security program strategic and tactical goals and objectives and program outreach/communication plans.
- Identifying, developing, and maintaining a performance management program, that includes performance measures, tracking metrics, and trend analysis.
Requirements
- 15+ years of work experience in IT and cybersecurity, with a technical background in networking, operating system, and/or software development
- Active Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification
- Experience with security development lifecycle management, DevSecOps, and CI/CD integration
- Ability to leverage programming languages where feasible such as Java, PHP, C, .NET, Go, or Python
- Experience with various operating systems including Windows, Linux and Unix
- Strong leadership and interpersonal skills to facilitate effective collaboration across a variety of stakeholders
- Demonstrated ability to function independently and define the proper methods & procedures
- Understanding of guiding cybersecurity principles and control guidance
- Effective writing skills to capture issues and recommendations
- Strong customer relationship building ability
- Education Requirement: Bachelor’s degree
- Required Certification(s): Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM)
- Minimum Years of Overall Experience: 15+
- Minimum Years of Specific Experience in Field: 5
- Minimum Clearance to Start: Secret
- Work Status Allowable: US Citizenship
Work Arrangement
Hybrid
Additional Information
- Travel: Little (less than 10%)
- Telecommute Options: Yes. Hybrid: 2 days onsite one week, 3 days onsite the next.
- On-call: Required periodically, with annual coverage varying up to 3-4 months