Cybersecurity Engineer
Sign up free to see how well your resume matches this role.
About this role
SAIC® is a premier Fortune 500® mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, civilian and intelligence markets includes secure high-end solutions in mission IT, enterprise IT, engineering services and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.
We are seeking a highly motivated Information System Security Officer (ISSO) to conduct research and analysis for our NGA N2W customer. This role is responsible for advising on network and information system security principles and best practices, advise on applicable government IC and Agency IT policies, procedures and operation instructions for IT, Information Assurance, and Information Management (IT/IA/IM), and perform periodic security scanning as required by the Office of the Under Secretary of Defense (OUSD).
Responsibilities will include the following:
- Operate within cleared environments to perform Information Assurance specific activities for customer needs and timelines.
- Perform assessments of systems and networks within the networking environment or enclave and identify where those systems or networks deviate from acceptable configurations, enclave policy, or applicable Agency policies and guidelines. Perform compliance audits (passive evaluation) and vulnerability assessments (active evaluation).
- Develop Risk Management Framework (RMF) process operating procedures, policies, and related documentation.
- Perform duties per NIST SP 900-137, Continuous Monitoring, and audit for anomalous or malicious user activity.
- Periodically review audits of all systems and monitor corrective actions to ensure closure of all action items.
- Manage media, including handling and control, labeling, virus-scanning solutions, and data transfers between classification domains via manual and automated processes.
- Create and enforce strict program control processes to ensure risk mitigation, system accreditation, and certification attainment support. Support will include process support, analysis support, coordination support, security certification test support, security documentation support, investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits.
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.