Information Security Compliance Specialist
Reston, VA Jobs
Salary:
Job Summary: The Information Security Compliance Specialist is responsible for identifying risks and ensuring the organization remains compliant with industry standards, relevant laws, and regulations. This role is instrumental in maintaining ISO 27001 and ISO 27701 certifications, as well as achieving and sustaining compliance with NIST 800-171. The Compliance Specialist will streamline audits, maintain certifications, and develop policies to uphold data security commitments. This position requires strong attention to detail, knowledge of compliance frameworks, and the ability to work collaboratively across departments.
Essential Functions
Ensure ongoing compliance with ISO 27001, ISO 27701, GDPR and NIST 800-171 requirements.
Develop, implement, and update security policies and procedures to meet regulatory and industry compliance standards.
Coordinate and support internal and external security audits, including audit preparation and response.
Conduct risk assessments to identify compliance gaps and recommend corrective actions.
Monitor changes in regulations and industry standards to ensure continued compliance.
Collaborate with IT and security teams to align compliance initiatives with security operations.
Provide training and guidance to employees on security policies and best practices.
Maintain compliance documentation and ensure proper record-keeping for audits and assessments.
Act as a liaison with auditors, regulators, and third-party assessors regarding security compliance matters.
Assist in incident response efforts to ensure compliance with reporting and documentation requirements.
Required Knowledge, Skills, Abilities
Strong understanding of ISO 27001, ISO 27701, and NIST 800-171 compliance requirements.
Experience conducting risk assessments and implementing security controls.
Knowledge of cybersecurity frameworks, regulatory standards, and industry best practices.
Ability to develop and document security policies, procedures, and controls.
Strong analytical skills to evaluate compliance risks with the ability to work across departments to meet compliance goals and recommend mitigation strategies.
Excellent organizational and project management skills to track and manage compliance initiatives.
Effective communication skills to provide training and collaborate with cross-functional teams.
Familiarity with security tools and technologies that support compliance efforts.
Required Education, Certifications/ Licenses, Related Experience
Bachelor's degree in Information Security, Cybersecurity, Compliance, or a related field (or equivalent experience).
Experience in ISO 27001, ISO 27701, NIST 800-171, and GDPR framework
Industry certifications such as CISA, CISM, CISSP, or ISO 27001.
Minimum of 3 years of experience in information security compliance, risk management, audit, or related field.
In lieu of degree, a total of 8 years of experience in related field (in addition to the management experience required) will meet the education and related experience requirements listed above.
Physical Job Requirements
Ability to work in an office environment with extended periods of desk work.
May require occasional lifting of equipment or documentation materials.
Ability to respond to compliance-related inquiries outside of regular business hours if needed.
Travel Requirements
Occasional travel may be required for training, conferences, or collaboration with remote teams.
Anticipated travel will be by car, air, and/or train
Securiport is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Securiport is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. Please see the United States Department of Labor'sEEO posterand EEO poster supplementfor additional information.
Disclaimer: Nothing in this restricts management's right to assign or reassign duties and responsibilities to this job at any time. The above statements are intended to describe the general nature and level of work being performed by people assigned to this position at the time this job description was written. They are not intended to be an exhaustive list of all duties, responsibilities and skills required of personnel so classified. This document does not create an employment contract, implied or otherwise, and all employees in this position are employed at-will.
Systems Engineer
Annapolis, MD Jobs
Our Mission At Dobbs Defense, we deliver mission-centric IT, Cyber, and data analytics solutions for our government and commercial clients through the convergence of automation, innovation, training, and education. Delivering high-quality IT, cybersecurity, and data analytics solutions through proven and innovative methods is our vision.
Job Description
Dobbs Defense Solutions is seeking a Systems Engineer to join our team. The Engineer will install, maintain, configure, and optimize Microsoft server operating systems. The Engineer will be responsible for manage and configure VDI environments. The Engineer will also Configure and maintain network services such as DNS and DHCP.
Duties
Knowledge in creating, administering, and troubleshooting Group Policies (GPOs).
Perform daily system monitoring, verifying the integrity and availability of all hardware, server resources, systems and key processes, reviewing system and application logs, and verifying completion of scheduled jobs such as backups
Work with internal and external IT teams to coordinate changes, implementations, and maintenances for network and security configurations
Support the administration of Microsoft SQL databases.
Develop and implement security measures to protect against unauthorized access, data breaches, and other cyber threats
Apply STIGs to IT systems and document results.
Review STIG checklists developed by others for accuracy and completeness.
Develop RMF security policy and procedures documents.
Qualifications
Required education and experience:
Experience in Infrastructure/Datacenter engineering and integration for both physical and virtual infrastructure hosting one or more Operating Systems: Windows, Linux, Solaris, UNIX, and/or AIX systems
Experience with one or more engineering disciplines:
Storage Engineering: multiple enterprise HPE Storage Area Networks (SAN)
Network Engineering: Cisco network LAN/WAN, Software Defined Networking (SDN)
Infrastructure/Cloud Engineering: VMware vCloud Enterprise Suite; hybrid cloud with multiple classified Government clouds
Current DoD 8570.1-M IAT Level II certification (i.e., Security+ CE, etc.)
Required Clearance
TS/SCI
Working Environment
Onsite
Our Equal Employment Opportunity Policy
Dobbs Defense Solutions is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth or breastfeeding), sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), gender expression and transgender status, national origin, ancestry, age, disability, military or veteran status, marital or domestic partner status, genetic information, citizenship, low-income status or any other status or characteristic protected by applicable law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
Powered by JazzHR
aFlMsT2KqI
SCCM/MCM System Engineer
Annapolis, MD Jobs
The Digital Services Endpoint Management Team requires an experienced Microsoft SCCM/Microsoft Configuration Manager (MCM) system engineer to perform all aspects of SCCM administration, maintenance, and operation of the SCCM Global Enterprise Solution used for Microsoft patch management, software distribution, operating system deployment, and hardware and software inventory across multiple networks. Duties include monitoring SCCM infrastructure system health; managing boundaries and collections; making required configuration changes; and investigating, analyzing and resolve technical issues and actively pursue mechanisms for preventing, or automating the response to reoccurrences.
The candidate will ensure the SCCM infrastructure functions properly with PKI-based authentication, corporate authorization services, firewalls, and SSL/TLS communications.
The candidate will contribute to development and ongoing improvement of industry best practices and standards for deploying enterprise desktop technologies.
The candidate will assist with the Enterprise Microsoft monthly patch ingest/test/deployment cycle (Patch Tuesday).
The candidate will assist with testing and deploying hotfixes/patches/new releases to the SCCM Infrastructure.
The candidate will assist with development of knowledge articles, documentation, and work instructions used by the SCCM, server, desktop teams, Tier 2/3 Help Desk technicians and remote/deployed units.
Critical Skills:
The ideal candidate will have 3+ years direct experience in the implementation, administration, and configuration of SCCM in a global enterprise environment (for hundreds to thousands of endpoints) across multiple air-gap networks.
5-10 years computer/IT professional experience with Windows Server Administrator; Win Server 2016, 2019 or 2022 OR Windows SQL Server.
Extensive working knowledge of and troubleshooting experience with standard (Windows) client platform administration, configuration, rights management and file access permissions needed to remediate issues.
Must be proficient with troubleshooting Windows Desktop and Server OS
Experience managing a desktop OS image for large corporate environments coupled with experience with desktop deployment automation architecture, design/migration and troubleshooting is highly preferred.
Extensive working knowledge of the Windows registry, interaction of drivers within the OS, and unattended/silent installs of Windows operating systems is highly preferred.
Must be a self-starter with strong attention to detail.
Advanced troubleshooting skills and ability to diagnose complex issues.
Excellent communication and interpersonal skills
Firewall Configuration
Microsoft System Center Configuration Manager (MS SCCM)
Patch Management
Process Documentation
Rights Management
Setting up Permissions
Strong understanding of TCP/IP networking, DNS, SSL/TLS, and related protocols.
Image Processing
Proficiency in scripting languages (e.g., PowerShell) for automation and configuration management tasks
Qualifications:
Fourteen (14) years of experience as an SE in programs and contracts of similar scope, type and complexity is required.
Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or related discipline from an accredited college or university is required.
Five (5) years of additional SE experience may be substituted for a Bachelor's degree.
Requirements:
U.S. Citizenship is required for all applicants. CTP is an equal opportunity employer and abides by applicable employment laws and regulations. All applicants and employees are subject to random drug testing in accordance with Executive Order 12564. Employment is contingent upon successful completion of a security background investigation and polygraph.
Certification Requirements:
DOD 8570 Certification IAT Level 2 Compliance Required (Security+ CE)
This position requires an active Security Clearance with appropriate Polygraph.
About us:
Founded in 2007,
Columbia Technology Partners
is Woman-Owned, Service-Disabled Veteran Owned Small Business with a specialization in technology and management consulting committed to solving intricate and sensitive technology issues facing corporations and federal agencies. Since its inception, CTP has been instrumental in the technical design, engineering development, operational deployment, and support of key systems. With a proven track record in information security, project management, systems/network engineering, security risk management, vulnerability assessments, and mobile security implementation; our employees have the experience, expertise, and innovative thinking our customers need for results that exceed expectations. CTP staff have worked closely with both government engineers and management to gather mission requirements, develop the architecture to deliver the needed functionality and assess tools available to meet or exceed the needs of the mission.
At Columbia Technology Partners (CTP), we are united in being the best that we can be as individuals, but our core belief is that we can be better together. Together we will take on each mission with an execution process that authentically represents who we are. Our success relies on our team values, the foundation we built around them, and the Partners we become along the way.
That's why our pay is competitive, our missions are critical, and our benefits
represent what matters
most to CTP: Our People.
Salary Range Transparency
At Columbia Technology Partners we are committed to transparency and fairness in our compensation practices. We believe in creating a work environment where employees feel valued, empowered, and rewarded for their contributions.
How We Determine Salary Ranges
Our salary ranges are based on the following key factors:
Job Role and Responsibilities: The specific duties and responsibilities associated with each role form the foundation of our compensation structure.
Market Research and Industry Benchmarks: We conduct regular analysis of market trends and salaries across our industry, using reliable compensation data to ensure we stay competitive.
Experience and Qualifications: An individual's experience, education, certifications, and specialized skills all contribute to determining their position within a salary range.
Location: Salary ranges may be adjusted based on geographic cost of living, in accordance with local and national standards.
Company Performance: Our compensation practices also take into account overall company performance and financial health, ensuring that we maintain sustainability while rewarding our team.
Really good benefits, for really GREAT people:
From our CTP Family to yours, we know how important these decisions are. Your benefits are about you, not us. Tell us what you need in order to see a future at CTP; lets get where you're going, together.
Medical: CTP offers 3 superior plans, bringing our employees both in-network and out-of-network options.
Vision + Dental: Both free to you + paid in full by CTP.
Retirement: 401k - 6% company contribution
PTO + Leave: A work life balance is extremely important to our team here at CTP, which is why our paid time off plans are so lucrative. Offering customizable leave plans to meet your needs is just one of our many perks! Jury Duty, Bereavement + Military Leave provided.
Career Growth: Up to $10,000 provided for approved career-related learning, training, education, and/or tuition.
Life and AD&D Insurance/Short-Term & Long-Term Disability: More peace of mind, at zero cost to you.
Profit Sharing Bonus: End of year cash gets added to your bottom-line.
Referral Bonus Program: Our tiered program provides an incentive with each stage of the hiring process your referral passes. Our bonuses range from $7,000-$20,000, if your referral joins the team.
Columbia Technology Partners
is an Equal Opportunity Employer. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, or membership in any other group protected by federal, state, or local law. Our EEO policy reflects our commitment to ensure equality and promote diversity and inclusion in the workplace. Our policy applies to all employees, job candidates, contractors, stakeholders, partners, and visitors.
CTP was voted one of the top 25 best places to work in Baltimore by Baltimore Magazine!
Security Engineer
Wheeling, IL Jobs
Benefits:
401(k)
401(k) matching
Dental insurance
Health insurance
Opportunity for advancement
Paid time off
Vision insurance
The Security Engineer is expected to perform a combination of cyber security functions such as deployment, maintenance, testing, and investigation of cyber security products, to ensure secure internal network protocols are implemented.
This role will use problem solving based on the company's security, policy and compliance requirements as well as combination of forensic and analytical and technical skills in reviewing network interfaces and activities.
Responsibilities:
Maintains all security systems and their corresponding or associated software, such as firewalls, intrusion detection/prevention systems, vulnerability management, SIEM, and anti-virus software.
Monitors and reports on security systems and end user activity audits.
Triages potential security incidents, assist with resolution and escalates to incidence response Manager/Team as needed.
Maintains and monitors endpoint protection software such as antivirus, MDR, and other security-oriented endpoint protection platforms.
Recommends, schedules (where appropriate), apply fixes, security patches, assist with disaster recovery procedures, and any other measures required in the event of a security breach.
Assist with remediation identified through the Vulnerability and Penetration testing.
Implement scripting where applicable to automate processes.
Assists with monitoring the overall operation of networks/Systems and participates in cyber security related problem resolutions.
Assist with performing remediations based on audit requirements and identified gaps.
Contacts hardware and software vendors to resolve technical problems.
Provides end-user support and training for security related products, practices, and policies.
Assist with deployments and maintenance of tools related to MDM, RBAC, PAM, IAM, Configuration management etc. to comply with HITRUST and SOC 2TYPE ii domain controls.
Provides technical services to relating to use, operation, and management of technology.
Keeps current with emerging cyber security events, trends and threat sources.
Performs other duties as assigned.
Minimum Required Qualifications:
Bachelor' s Degree or higher (Management Information Systems, Decision and Information Sciences, Computer Information Systems, Computer Sciences, Accounting/Finance, etc.) or equivalent experience.
At least three years of IT Security tools deployment experience OR at least four (4) years of experience in Information Security analysis.
Proficiency in communication, strong verbal skills.
Strong project management skills and technical skills around security related tools.
Possesses proficient understanding of: IT general controls (e.g., security, change management, disaster recovery & backup, infrastructure, etc.); SDLC/Agile methodologies, cybersecurity, and cloud.
Possesses intermediate understanding of operating system and database platforms (e.g., mainframe, Active Directory, Windows, Linux, Oracle, etc.); network architecture; IT governance processes; IT risk management and assessment processes.
Preferred Certifications:
Security +
GIAC GSEC (Global Information Assurance Certification)
SSCP (Systems Security Certified Practitioner)
Additional Qualifications:
Broad hands-on knowledge of firewalls, intrusion prevention/detection systems, anti-virus software, data encryption, and other industry-standard techniques and practices
In-depth technical knowledge of network, PC, and platform operating systems
Working technical knowledge of current systems software, protocols, and standards
Strong knowledge of TCP/IP and network administration/protocols
Familiarity with security frameworks such as, ISO 27001, SOC 2 TYPE II, HITRUST etc.
Intuition and keen instincts to pre-empt attacks
Ability to develop basic scripts in languages such as PowerShell or Python
Knowledge of applicable practices and laws relating to data privacy and protection
High level of analytical and problem-solving abilities
Ability to conduct research into security issues and products as required
Strong understanding of the organization's goals and objectives
Strong interpersonal and oral communication skills
Highly self-motivated and directed
Strong organizational skills
Excellent attention to detail
Ability to effectively prioritize and execute tasks in a high-pressure environment
Experience working in a team-oriented, collaborative environment
Flexible work from home options available. Compensation: $85,000.00 per hour
Our Story At Tree Top Staffing, we take pride in helping job seekers find their ideal role and employers find the right candidate for their company. Our organization is instantiated by experienced professionals providing full service employment solutions including: contract, contract-to-hire, and direct-hire placements within multiple lines of business.
Our Mission We adhere to a set of 4 defining principles encapsulating:
Servitude
Accountability
Integrity
Discipline
If you make a promise, keep it, as your actions prove your greatness. Our goal at Tree Top Staffing is to set our clients and consultants up for success. It is imperative to ensure an all-around fit from both sides for long term relations to thrive.
Our Results Tree Top Staffing utilizes advanced recruiting tools to ensure top talent is presented to our clients when their needs arise.
Our success is measured by the success of our clients. It is a privilege to help job seekers find their dream position and employers find the right fit for their company.
Security Engineer
Fort Washington, PA Jobs
Summary/Objective
The Security Application Engineer position plays an active role with sales support, engineering, operations, and customer support. Responsibilities include the support of installation, programming, and expansion of Card Access, IP Video, Paging, Intercom, Fire Alarm, and Intrusion systems for customers throughout the Pennsylvania, New Jersey, and Delaware region.
The Security Applications Engineer must be able to articulate technology, design and product positioning as well as maintain strong relationships throughout the design, estimating, and sales cycle with Sales and Operations.
Essential Functions
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Proficiency in CAD software for creating technical drawings and schematics.
Strong understanding of fire alarm codes, standards, and regulations.
Plan and perform sophisticated integration programming.
Provide in-house programming and application support functions for field staff.
Provide installation guidelines and best practices.
Provide training to internal and external users.
Startup, load, and deploy new system servers and archivers
Interface with customer IT departments to coordinate network connectivity for new installations and expansion projects.
Provide technical support for installation technicians, sub-contractors, and customers.
Make recommendations regarding systems installations.
Review sales estimates for technical accuracies and make recommendations and changes as required.
Other duties as assigned
Competencies
Fully proficient and independent design skills.
Good verbal and written communication skills.
Ability to manage a varied and heavy workload and set priorities.
Ability to adapt to changes in the work environment, delays, or unexpected events; manage competing demands; change approach or method to best fit the situation.
Ability to read schematic and/or construction plans
Strong organizational and self-motivated skills with a professional attitude.
Constant use of discretion and problem analysis.
Frequent use of judgment and independent action.
Understands process of construction projects and the requirements to document all changes or deviations to specifications and project scope of work.
Knowledge of network communications technology.
Knowledge of building codes and standards.
Ability to work remotely, hybrid schedule and in the office as needed
Supervisory Responsibility
This position has no supervisory responsibilities.
Work Environment
This position operates in an office setting as well as customer jobsites in an environment that may contain dust, noise, oils, greases, grinding debris, compressed air, metal shavings, propane and solvents.
Physical Demands
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
While performing the duties of this job, the employee is regularly required to read, count, type and write to accurately complete all documentation; sitting, standing, bending and lifting also necessary. This position requires occasional heavy lifting.
Position Type/Expected Hours of Work
This is a full-time position. Standard days and hours of work are Monday through Friday, 8 a.m. to 5 p.m.
Travel
Travel to customer/prospect sites on a regular basis as needed to complete job specific duties.
Required Education and Experience
4 plus years of installation, design, and/or maintenance of Card Access, IP Video, Paging, Intercom, Fire Alarm, and Intrusion systems or other related experience.
High School Diploma or GED Equivalency at minimum
Individual must possess a valid Driver's license in good standing.
Qualified Applicants must be legally authorized to work in the United States.
Preferred Education and Experience
Vocational classes in Electrical Engineering or Electrical Design related to this job.
Associates degree in Electronics or other technical field or equivalent experience preferred.
Related Systems Manufacturers Certifications in Installation and Programming.
NICET Certification in Fire Alarm Systems Level II or higher.
Work Authorization/Security Clearance (if applicable)
Criminal Background Check, PA Child Welfare clearance and FBI fingerprinting clearance required, DMV check
AAP/EEO Statement
CM3 Building Solutions, Inc. is an affirmative action employer and does not consider disability, color, gender identity, genetic information, military or veteran status, national origin, race, religion, sex, sexual orientation, age 40 and over, or any other applicable status protected by state or local law, in any employment decision.
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Security Engineer
Reston, VA Jobs
Salary:
Job Summary: The Security Engineer is responsible for identifying, analyzing, and mitigating security threats while ensuring the organization's cyber defenses remain strong. This role focuses on implementing advanced security measures, monitoring network activity, and responding to cyber incidents in a timely and effective manner. The Engineer will work closely with IT and security teams to enhance the organization's overall security posture and protect critical data from potential breaches.
Essential Functions
Design, implement, and maintain security solutions to protect IT infrastructure and sensitive data.
Manage and maintain Security Operations Center functions, including the monitoring and analysis of security events, alerts, and incidents.
Conduct risk assessments,
Lead and coordinate incident response activities, including investigation, containment, and remediation.
Develop and enforce security policies, procedures, and best practices.
Conduct vulnerability assessments and penetration testing to identify security gaps.
Configure, deploy, and manage EDR/XDR solutions to detect and respond to threats on endpoints across the organization.
Investigate and analyze security breaches to determine root causes and implement corrective actions.
Collaborate with IT teams to ensure secure configuration of networks, servers, and endpoints.
Provide recommendations and deploy security tools such as firewalls, intrusion detection systems (IDS), and endpoint protection.
Stay updated on emerging cybersecurity threats, industry best practices, and regulatory compliance requirements.
Oversee security configurations for Office 365, ensuring best practices are followed in access controls, monitoring, and incident detection in cloud services.
Train staff on cybersecurity awareness and promote security best practices across the organization.
Document security incidents, response actions, and resolution processes for continuous improvement.
Required Knowledge, Skills, Abilities
Strong understanding of cybersecurity principles, frameworks, and methodologies.
Proficiency in security technologies, including SIEM, firewalls, antivirus, and endpoint security solutions.
Experience with security incident detection, analysis, and response.
Knowledge of network protocols, cloud security, and encryption methods.
Ability to assess security risks and develop mitigation strategies.
Proficiency in scripting or programming languages (Python, PowerShell, etc.) is a plus.
Strong analytical, problem-solving, and decision-making skills.
Excellent communication and collaboration skills to work with cross-functional teams.
Familiarity with regulatory compliance requirements (e.g., NIST, ISO 27001, GDPR)
Required Education, Certifications/ Licenses, Related Experience
Bachelors degree in computer science, Information Security, or a related field (or equivalent experience).
Industry certifications such as CISSP, CISM, CEH, GCIH or Security+ preferred.
Minimum of 3-5 years of experience in cybersecurity, network security, SOC Analyst or a related field.
In lieu of degree, a total number of 10 years of experience in related fields (in addition to the management experience required) will meet the education and related experience requirements listed above
Physical Job Requirements
Ability to work in an office environment with prolonged periods of sitting at a desk.
May require lifting of equipment (up to 25 lbs) as needed.
Ability to respond to security incidents outside of normal working hours as necessary.
Travel Requirements
Occasional travel may be required for training, conferences, or collaboration with remote teams.
Anticipated travel will be by car, air, and/or train
Securiport is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Securiport is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. Please see the United States Department of Labor'sEEO posterand EEO poster supplementfor additional information.
Disclaimer: Nothing in this restricts management's right to assign or reassign duties and responsibilities to this job at any time. The above statements are intended to describe the general nature and level of work being performed by people assigned to this position at the time this job description was written. They are not intended to be an exhaustive list of all duties, responsibilities and skills required of personnel so classified. This document does not create an employment contract, implied or otherwise, and all employees in this position are employed at-will.
Cyber Security Project Engineer
Herndon, VA Jobs
Cyber security project engineer skilled in supporting Information Assurance, Certification & Accreditation and Assessment & Authorization activities. You will successfully guide the team through the security process coordinating and tracking risks, generating security plans and be the security advocate for all system/architecture changes.
An active security clearance is required for this position.
Operations Security Engineer
Andrews Air Force Base, MD Jobs
Grow, innovate, and generate progress: Harness your expertise to solve challenges and celebrate success! JCS Solutions has a need for an Operations Security Engineer to join our growing team. This individual will work alongside a dedicated group of professionals bring AFNCR information technology systems through the full life cycle of the Risk Management Framework (RMF) processes to achieve local and/or USAF Authority to Operate (ATO). The position is 100% on-site at Joint Base Andrews (JBA), MD. This position offers an excellent opportunity to be part of a high-performing team responsible for supporting a high-velocity collaborative environment, along with tremendous growth potential. If you are interested in a challenge and a great working environment, apply today!
What's in it for you:
Join a premier technology firm specializing in innovative solutions.
Be part of a collaborative, inclusive, and innovative work culture.
Enjoy tremendous growth potential in a high-performing team environment.
A robust benefits package:
Health, dental, and vision insurance
Life insurance
Short-and-long term disability
Paid time off (PTO)
401k retirement plan with employer match
Annual Professional Development Reimbursement Program
And more!
What you will do:
The specific duties include but are not necessarily limited to the following:
Implement operating system and network device security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides
Performing vulnerability assessments using Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), the Security Content Automation Protocol (SCAP) Compliance Checker, incorporating automated Benchmarks
Coordinate stakeholders to include operations, cyber, vendor and Government client generate and resolve Plan of Action and Milestones (POA&Ms).
Installing updates to systems in compliance with STIG requirements
Creating finalized STIG checklists for their applicable OS experience
Experience with PowerShell and Evaluate STIG
Comfortable in a fast-paced environment.
Technically strong and able to make quick, sound decisions.
Excellent communication and collaboration skills are a must.
What you will bring:
U.S. Citizenship
Active Secret Clearance (Top Secret preferred).
Bachelor's degree in computer science, Cybersecurity, Information Assurance, or related discipline and 6+ years of relevant experience. Additional experience may be considered in lieu of a degree.
Current IAT-II certification (e.g., Security +, CCNA Security, CySA+) as defined by DoD 8570.01-M and/or 8140.
Current Operating System certification (e.g., Windows Server, Linux+, Red Hat Certified System Administrator, etc.).
5 years of experience as a System Administrator managing Windows systems (Server 2019. 2022), IIS, SQL
Experience implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides
Experience with performing vulnerability assessments using Assured Compliance Assessment Solution (ACAS)
Demonstrated ability to correct flaws and implement technical controls in the hardware or software installed within a network environment
Must be able to establish and maintain positive relationships with internal and external customers
Possess professional and effective communication skills, both verbal and written
Proactive approach to your work and you're able to accomplish tasks with limited guidance and supervision
Demonstrated critical thinking and problem-solving skills
How you will wow us:
Experience supporting CCRI, CORA, or other Cyber Readiness Assessments.
Familiarity with DoD mission systems and infrastructure.
Working knowledge of HBSS, SIEM tools, and network security monitoring.
Experience writing SSPs, POA&Ms, and supporting ATO (Authorization to Operate) processes.
Experience with Automation of system hardening via GPO, PowerShell, Ansible, Satellite
Working knowledge of the Air Force and/or DoD is a plus.
JCS Solutions LLC (JCS) is a premier technology firm specializing in enterprise-wide capabilities including cloud and infrastructure solutions, cyber security, digital modernization, next generation technologies enablement, software solutions, and mission support services dedicated to providing the highest quality of services and solutions. JCS delivers expert management consulting and information technology (IT) solutions to federal agencies.
We are a learning organization that promotes a work culture of collaboration, inclusiveness, inspiration and innovation.
JCS has been certified as a
Great Place to Work
four years in a row and was awarded as Washington Post's
Top Places to Work for 2024.
Our employees embody our core values, and we are looking for others who do too!
Customer Experience: Strive for excellence and delight our clients
Innovation: Embrace creative thinking to enable continual growth and powerful solutions
Accountability: Take ownership of and pride in our actions and service delivery
Inspire: Be inspired to be your best self and have fun in the process
Integrity: Do the right thing, the right way, every time!
Stewardship: Careful management of something entrusted to us.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to any status protected by applicable federal, state, or local laws.
Operations Security Engineer
Andrews Air Force Base, MD Jobs
Job DescriptionGrow, innovate, and generate progress: Harness your expertise to solve challenges and celebrate success! JCS Solutions has a need for an Operations Security Engineer to join our growing team. This individual will work alongside a dedicated group of professionals bring AFNCR information technology systems through the full life cycle of the Risk Management Framework (RMF) processes to achieve local and/or USAF Authority to Operate (ATO). The position is 100% on-site at Joint Base Andrews (JBA), MD. This position offers an excellent opportunity to be part of a high-performing team responsible for supporting a high-velocity collaborative environment, along with tremendous growth potential. If you are interested in a challenge and a great working environment, apply today!
What’s in it for you:
Join a premier technology firm specializing in innovative solutions.
Be part of a collaborative, inclusive, and innovative work culture.
Enjoy tremendous growth potential in a high-performing team environment.
A robust benefits package:
Health, dental, and vision insurance
Life insurance
Short-and-long term disability
Paid time off (PTO)
401k retirement plan with employer match
Annual Professional Development Reimbursement Program
And more!
What you will do:
The specific duties include but are not necessarily limited to the following:
Implement operating system and network device security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides
Performing vulnerability assessments using Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), the Security Content Automation Protocol (SCAP) Compliance Checker, incorporating automated Benchmarks
Coordinate stakeholders to include operations, cyber, vendor and Government client generate and resolve Plan of Action and Milestones (POA&Ms).
Installing updates to systems in compliance with STIG requirements
Creating finalized STIG checklists for their applicable OS experience
Experience with PowerShell and Evaluate STIG
Comfortable in a fast-paced environment.
Technically strong and able to make quick, sound decisions.
Excellent communication and collaboration skills are a must.
What you will bring:
U.S. Citizenship
Active Secret Clearance (Top Secret preferred).
Bachelor’s degree in computer science, Cybersecurity, Information Assurance, or related discipline and 6+ years of relevant experience. Additional experience may be considered in lieu of a degree.
Current IAT-II certification (e.g., Security +, CCNA Security, CySA+) as defined by DoD 8570.01-M and/or 8140.
Current Operating System certification (e.g., Windows Server, Linux+, Red Hat Certified System Administrator, etc.).
5 years of experience as a System Administrator managing Windows systems (Server 2019. 2022), IIS, SQL
Experience implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides
Experience with performing vulnerability assessments using Assured Compliance Assessment Solution (ACAS)
Demonstrated ability to correct flaws and implement technical controls in the hardware or software installed within a network environment
Must be able to establish and maintain positive relationships with internal and external customers
Possess professional and effective communication skills, both verbal and written
Proactive approach to your work and you're able to accomplish tasks with limited guidance and supervision
Demonstrated critical thinking and problem-solving skills
How you will wow us:
Experience supporting CCRI, CORA, or other Cyber Readiness Assessments.
Familiarity with DoD mission systems and infrastructure.
Working knowledge of HBSS, SIEM tools, and network security monitoring.
Experience writing SSPs, POA&Ms, and supporting ATO (Authorization to Operate) processes.
Experience with Automation of system hardening via GPO, PowerShell, Ansible, Satellite
Working knowledge of the Air Force and/or DoD is a plus.
JCS Solutions LLC (JCS) is a premier technology firm specializing in enterprise-wide capabilities including cloud and infrastructure solutions, cyber security, digital modernization, next generation technologies enablement, software solutions, and mission support services dedicated to providing the highest quality of services and solutions. JCS delivers expert management consulting and information technology (IT) solutions to federal agencies.
We are a learning organization that promotes a work culture of collaboration, inclusiveness, inspiration and innovation.
JCS has been certified as a
Great Place to Work
four years in a row and was awarded as Washington Post’s
Top Places to Work for 2024.
Our employees embody our core values, and we are looking for others who do too!
Customer Experience: Strive for excellence and delight our clients
Innovation: Embrace creative thinking to enable continual growth and powerful solutions
Accountability: Take ownership of and pride in our actions and service delivery
Inspire: Be inspired to be your best self and have fun in the process
Integrity: Do the right thing, the right way, every time!
Stewardship: Careful management of something entrusted to us.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to any status protected by applicable federal, state, or local laws.
Powered by JazzHR
2PKFfsan90
(270) Cyber Analyst II
Alexandria, VA Jobs
Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future.
Position Overview
Arlo is in search of a Cyber Analyst - Force Design, Readiness, and C2 Assessments to deliver consistent, responsive, and technical Cyberspace Oversight Support for the Office of the Principal Cyber Advisor (PCA). The Analyst will provide technical expertise and policy oversight support for the day-to-day operations to implement the DoD Cyber strategy and to integrate cyberspace activities across the entire DoD. Areas to support may include but not limited to, general support services including writing and analysis and cyberspace operations and analytic support...
Work Location: Onsite at the Mark Center- Alexandria, VA
Clearance: Must have a current and active Top-Secret security clearance with SCI eligibility.
Job Responsibilities and/or Success Factors
Conduct deliberate analysis supporting the development of cyber workforce and readiness policy guidance in DoD. Develop metrics to track progression of implementation of DoD Cyber Workforce Strategy.
Assist the office of the PCA with implementing, leading and sustaining DoD's cyber manpower strategies and human capital initiatives.
Manage competing cyber manpower priorities/tasks across the Department.
Evaluate the performance of cyber workforce programs to ensure implementation in accordance with established statutory and regulatory guidance.
Identify program efficiencies or opportunities within cyber workforce programs, projects and activities to obtain cost savings.
Use knowledge of readiness standards and requirements with the associated metrics to assess the ability of organizations (e.g. the joint force) to meet specific demands (e.g., cyber warfighter) for assigned mission areas.
Conduct deliberate analysis supporting USCYBERCOM's Joint Force Trainer and Joint Force Provider roles, to include identification of mission essential tasks and readiness reporting.
Assist the Office of PCA to develop, promote and implement effective organizational strategies to foster learning environments that enhance the professional, technical, and leadership skills of a diverse Cyber workforce.
Identify cyber workforce issues to bring forward to departmental venues and discussions.
Conduct deliberate analysis supporting the development of cyber force design guidance and C2 structures in DoD. Identify gaps in the Department's cyber operations posture and recommend mitigations.
Identify cyber force design and C2 issues to bring forward to departmental venues and discussions.
Education and Minimum Qualifications
Must have a current and active Top-Secret security clearance with SCI eligibility.
Bachelors in a related field from an accredited university/college.
Minimum 7 years of combined Joint, Interagency, OSD, or Service Headquarters experience performing work with the Cyber Mission Force (CMF) or the Signals Intelligence (SIGINT) community.
Minimum 7 years of experience managing cyber manpower initiatives; coordinating programming and budget issues; preparing manpower and workforce products (i.e., executive briefs, decision papers, information papers, talking points, analysis, etc.); and representing senior leadership in cyber operations.
Desired Qualifications
Master's degree in a related field from an accredited university/college.
AAP Statement
We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.
Cyber Security Analyst
Alexandria, VA Jobs
Our client seeking a Cyber Security Operations Analyst to support an operations team that supports a large government customer. The candidate will be relied upon to assist teammates and perform troubleshooting as needed. The candidate should excel in a fast-paced work environment and be willing to face new challenges.
Qualifications
• Proficiency with vulnerability scanning, remediation and reporting
• Knowledge in web application scanning using various tools
• Demonstrated proficiency with Windows, UNIX, & LINUX operating systems
• Experience working in a customer service information technology environment
• Network security and system security experience
• Ability to discuss real world troubleshooting; problems and solutions encountered
• Knowledge of IT security best practices, US federal government standards, regulations and policy (FedRamp, TIC, NIST 800-37rev1 & 800-53rev3)
• Must be motivated and able to work independently
• Proven project leadership (PowerPoint presenting, MS Project Planning)
• Experience working with change implementation in a controlled environment
• Excellent verbal, written communication and technical writing skills
Bachelors Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training or work experience.
2-5 years of related experience in data security administration.
Experience using some of the following tools:
o Nessus
o Tenable Security Center
o Netsparker
o WebInspect
o BurpSite
Additional Information
Work with blue Stone recruiting to find your next Cyber Security role. You can find us at ******************************* We look forward to speaking with you.
Cyber Security Analyst (TS/SCI Rquirement)
Arlington, VA Jobs
div class="col-12 col-md-8"div class="sc-ca SCKo fLrkuv"divspanspanspanbspanspanspan Job Description/span/span/span/b/span/span/spanbr/ spanspanspanspanspanspan We are seeking a bCyber Security Analyst/b. This position provides 24x7 cybersecurity monitoring and analysis services for Department of Defense networks above the SECRET level. This includes performing real-time cyber threat intelligence analysis, correlating actionable security events, performing network traffic analysis using raw packet data, and participating in the coordination of resources during the incident response process./span/span/span/span/span/span
ul
lispanspanspanspanspanspan Review DoD and open source intelligence for threats and to identify Indicators of Compromise (IOCs) and integrate those into sensors and SIEMs/span/span/span/span/span/span/li
lispanspanspanspanspanspan Utilize alerts from endpoints, IDS/IPS, netflow, and custom sensors to identify compromises on customer networks/endpoints/span/span/span/span/span/span/li
lispanspanspanspanspanspan Review massive log files, pivot between data sets, and correlate evidence for incident investigations/span/span/span/span/span/span/li
lispanspanspanspanspanspan Triage alerts to identify malicious actors on customer networks/span/span/span/span/span/span/li
lispanspanspanspanspanspan Report incidents to customers and USCYBERCOM/span/span/span/span/span/span/li
/ul
spanspanspanbspanspanspan Qualifications/span/span/span/b/span/span/span
ul
lispanspanspanspanspanspan Bachelor's Degree and 4+ years of prior relevant experience; additional work experience or Cyber courses/certifications may be substituted in lieu of a degree./span/span/span/span/span/span/li
lispanspanspanspanspanspan Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements./span/span/span/span/span/span/li
lispanspanspanspanspanspan Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings/span/span/span/span/span/span/li
lispanspanspanspanspanspan DoD 8570 IAT level II or higher certification such as CompTIA Security+ CE, ISC2 SSCP, SANS GSEC prior to starting./span/span/span/span/span/span/li
lispanspanspanspanspanspan DoD 8570 CSSP-A level Certification such as CEH, CySA+, GCIA or other certification is required within 180 days of hire./span/span/span/span/span/span/li
lispanspanspanspanspanspan Demonstrated commitment to training, self-study and maintaining proficiency in the technical cyber security domain and an ability to think and work independently/span/span/span/span/span/span/li
lispanspanspanspanspanspan Bachelor's degree and less than 2+ years of prior relevant experience; additional work experience or Cyber courses/certifications may be substituted in lieu of degree./span/span/span/span/span/span/li
lispanspanspanspanspanspan Strong analytical and troubleshooting skills/span/span/span/span/span/span/li
lispanspanspanspanspanspan Willing to perform shift work/span/span/span/span/span/span/li
lispanspanspanspanspanspan Must be a US Citizen/span/span/span/span/span/span/li
lispanspanspanspanspanspan Must have an active DoD TOP Secret security w/ SCI clearance eligibility./span/span/span/span/span/span/li
/ul
spanspanspanbspanspanspan Preferred Qualifications:/span/span/span/b/span/span/span
ul
lispanspanspanspanspanspan CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization./span/span/span/span/span/span/li
lispanspanspanspanspanspan Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs)./span/span/span/span/span/span/li
lispanspanspanspanspanspan Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements./span/span/span/span/span/span/li
lispanspanspanspanspanspan Demonstrated hands-on experience analyzing high volumes of logs, network data (e.g. Netflow, Full Packet Capture), and other attack artifacts in support of incident investigations./span/span/span/span/span/span/li
lispanspanspanspanspanspan In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. ArcSight, Splunk, Nitro/McAfee Enterprise Security Manager, QRadar, LogLogic)./span/span/span/span/span/span/li
lispanspanspanspanspanspan Experience and proficiency with any of the following: Anti-Virus, HIPS/HBSS, IDS/IPS, Full Packet Capture, Network Forensics./span/span/span/span/span/span/li
lispanspanspanspanspanspan Experience with malware analysis concepts and methods./span/span/span/span/span/span/li
lispanspanspanspanspanspan Unix/Linux command line experience./span/span/span/span/span/span/li
lispanspanspanspanspanspan Scripting and programming experience./span/span/span/span/span/span/li
lispanspanspanspanspanspan Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings./span/span/span/span/span/span/li
lispanspanspanspanspanspan Familiarity or experience in Intelligence Driven Defense and/or Cyber Kill Chain methodology./span/span/span/span/span/span/li
lispanspanspanspanspanspan Existing 8570 CSSP Analyst Certifications (CEH), CySA+ etc./span/span/span/span/span/span/li
/ul
spanspanspanbspanspanspan Clearance Level: TSSCI/span/span/span/b/span/span/spanbr/
spanspanspanspanspanspan Certifications: IAT Level II Baseline Certification/span/span/span/span/span/spanbr/
/div/div/div
Cyber Security Analyst (TS/SCI Rquirement)
Arlington, VA Jobs
We are seeking a Cyber Security Analyst. This position provides 24x7 cybersecurity monitoring and analysis services for Department of Defense networks above the SECRET level. This includes performing real-time cyber threat intelligence analysis, correlating actionable security events, performing network traffic analysis using raw packet data, and participating in the coordination of resources during the incident response process.
Review DoD and open source intelligence for threats and to identify Indicators of Compromise (IOCs) and integrate those into sensors and SIEMs
Utilize alerts from endpoints, IDS/IPS, netflow, and custom sensors to identify compromises on customer networks/endpoints
Review massive log files, pivot between data sets, and correlate evidence for incident investigations
Triage alerts to identify malicious actors on customer networks
Report incidents to customers and USCYBERCOM
Qualifications
Bachelor's Degree and 4+ years of prior relevant experience; additional work experience or Cyber courses/certifications may be substituted in lieu of a degree.
Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.
Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings
DoD 8570 IAT level II or higher certification such as CompTIA Security+ CE, ISC2 SSCP, SANS GSEC prior to starting.
DoD 8570 CSSP-A level Certification such as CEH, CySA+, GCIA or other certification is required within 180 days of hire.
Demonstrated commitment to training, self-study and maintaining proficiency in the technical cyber security domain and an ability to think and work independently
Bachelor's degree and less than 2+ years of prior relevant experience; additional work experience or Cyber courses/certifications may be substituted in lieu of degree.
Strong analytical and troubleshooting skills
Willing to perform shift work
Must be a US Citizen
Must have an active DoD TOP Secret security w/ SCI clearance eligibility.
Preferred Qualifications:
CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization.
Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.
Demonstrated hands-on experience analyzing high volumes of logs, network data (e.g. Netflow, Full Packet Capture), and other attack artifacts in support of incident investigations.
In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. ArcSight, Splunk, Nitro/McAfee Enterprise Security Manager, QRadar, LogLogic).
Experience and proficiency with any of the following: Anti-Virus, HIPS/HBSS, IDS/IPS, Full Packet Capture, Network Forensics.
Experience with malware analysis concepts and methods.
Unix/Linux command line experience.
Scripting and programming experience.
Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.
Familiarity or experience in Intelligence Driven Defense and/or Cyber Kill Chain methodology.
Existing 8570 CSSP Analyst Certifications (CEH), CySA+ etc.
Clearance Level: TSSCI
Certifications: IAT Level II Baseline Certification
Cyber Security Analyst
Boca Raton, FL Jobs
Reports to CISO and works with a team of Cyber Security specialists. The Cyber Security Analyst is responsible for identifying risks to the confidentiality, integrity, and availability of our clients products and services, while maintaining compliance with applicable regulatory standards.
In this role, you will be expected to contribute to the integrity and sustainability of the service delivery network, which consists of advanced server-based applications used to support our client's customers. The successful candidate will work directly with senior team members on issues that may require some after-hours and weekend availability.
Specific Job Duties:
• Articulate technical and security requirements to departments/business groups
• Identify gaps in security operations and develop mitigation strategies
• Assist with the maintenance of application and operating system software in the Service Delivery Network
• Participate in disaster recovery and business continuity planning
• Perform software development lifecycle auditing
• Prioritize compliance actions according to business risk
Desired Preferred Skills:
• Industry certifications - PMP, CISA, CISSP, Security +
• Department of Defense IT experience
• Pharmacy or healthcare experience
Qualifications
• Masters's degree in computer science or relative discipline
• 5-10 years combined experience in information security
• Proficient with Unix / Linux
• Strong analytical problem solving
• Knowledge of the software development lifecycle
• Proven ability to plan and work to a deadline
• Must be able to obtain Department of Defense clearance
Additional Information
Work with blue Stone recruiting to find your next Cyber Security role. You can find us at ******************************* We look forward to speaking with you.
Product Security Engineer
Virginia Jobs
div class="col-12 col-md-8"div class="sc-ca SCKo fLrkuv"divstrong Introduction /strongbr/ We working on a project that tackles the problem of managing large-scale IT networks. We are seeking talented and highly motivated engineers to join us in bringing this project to a larger audience. You would be responsible for helping to create, evolve, document, and implement security development and deployment practices for a product that's delivered both on-premises as well as to the cloud. This work would include evaluating and disseminating information and recommendations from resources such as NIST, OWASP, MITRE, and other sources of security information and best practices. This work would also include-with the assistance of the rest of the development team-implementing these security controls and practices as part of the software development process, supplying guidance and requirements for deploying our product on-premises, and creating a secure environment for our upcoming cloud offering.br/
br/
Our product is a .NET Core application (with some TypeScript and Python components) backed primarily by PostgreSQL, that serves both a web frontend and REST API. The application source is hosted in GitLab, and we use merge requests and GitLab CI to manage our code contribution workflows.br/
br/
strong Things we really need /strong
ul
li Experience maintaining a secure software supply chain (monitoring for CVEs, creating SBOMs, etc.)/li
li Experience evaluating security best practices and applying them to processes and assets/li
li Experience reviewing code and architecture to identify potential security issues/li
li Experience writing internal documentation around security evaluations and decisions/li
li Experience with security monitoring infrastructure (log analysis, web application firewalls)/li
li United States citizenship/li
li8+ years of experience/li
/ul
strong Things we want too /strong
ul
li Familiarity with writing infrastructural code in support of security goals (abstractions, constraints, etc.)/li
li Familiarity with working with developers to help them learn and self-apply secure development principals/li
li Familiarity with government/industry security auditing processes/li
li Specific familiarity with web security concepts and best practices (TLS/HTTPS, common web vulnerabilities, federated authentication, etc.)/li
/ul
strong Things that are extra cool /strong
ul
li Specific familiarity with government programs pertaining to secure application development (STIGs, APL, NIAP)/li
li Specific experience with the Microsoft web application development stack (C#, .NET, ASP.NET)/li
li Specific experience with AWS security tooling/li
li Experience with static application security analysis tools/li
/ul
strong Our end of the bargain /strong
ul
li Remote-first environment (if that's your thing)/li
li Dedicated collaborative office space in NoVA (if that's your thing)/li
li We respect work/life balance/li
li Occasional on-site team summits/li
li Competitive salary and annual reviews/li
/ul/div/div/div
(280) Information Security Support SME
Arlington, VA Jobs
Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future.
Job Responsibilities and/or Success Factors:
Conducts security reviews of documents, transcripts, and manuscripts to determine whether classified information is contained in the document and if an unauthorized disclosure has occurred and develop metrics to track the disclosures.
Coordinates with component original classification authorities to identify disposition of each case.
Collaborates with the original classification authority (OCA) and the DoD Office of the General Counsel to ensure initial inquiries and damage assessments are conducted, as well as determine if further investigation and/or referral to the Department of Justice is warranted.
Assists in preparing notification correspondence for the Congress and/or the Information Security Oversight Office.
Assists with policy development reference information security and unauthorized disclosures.
Education and Minimum Qualifications:
Must have an active TS/SCI Security Clearance
Bachelor's degree from an accredited college or university, preferably in information security or related.
Experience with OUSD(I&S) is preferred.
Demonstrated knowledge of the Department's supporting security functions to include insider threat, operations security, technology protection, habeas, declassification, SCI and SAP security policies is desired.
Required Qualifications:
5 years of security policy experience in the following areas:
Demonstrated knowledge of policies and procedures used in the information security discipline-for DoD, the Defense Intelligence Enterprise, and at the national level
Demonstrated experience recommending security policy positions and once approved, representing those positions to a broad constituency at various forums as well as facilitate or chair forums to draft policy and/or achieve policy issue resolution
Demonstrated experience drafting, coordinating, and staffing actions • Demonstrated experience using written communications skills and ability to independently draft, coordinate, and staff actions within OSD, the Services, DIA and the Joint Staff
Strongly Desired:
Experience demonstrating understanding of the CFIUS process.
Experience briefing leaders on CFIUS cases.
Experience researching companies that are repeating in the CFIUS process to look for trends of purchasing.
AAP Statement
We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.
Cyber Engineer - Senior - TS/SCI
Triangle, VA Jobs
GRIMM researches and develops the art of the possible in business modernization and computing technologies through cybersecurity, sensors, tools, analytics, frameworks, modeling and simulation, automated testing, cyber range Installation, Operations, and Maintenance (IOM), consulting, and intelligence. Our practices build on extensive experience in cyber mission support for national defense, and commercial service improvement and consulting. Our engineers and subject matter experts (SMEs) learned their trade from real-world engagements, not just textbooks.
Job Description
Cyber Engineer - Senior
We're searching for
Cyber Engineer - Senior
to support the client's tactical and strategic approaches for mission and ways forward.
Provide technical and engineering support in the exploitation and/or remediation of infrastructure and computer systems.
Understanding in information assurance, with expertise in computer and telecommunication network systems and cyber operations.
Assist in researching new concepts for developing situational awareness and vulnerability tools to support CNO efforts.
Assist the Government with the identification, exploitation, and/or remediation of infrastructure and system vulnerabilities; developing and implementing offensive and/or self-defending networks; developing and defending effects-based capabilities; and reverse engineering of systems exploitations to include computer forensics, and analysis of binaries, assembly language, source code, and/or malicious logic code.
Direct performance of a major program, project, or activity relating to Information Technology, Ethical Hacking, Cyber Security, and/or Information Assurance.
LOCATION
In Quantico, Virginia area
We promote a Drug-Free Workplace, are an Equal Opportunity Employer (EOE) and Affirmative Action Employer.
Qualifications
GRIMM researches and develops the art of the possible in business modernization and computing technologies through cybersecurity, sensors, tools, analytics, frameworks, modeling and simulation, automated testing, cyber range Installation, Operations, and Maintenance (IOM), consulting, and intelligence. Our practices build on extensive experience in cyber mission support for national defense, and commercial service improvement and consulting. Our engineers and subject matter experts (SMEs) learned their trade from real-world engagements, not just textbooks.
Cyber Engineer - Senior
We're searching for
Cyber Engineer - Senior
to support the client's tactical and strategic approaches for mission and ways forward.
REQUIREMENTS
Minimum 7 years, performing above referenced duties with the following recent hands-on experience;
Senior-level or technical lead in a related position on a major program, project, or activity.
Information Technology, Ethical Hacking, Cyber Security, and/or Information Assurance.
Must be a US Citizen with TS/SCI Full Scope Clearance.
Must have a Bachelor's or Masters or PhD Degree in Computer Science, Computer Engineering, Software Engineering, Electrical Engineering, Computer and Information Security, Computer Security, and/or Network Administration from an accredited university/college.
LOCATION
In Quantico, Virginia area
We promote a Drug-Free Workplace, are an Equal Opportunity Employer (EOE) and Affirmative Action Employer.
Additional Information
GRIMM offers security engineering and consulting services, backed by the research and development, to deliver the art of the possible in cybersecurity. We specialize in breaking things, discovering vulnerabilities, and demonstrating impact to solve complex cybersecurity problems.
GRIMM services government and commercial clients from a diverse range of industries. We work in hardware, firmware, and software across traditional enterprise computing, embedded devices, automobiles, planes, drones, energy, and mobile.
This is not your ordinary company! This is a collection of the best people in cybersecurity that you have likely never encountered in one place.
GRIMM is a team of industry leaders, which includes the largest number of DEF CON CTF Black Badge holders in a single company. We are looking for people at all levels, with a passion for cybersecurity who want to help grow and shape the industry.
We promote a Drug-Free Workplace, are an Equal Opportunity Employer (EOE) and Affirmative Action Employer.
Visit our career site at ************************
Cyber Engineer - Senior - TS/SCI
Triangle, VA Jobs
GRIMM researches and develops the art of the possible in business modernization and computing technologies through cybersecurity, sensors, tools, analytics, frameworks, modeling and simulation, automated testing, cyber range Installation, Operations, and Maintenance (IOM), consulting, and intelligence. Our practices build on extensive experience in cyber mission support for national defense, and commercial service improvement and consulting. Our engineers and subject matter experts (SMEs) learned their trade from real-world engagements, not just textbooks.
Job Description
Cyber Engineer - Senior
We're searching for
Cyber Engineer - Senior
to support the client's tactical and strategic approaches for mission and ways forward.
Provide technical and engineering support in the exploitation and/or remediation of infrastructure and computer systems.
Understanding in information assurance, with expertise in computer and telecommunication network systems and cyber operations.
Assist in researching new concepts for developing situational awareness and vulnerability tools to support CNO efforts.
Assist the Government with the identification, exploitation, and/or remediation of infrastructure and system vulnerabilities; developing and implementing offensive and/or self-defending networks; developing and defending effects-based capabilities; and reverse engineering of systems exploitations to include computer forensics, and analysis of binaries, assembly language, source code, and/or malicious logic code.
Direct performance of a major program, project, or activity relating to Information Technology, Ethical Hacking, Cyber Security, and/or Information Assurance.
LOCATION
In Quantico, Virginia area
We promote a Drug-Free Workplace, are an Equal Opportunity Employer (EOE) and Affirmative Action Employer.
Qualifications
GRIMM
researches and develops the art of the possible in business modernization and computing technologies through cybersecurity, sensors, tools, analytics, frameworks, modeling and simulation, automated testing, cyber range Installation, Operations, and Maintenance (IOM), consulting, and intelligence. Our practices build on extensive experience in cyber mission support for national defense, and commercial service improvement and consulting. Our engineers and subject matter experts (SMEs) learned their trade from real-world engagements, not just textbooks.
Cyber Engineer - Senior
We're searching for
Cyber Engineer - Senior
to support the client's tactical and strategic approaches for mission and ways forward.
REQUIREMENTS
Minimum 7 years, performing above referenced duties with the following recent hands-on experience;
Senior-level or technical lead in a related position on a major program, project, or activity.
Information Technology, Ethical Hacking, Cyber Security, and/or Information Assurance.
Must be a US Citizen with TS/SCI Full Scope Clearance.
Must have a Bachelor's or Masters or PhD Degree in Computer Science, Computer Engineering, Software Engineering, Electrical Engineering, Computer and Information Security, Computer Security, and/or Network Administration from an accredited university/college.
LOCATION
In Quantico, Virginia area
We promote a Drug-Free Workplace, are an Equal Opportunity Employer (EOE) and Affirmative Action Employer.
Additional Information
GRIMM
offers security engineering and consulting services, backed by the research and development, to deliver the art of the possible in cybersecurity. We specialize in breaking things, discovering vulnerabilities, and demonstrating impact to solve complex cybersecurity problems.
GRIMM services government and commercial clients from a diverse range of industries. We work in hardware, firmware, and software across traditional enterprise computing, embedded devices, automobiles, planes, drones, energy, and mobile.
This is not your ordinary company! This is a collection of the best people in cybersecurity that you have likely never encountered in one place.
GRIMM is a team of industry leaders, which includes the largest number of DEF CON CTF Black Badge holders in a single company. We are looking for people at all levels, with a passion for cybersecurity who want to help grow and shape the industry.
We promote a Drug-Free Workplace, are an Equal Opportunity Employer (EOE) and Affirmative Action Employer.
Visit our career site at ************************
Cyber Security Analyst
Saint Charles, IL Jobs
Job DescriptionAbout UFP MedTech:
UFP Technologies is a designer and custom manufacturer of comprehensive solutions for medical devices, sterile packaging, and other highly engineered custom products. UFP is an important link in the medical device supply chain and a valued outsource partner to most of the top medical device manufacturers in the world. The Company’s single-use and single-patient devices and components are used in a wide range of medical devices and packaging for minimally invasive surgery, infection prevention, wound care, wearables, orthopedic soft goods, and orthopedic implants.
UFP Technologies, Inc. offers a competitive benefits package, including but not limited to:
Medical, Dental, Vision, Life, Disability Insurance
401K with a matching contribution
Paid time off, Paid holidays, Employee discounts and much more!
Location: The position will be on-site full-time in St. Charles, IL. The position holder will need to be within commuting distance (within 45 min).
Cyber Security Analyst Summary:
The Cyber Security Analyst is responsible for assisting with the day-to-day operations of securing the firm’s various information systems. The Cyber Security Analyst is tasked with providing technical expertise in all areas of network, system, and application security. Works closely with the various team members in the Information Technology department to ensure that systems and networks are always designed, developed, deployed, and managed with an emphasis on strong, effective security and risk management controls. The Cyber Security Analyst leads the firm's vulnerability management program, manages the annual cybersecurity assessments and penetration tests, and researches and reports on emerging threats to help the firm take pre-emptive risk mitigation steps. Effectively correlates and analyzes security events within UFP’s systems environment to proactively detect threats and mitigate attacks before they occur.
Cyber Security Analyst Duties and Responsibilities:
Studies evolving threats and other industry developments related to cyber security.
Researches / evaluates emerging cyber security threats and ways to manage them.
Plans for disaster recovery and creates contingency plans in the event of any security breaches.
Monitors for attacks, intrusions and unusual, unauthorized or illegal activity.
Tests and evaluates security products.
Designs new security systems or upgrades existing ones.
Uses advanced analytic tools to determine emerging threat patterns and vulnerabilities.
Runs internal security scans, coordinates mitigation and tracks results.
Investigates security alerts and is a part of the incident response team.
Monitors identity and access management, including monitoring for abuse of permissions by authorized system users.
Liaises with stakeholders in relation to cyber security issues and provides future recommendations.
Generates reports for both technical and non-technical staff and stakeholders.
Maintains an information security risk register and assists with internal and external audits relating to information security.
Creates and conducts employee training programs related to cyber security.
Monitors and mitigates 'phishing' emails and 'pharming' activity including conducting employee training and re-training.
Assists with the creation, maintenance and delivery of cyber security awareness training for colleagues.
Coordinates the creation and maintenance of cyber security policies and standards.
Responds and manages helpdesk tickets related to cyber security.
Coordinates projects related to cyber security such as CMMC certification.
Performs all other duties as assigned or needed.
Cyber Security Analyst Qualification Requirements:
Bachelor’s in cyber security or related discipline.
Hands-on experience.
2+ years of systems administration in an active directory environment.
2+ years of cyber security experience.
Security+ certification.
Experience / familiarity with the following :
IT Security Frameworks (NIST, GDPR, PCI, ISO 27001, CMMC, etc.)
IT Security Tools (Nessus, Kali Linux, Metaspolit, Wireshark, etc.)
Azure / Office 365
Endpoint, server and network malware detection
SQL Server
SharePoint
ERP systems
Security+
Scripting language (Powershell, Python, etc.)
Linux
To apply for this job please create a profile with us through our online application system. Click the "Apply" box in the upper right-hand corner to start the application process. Or, if you already have a social media account with LinkedIn, Google, or Facebook you can use your log in credentials to apply.
UFP Technologies, Inc. is an Equal Opportunity/Affirmative Action employer Minorities/Women/Veterans/Disabled.
#UFP #IL
Data and System Security Engineer
Lincolnshire, IL Jobs
AYR Global IT Solutions is a national staffing firm focused on cloud, cyber security, web application services, ERP, and BI implementations by providing proven and experienced consultants to our clients. Our competitive, transparent pricing
model and industry experience make us a top choice of Global System
Integrators and enterprise customers with federal and commercial
projects supported nationwide.
Job Role: Data and System Security Engineer
Location: Lincolnshire, IL
Duration: 6+ Months
Qualifications
Job Description:
Data and System Security engineer
Experience with data encryption management solutions, such as Vormteric and CloudLink
Experience with PKI management solutions, such as ADCS and External providers
Investigative and analytical problem solving skills
Customer service/support experience
Additional Skills:PKI
Knowledge of encryption management technologies, such as Vormetric, CloudLink.
Additional Information
If anyone might be intersted please send resumes to kmarsh@ayrglobal (dot) com or you can reach me direct at **************