Cyber Security Software Integration Engineer
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Cybersecurity engineer integrating secure cloud software factories for SAIC’s defense and space missions. Supporting RMF, vulnerability assessments, ATOs, and DoD compliance for SDA’s BMC3 program.
Responsibilities:
- Support BMC3 AppFac active cyber defense operations in the DOD AWS CloudOne
- Provide engineering analysis and security recommendations for design implementation and operational execution
- Perform computer and network security vulnerability assessments to identify, evaluate, and mitigate risks, threats, and vulnerabilities using SD Element
- Develop the Authorization & Assessment (A&A) body of evidence to meet DoD and Federal directives
- Monitor security audit and intrusion detection logs for system and network anomalies
- Monitor technical access-control methods to maintain system and data integrity
- Achieve CtFs or ATOs across multiple government customers with minimal oversight
- Conduct and manage continuous monitoring activities for assigned systems
- Partner with engineers to analyze software, interpret security requirements, and plan control implementations
- Provide customer service, policy expertise, and high-quality documentation
- Serve as the primary in-person point of contact for U.S. Government customers on cybersecurity and compliance requirements
- Perform network vulnerability scans, provide remediation alternatives, and conduct security risk assessments
- Bridge high-level security requirements and policies into IT components and information systems through security design or configuration
- Provide security consultation and engineering guidance to product owners, customers, system owners, and developers
- Coordinate security processes within the Department’s lifecycle management and governance process
- Discern technical and administrative cybersecurity and A&A requirements and develop project plans and schedules
- Interpret vulnerability scan findings from ACAS (Tenable Nessus) and SCAP (STIG benchmark)
- Manage POA&Ms for remediation findings
- Assist customers in identifying security solutions for networks, VPNs, application systems, public key infrastructures, authentication, and directory services
Requirements:
- Bachelor’s degree and 5 years or more experience, or master’s degree and 3 years or more experience
- Technical experience accepted in lieu of a degree
- Knowledge of the DoD Risk Management Framework (RMF) lifecycle (Step 1–Step 6)
- Knowledge of selecting and engineering security controls via NIST SP.800-190
- Knowledge of selecting and engineering National Security System security controls via CNSSI 1253
- Knowledge of assessing technical and administrative security-control implementation in accordance with NIST.SP.800-190
- Knowledge of the Enterprise Mission Assurance Support Service (eMASS)
- Knowledge of applying security controls to Unix variants, Microsoft operating systems, and Linux operating systems
- Knowledge of networking, software development, scripting languages, software integration, or related skills
- Knowledge of networking protocols and security technologies including encryption, IPsec, PKI, VPNs, firewalls, proxy services, DNS, and access-lists
- Knowledge of DoD Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and industry best practices
- Knowledge of Certificate to Field (CtF) policies
- Must be a U.S. citizen
- Must have an active Secret clearance
- Possess a DoD 8570 IAT Level II certification, such as Security+, or be able to obtain it within 60 days
Benefits:
- Primarily remote work arrangement
- Opportunity to mentor junior developers
- Opportunity to leverage leadership abilities
- Exposure to advanced security and automation practices
- Opportunity to work with highly skilled engineers and architects



















