Security architect jobs in Hagerstown, MD - 190 jobs
All
Security Architect
Security System Engineer
Information Systems Security Officer
Security Engineer
Network Security Architect
Senior Security Analyst
Security Engineer
ITC Federal, Inc. 4.7
Security architect job in Rockville, MD
ID 2026-1478 Remote No
JOB TITLE: Senior Security Engineer
POSITION INFORMATION: Full-Time Position
POSITION TIMING: Employment is contingent upon obtaining a Public Trust clearance prior to start; processing typically takes 2-3 months.
BENEFITS: Health, Dental and Vision, 401(k), Flexible Spending Account (FSA), 11 Paid Federal Holidays, PTO, education reimbursement
ITC Federal is an information technology and consulting company focused on servicing the needs of the Federal Government. ITC's mission is to apply earned expertise in information technology and information assurance/security to assist this client in achieving its mission. ITC is located in Fairfax, VA and offers outstanding compensation and benefits plan and a challenging and rewarding professional work environment.
Responsibilities
RESPONSIBILITIES:
Develop and implement internal System Security Plan (SSP) and Security Assessment Plan (SAP)
Evaluate the effectiveness of security controls, and develop findings and remediation recommendations i.e. Plan of Action and Milestones (POA&Ms)
Develop and implement security and compliance audit logging and monitoring
Implement and maintain security compliance and security monitoring technologies
Monitor security events and respond and/or coordinate response and mitigation efforts
Perform system architecturesecurity risk and waiver assessments and propose mitigation plans
Perform Security Impact Assessment (SIA) for proposed system change requests
Perform vulnerability assessment and vulnerability remediation/mitigation research
Monitor patch and security advisories releases and review and develop deployment plans
Develop and implement security policy, processes, procedures, and guidance documentation
Provide security guidance to drive infrastructure decisions in collaboration with other technical and management stakeholders to ensure security policies and principles are being upheld
Engage in ongoing research of new and emerging security technologies that may benefit the security posture of strategic goals
Work closely with senior management, systems operations staff, software development staff, support staff, 3
rd
parties and end-users to ensure rapid resolution of security issues.
Support others in analyzing and resolving difficult technical problems.
Conduct in-depth technical reviews of new and existing IT systems in order to identify the appropriate mitigation strategies required to bring these systems into compliance with established NIST policy and industry guidelines.
Performs other security related duties as required.
Qualifications
REQUIRED KNOWLEDGE, SKILLS AND ABILITIES:
Bachelor of Science in Computer Engineering / Computer Science with 4-7 years' experience.
3+ years of experience system architecture design with experience providing security integration.
2+ years of experience working with virtualization technologies.
1+ year of working with cloud services and/or collaboration with cloud service providers.
One or more of the following certification: MCSA/MCSE, CCNA Security, GSEC, GCIA, GCIH, CISA, CISM, CCSP, CAP and/or CISSP.
In-depth understanding of access control, authentication and authorization, security auditing, and security configuration technologies.
In-depth understanding of standard Internet protocols (i.e., FTP, HTTP, DNS, DHCP, RADIUS, SNMP, and SMTP).
In-depth understanding of security and compliance best practices and standard (i.e., FISMA, FedRAMP, CIS Benchmarks, DoD STIGs, SCAP, NIST SP800-53/39/37, ISO 27001/27002).
Recent hands-on experience or familiarity implementing IT security equipment (Governance Risk and Compliance Tools, Firewalls, Intrusion Detection Systems, Vulnerability Scanners, Virtual Private Networking, virus protection technologies, and Log Management solutions, Security Information and Event Management Solutions).
Familiarity or experience with the following types of appliances/ tools a plus: Tenable Security Center/ Nessus, Web Inspect, LogRythm, BigFix, SentinelOne, Active Directory, Palo Alto Firewall, Juniper SRX Firewall, Cisco, Global Protect.
Ability to perform risk assessments and build risk mitigation plans.
Strong organization, written and oral communication skills.
Strong ability to function independently or as a part of a large, integrated cross-functional team.
Intellectual curiosity and a willingness to learn new things
Experience working in a dynamic lab environment preferred
Experience with FISMA Compliance/ NIST Risk Management Framework (RMF) contracts preferred
WORK ENVIRONMENT AND PHYSICAL DEMANDS: Candidate must be able to function in general office environment.
ITC Federal is an equal opportunity employer and will not discriminate against any application for employment on the basis of age, race, color, gender, national origin, religion, creed, disability, veteran status, marital status, sexual orientation, genetic information, military status, disability, or sex including pregnancy and childbirth or related medical condition or on any other basis prohibited by law.
$98k-137k yearly est. 3d ago
Looking for a job?
Let Zippia find it for you.
Multidisciplinary Engineer - National Security
Expedition Technology
Security architect job in Herndon, VA
Join the Expedition: Engineers Wanted
At Expedition Technology (EXP), we don't just build things-we build the future. Whether it's decoding signals from the edge of the spectrum, teaching machines to see the unseen, or crafting AI that thinks faster than the threat, we're in the business of solving national security challenges with elegance, grit, and a whole lot of code.
We're not hiring for a specific role. We're hiring for a mindset.
If you're an engineer who:
Gets excited about sensor processing (any sensors, any types of signals)
Regularly wonders how to incorporate new paradigms to tackle previously unsolved problems (LVLMs? Agents? RL? Quantum? What's next?)
Thinks cloud or embedded systems can be beautiful
Can build a visualization that makes complex data feel like a story
Wants to work on projects that matter-to the country and the world
What We Do (and You Could Too):
Build AI/ML systems that help the Department of Defense and Intelligence Community make faster, smarter decisions in dynamic environments
Develop real-time solutions for low power edge devices, cloud platforms, and everything in between
Research, prototype, and deploy novel technology
Collaborate in "team of teams" structures that prioritize agility, autonomy, and impact
What You Bring (The Essentials):
A deep-seated passion for solving hard problems.
An active TS/SCI clearance and U.S. Citizenship.
A collaborative spirit and a drive to learn from and teach others.
And Expertise in One or More of These Areas:
We don't expect you to be an expert in everything.
We're looking for people who have a center of gravity in one of these areas and are excited to learn about the others.
Software Engineering: Writing clean, robust, and efficient code.
AI/ML Development: Building, training, and deploying models using frameworks like PyTorch or TensorFlow. Experience with RF, CV, or NLP is a major plus.
Signal Processing: A strong theoretical and practical understanding of digital signal processing (DSP) for communications, RADAR, or other sensor systems.
Systems Engineering & DevOps: Designing and maintaining complex systems, whether on cloud platforms (AWS, Azure) or on-premise hardware.
Embedded Systems: Developing and optimizing software for resource-constrained edge devices (e.g., FPGAs, GPUs, SoCs).
What You Get:
A front-row seat to the future of defense tech
A culture that values experimentation, iteration, and the occasional bad pun
The chance to work with people who believe in what they do-and have fun doing it
Ready to explore, experiment, and expand? Join Expedition!
Apply now-or just reach out and tell us what you're excited to work on. We're listening.
Clearance required: TS/SCI
Who is Expedition Technology?
Expedition Technology (EXP) designs, develops, and delivers innovative, advanced signal, image, and multi-INT solutions for the defense and intelligence communities. We leverage advanced algorithms, platforms, and technologies to solve our customers' most complex, demanding, and urgent C4ISR challenges. Our culture promotes individual growth and opportunity, prioritizes a collaborative team spirit, and invites the intellectually curious to creatively solve challenging problems. Headquartered in Northern Virginia's high-tech corridor, EXP is a rapidly growing, privately held, employee-owned company that pushes the boundaries of what is possible every day.
Interested in joining our team? Let's explore together.
To learn more about EXP and discover why we are an award-winning workplace, visit ourweb siteand follow us on LinkedIn.
Join Our Team and Enjoy Exceptional Benefits!
Expedition Technology (EXP) offers a flexible, self-directed benefits package that is designed to fit your individual needs.Here's a glimpse of the outstanding benefits you can enjoy when you join our team:
Company-paid medical, dental, and vision insurance
Generous Time Off: Enjoy 12 paid holidays, up to 33 days of PTO, and generous sick leave
Robust 401(k) Plan: Benefit from up to a 12% company contribution, including a 3% safe harbor, 6% match, and up to 3% additional as a form of profit sharing.
Student Loan Repayment: Take advantage of our unique option to reallocate a portion of your 401(k) match funds to repay student loans, helping you achieve financial freedom faster.
Paid Parental Leave: Six weeks of paid leave for the primary caregiver and 2 weeks of paid leave for the secondary caregiver for you to bond with your new family member.
Tuition Reimbursement: Pursue further education with up to $5,250/year available to support your continuous learning and growth.
Referral Bonus Program: Earn rewards for bringing talented individuals into our team.
Exclusive Entertainment Perks: Enjoy free tickets to sporting events, theater, concerts, and more, adding fun and excitement to your life.
Onsite Amenities: Stay fit and healthy with our free, onsite fitness center, active workstations featuring treadmill and bike desks, and enjoy our onsite cafeteria with reduced-cost options.
Inspiring Work Culture: Thrive in a collaborative, creative, and supportive culture where you are encouraged to push boundaries, take risks, and enjoy the rewards.
Join us and be part of a team that values your well-being and professional growth. Apply today and take the first step towards a fulfilling career with us!
EXP is proud to be an Equal Opportunity Employer that believes a diverse range of talent creates an environment that fosters creativity and innovation
.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, disability, national origin, genetic information, or protected veteran status.
$81k-112k yearly est. 2d ago
Security Architect
Arthur Grand Technologies
Security architect job in Ashburn, VA
Job Brief:
SecurityArchitecture
Duration: Long Term Contract
Rate: $Negotiable
Integrate into the Information Security Program to provide actionable advice and recommendations for the continued maturation of client security stack and associated systems/interfaces.
Develop requirements for implementing zero trust architecture (ZTA) to meet client business needs.
Develop an initial understanding of the current state securityarchitecture by documenting current, ‘as-is', securityarchitecture.
Responsibilities:
Establish a securityarchitecture governance model and create / update processes for the securityarchitecture. Develop desired securityarchitecture.
Develop detailed project plans for security solutions implementation.
Assist with the selection of available vendors.
Assist the client Architecture and Standards team in developing a roadmap for achieving ZTA for all applicable client systems.
Develop requirements for implementing multi-factor authentication (MFA) to meet client business needs.
Assist the client Architecture and Standards team in developing a roadmap for implementing MFA for all applicable client systems.
Develop requirements for implementing encryption at rest and in-transit to meet client business needs.
Assist the client Architecture and Standards team in developing a roadmap for implementing encryption at rest and in-transit for all applicable client systems.
Develop requirements for implementing Endpoint Detection and Response (EDR) to meet client business needs; and
Assist the client Architecture and Standards and Security Operations teams in developing a roadmap for implementing EDR.
Skills Required: IAM,ZTA
$102k-151k yearly est. 60d+ ago
Security Architect
LCG 3.8
Security architect job in Rockville, MD
Work Type: Hybrid Work (Minimum 2 days onsite - may extend based on client meetings, delivery needs, and proposal support)
Job Title: SecurityArchitect
Clearance: Public Trust
Job Summary: LCG is seeking a SecurityArchitect provides enterprise cybersecurity architecture and engineering support to Client's Office of Management, Technology and Operations (OMTO), Division of Technology Management (DTM). This role is responsible for designing and improving securityarchitecture across hybrid (cloud + on-premises) environments, ensuring alignment with HHS and federal cybersecurity mandates, and supporting modernization efforts that strengthen security posture, improve operational resilience, and enable compliant system delivery.
The SecurityArchitect will lead technical planning for security control implementation, provide guidance to stakeholders across infrastructure and application teams, and contribute to remediation strategy, continuous monitoring alignment, and integration of security requirements into enterprise environments. The position supports Client's cybersecurity and risk-based program objectives including improving security infrastructure, integrating federal requirements into operational execution, and supporting continuous monitoring and automation activities.
Key Responsibilities
SecurityArchitecture Design & Improvement
Design and recommend enterprise securityarchitecture improvements for Client systems, focusing on strengthening security posture across network, infrastructure, cloud, and application layers.
Develop securityarchitecture artifacts such as:
Target-state securityarchitecture models
Security service integration patterns (identity, logging, scanning, endpoint security, WAF)
Security control inheritance mapping for enterprise services and shared platforms
Conduct architecture reviews to identify security gaps and opportunities for improved resiliency and compliance alignment.
Vulnerability Remediation Strategy Support
Support the development of vulnerability remediation strategies by analyzing scan results, security weaknesses, and systemic configuration issues impacting Client environments.
Recommend enterprise remediation approaches such as:
Standard security baselines (e.g., hardened images, secure configurations)
Compensating controls where patching is delayed or constrained
Repeatable remediation processes across system classes (servers, endpoints, cloud workloads)
Assist stakeholders in prioritizing remediation based on risk, mission impact, and federal compliance expectations.
Analyze HHS Design Requirements & Security Impacts
Analyze HHS and federal design requirements and evaluate impacts to Client's architecture, implementations, and operational processes.
Translate requirements into actionable securityarchitecture guidance for:
Infrastructure engineering teams
Application owners and system developers
Governance/compliance stakeholders (FISMA, RMF, POA&M coordination)
Provide architectural interpretation and support for new security mandates and evolving federal expectations.
Define Security Deployment Approach (Enterprise Implementation Patterns)
Define secure deployment approaches for new and existing systems, ensuring security controls and tools are implemented consistently and efficiently.
Produce standardized design approaches for:
Secure logging and monitoring architectures (supporting SIEM/Splunk ingestion and monitoring coverage)
Vulnerability scanning integration and automated evidence generation
Identity and privileged access integration (IAM + PAM patterns)
Ensure solutions support both operational needs and compliance requirements.
Implementation Plans for New Controls, Capabilities, and Tools
Create implementation plans for deploying new security controls or tool capabilities, including:
Scope definition and technical prerequisites
Integration dependencies across teams and environments
Phased rollouts, validation checkpoints, and operational transition steps
Support adoption of security tools and security control implementation activities that improve Client's maturity and automated security posture.
Support Cloud + On-Prem Security Integrations
Architect integration of cloud and on-prem solutions to support secure hybrid operations aligned to Client's enterprise security framework.
Support integration activities involving:
Cloud security tooling integrations
Network security boundaries and monitoring pipelines
Web application protection patterns (e.g., WAF integrations)
Assist with securearchitecture decisions for systems operating under federal compliance constraints.
Provide Technical Guidance to Stakeholders
Provide technical leadership and architecture guidance to cross-functional stakeholders including system owners, engineers, program teams, and compliance personnel.
Support design reviews, technical working sessions, and architecture decision-making, including:
Explaining security control requirements and implementation options
Advising on secure patterns for system modernization and new deployments
Collaborating on resolving engineering blockers impacting security posture
Support Modernization & Automation Initiatives
Support modernization initiatives that improve Client's cybersecurity capability through automation and improved security-by-design practices.
Contribute architecture guidance for initiatives such as:
Enhanced continuous monitoring approaches (NIST SP 800-137 aligned)
Integrating security requirements into DevSecOps/CI/CD delivery pipelines (as applicable to security automation goals)
Supporting implementation strategies for improved security metrics and reporting capabilities
Requirements:
Education: Bachelor's degree in one of the following or related technical discipline (Cybersecurity / Information Assurance /Information Systems / Information Technology / Computer Science / Engineering)
Certification: Preferred: CISSP (industry standard preferred credential for senior securityarchitecture roles)
Experience:
Minimum: 5+ years of experience in enterprise securityarchitecture and/or security engineering
Experience supporting federal cybersecurity programs and security governance objectives (FISMA/NIST-aligned)
Hands-on exposure to cloud securityarchitecture and hybrid integration patterns
Experience designing security modernization approaches (automation, improved monitoring, scalable control deployment).
Strong background in securityarchitecture and security engineering with demonstrated ability to design enterprise security solutions
Experience developing architecture recommendations that improve security posture across hybrid IT environments
Ability to evaluate and translate security requirements into actionable architecture decisions and implementation plans
Working knowledge of:
Vulnerability remediation strategy development and execution support
Continuous monitoring practices and operational security reporting
Security tool integrations and technical dependencies across organizations
Tools Set / Platforms
The SecurityArchitect will work across architecture and compliance support tooling such as:
Securityarchitecture tools (models, diagrams, and enterprise design artifacts)
GRC artifacts and governance documentation (e.g., control evidence, security posture analysis)
Cloud security tooling and hybrid security capabilities
Scanning tools outputs used to drive remediation and risk reduction efforts
Compensation and Benefits
The projected compensation range for this position is $100,000 to $200,000 per year, benchmarked in the Washington, D.C. metropolitan area. Salary at LCG is determined by various factors, including but not limited to role, location, education/training, skills, certifications, and experience.
LCG offers a competitive and comprehensive benefits package including medical, dental, and vision insurance, life and disability insurance, retirement plan contributions, paid leave, federal holidays, professional development opportunities, and lifestyle benefits.
Devoted to Fair and Inclusive Practices
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.
If you are interested in applying for employment with LCG and need special assistance or an accommodation to apply for a posted position, contact Human Resources at *************.
Securing Your Data
Beware of fraudulent job offers using LCG's name. LCG will never request payment-related details or advance payment during the application process. Legitimate communication will only come from lcginc.com or ************************* email addresses.
Location: Rockville, MD
Work Type: Hybrid Work (Minimum 2 days onsite - may extend based on client meetings, delivery needs, and proposal support)
Job Title: SecurityArchitect
Clearance: Public Trust
Job Summary: LCG is seeking a SecurityArchitect provides enterprise cybersecurity architecture and engineering support to Client's Office of Management, Technology and Operations (OMTO), Division of Technology Management (DTM). This role is responsible for designing and improving securityarchitecture across hybrid (cloud + on-premises) environments, ensuring alignment with HHS and federal cybersecurity mandates, and supporting modernization efforts that strengthen security posture, improve operational resilience, and enable compliant system delivery.
The SecurityArchitect will lead technical planning for security control implementation, provide guidance to stakeholders across infrastructure and application teams, and contribute to remediation strategy, continuous monitoring alignment, and integration of security requirements into enterprise environments. The position supports Client's cybersecurity and risk-based program objectives including improving security infrastructure, integrating federal requirements into operational execution, and supporting continuous monitoring and automation activities.
Key Responsibilities
SecurityArchitecture Design & Improvement
Design and recommend enterprise securityarchitecture improvements for Client systems, focusing on strengthening security posture across network, infrastructure, cloud, and application layers.
Develop securityarchitecture artifacts such as:
Target-state securityarchitecture models
Security service integration patterns (identity, logging, scanning, endpoint security, WAF)
Security control inheritance mapping for enterprise services and shared platforms
Conduct architecture reviews to identify security gaps and opportunities for improved resiliency and compliance alignment.
Vulnerability Remediation Strategy Support
Support the development of vulnerability remediation strategies by analyzing scan results, security weaknesses, and systemic configuration issues impacting Client environments.
Recommend enterprise remediation approaches such as:
Standard security baselines (e.g., hardened images, secure configurations)
Compensating controls where patching is delayed or constrained
Repeatable remediation processes across system classes (servers, endpoints, cloud workloads)
Assist stakeholders in prioritizing remediation based on risk, mission impact, and federal compliance expectations.
Analyze HHS Design Requirements & Security Impacts
Analyze HHS and federal design requirements and evaluate impacts to Client's architecture, implementations, and operational processes.
Translate requirements into actionable securityarchitecture guidance for:
Infrastructure engineering teams
Application owners and system developers
Governance/compliance stakeholders (FISMA, RMF, POA&M coordination)
Provide architectural interpretation and support for new security mandates and evolving federal expectations.
Define Security Deployment Approach (Enterprise Implementation Patterns)
Define secure deployment approaches for new and existing systems, ensuring security controls and tools are implemented consistently and efficiently.
Produce standardized design approaches for:
Secure logging and monitoring architectures (supporting SIEM/Splunk ingestion and monitoring coverage)
Vulnerability scanning integration and automated evidence generation
Identity and privileged access integration (IAM + PAM patterns)
Ensure solutions support both operational needs and compliance requirements.
Implementation Plans for New Controls, Capabilities, and Tools
Create implementation plans for deploying new security controls or tool capabilities, including:
Scope definition and technical prerequisites
Integration dependencies across teams and environments
Phased rollouts, validation checkpoints, and operational transition steps
Support adoption of security tools and security control implementation activities that improve Client's maturity and automated security posture.
Support Cloud + On-Prem Security Integrations
Architect integration of cloud and on-prem solutions to support secure hybrid operations aligned to Client's enterprise security framework.
Support integration activities involving:
Cloud security tooling integrations
Network security boundaries and monitoring pipelines
Web application protection patterns (e.g., WAF integrations)
Assist with securearchitecture decisions for systems operating under federal compliance constraints.
Provide Technical Guidance to Stakeholders
Provide technical leadership and architecture guidance to cross-functional stakeholders including system owners, engineers, program teams, and compliance personnel.
Support design reviews, technical working sessions, and architecture decision-making, including:
Explaining security control requirements and implementation options
Advising on secure patterns for system modernization and new deployments
Collaborating on resolving engineering blockers impacting security posture
Support Modernization & Automation Initiatives
Support modernization initiatives that improve Client's cybersecurity capability through automation and improved security-by-design practices.
Contribute architecture guidance for initiatives such as:
Enhanced continuous monitoring approaches (NIST SP 800-137 aligned)
Integrating security requirements into DevSecOps/CI/CD delivery pipelines (as applicable to security automation goals)
Supporting implementation strategies for improved security metrics and reporting capabilities
Requirements:
Education: Bachelor's degree in one of the following or related technical discipline (Cybersecurity / Information Assurance /Information Systems / Information Technology / Computer Science / Engineering)
Certification: Preferred: CISSP (industry standard preferred credential for senior securityarchitecture roles)
Experience:
Minimum: 5+ years of experience in enterprise securityarchitecture and/or security engineering
Experience supporting federal cybersecurity programs and security governance objectives (FISMA/NIST-aligned)
Hands-on exposure to cloud securityarchitecture and hybrid integration patterns
Experience designing security modernization approaches (automation, improved monitoring, scalable control deployment).
Strong background in securityarchitecture and security engineering with demonstrated ability to design enterprise security solutions
Experience developing architecture recommendations that improve security posture across hybrid IT environments
Ability to evaluate and translate security requirements into actionable architecture decisions and implementation plans
Working knowledge of:
Vulnerability remediation strategy development and execution support
Continuous monitoring practices and operational security reporting
Security tool integrations and technical dependencies across organizations
Tools Set / Platforms
The SecurityArchitect will work across architecture and compliance support tooling such as:
Securityarchitecture tools (models, diagrams, and enterprise design artifacts)
GRC artifacts and governance documentation (e.g., control evidence, security posture analysis)
Cloud security tooling and hybrid security capabilities
Scanning tools outputs used to drive remediation and risk reduction efforts
Compensation and Benefits
The projected compensation range for this position is $100,000 to $200,000 per year, benchmarked in the Washington, D.C. metropolitan area. Salary at LCG is determined by various factors, including but not limited to role, location, education/training, skills, certifications, and experience.
LCG offers a competitive and comprehensive benefits package including medical, dental, and vision insurance, life and disability insurance, retirement plan contributions, paid leave, federal holidays, professional development opportunities, and lifestyle benefits.
Devoted to Fair and Inclusive Practices
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.
If you are interested in applying for employment with LCG and need special assistance or an accommodation to apply for a posted position, contact Human Resources at *************.
Securing Your Data
Beware of fraudulent job offers using LCG's name. LCG will never request payment-related details or advance payment during the application process. Legitimate communication will only come from lcginc.com or ************************* email addresses.
$100k-200k yearly Easy Apply 4d ago
Information Systems Security Officer (ISSO) - TS/SCI with Polygraph
GDIT
Security architect job in Herndon, VA
Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Top Secret SCI + Polygraph
Clearance Level Must Be Able to Obtain:
Top Secret SCI + Polygraph
Public Trust/Other Required:
None
Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Information Security, Information Technology Security, System Security Plans
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes
Job Description:
Own the opportunity as an Information Systems Security Officer (ISSO) and help ensure the mission is never interrupted. At GDIT, we deliver clarity with our cloud solutions and provide meaningful work. Your work will be an important part of transforming our clients for the modern age and help them face any obstacle
Ensure the safety and security of our nation as a Software Developer at GDIT. You'll apply the latest technology and provide operational support to deliver actionable intelligence for the Intelligence Community. Here, your work will have meaning and impact as you deliver your best every day.
At GDIT, people are our differentiator. As an ISSO supporting the customer, you will be trusted to solve complex IT issues while delivering outstanding customer service.
HOW THE ISSO WILL MAKE AN IMPACT
Work in close collaboration with a small team of ISSOs and ISSE to support the customers critical systems
Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in
the security authorization package
Conduct periodic reviews of Information Systems to ensure compliance with the security authorization package
Coordinate with systems administrators to perform system scans for A&A and continuous monitoring to include but not limited
to network devices, servers, databases, and web services
Perform compliance audits, participate in incident handling, and lead or assist investigations into security anomalies
Perform review of audit logs and continuous monitoring tools for IT systems to identify anomalies, hacking or insider threats
WHAT YOU'LL NEED TO SUCCEED:
Education: BA/BS (or equivalent experience)
Required Experience: 8+ years of relevant experience
Required Technical Skills:
ICD-503, FISMA, RMF, NIST, FIPS, CNSSI 1253, Nessus, A&A, Strong Engineering Experience
Required Skills and Abilities: Demonstrated on-the-job knowledge experience with reviewing security concepts of operations, systems security plans, security control assessments, contingency plans, configuration management plans, incident response plans, vulnerability scanning, and/or vulnerability management plans
Security Clearance Level: TS/SCI w/ Polygraph
Location: Herndon, VA - Customer Site
#OpportunityOwned
#GDITCareers
#WeAreGDIT
#JET
#VA_2025Alumni
#GDITEnhanced2026
GDIT IS YOUR PLACE:
401K with company match
Comprehensive health and wellness packages
Internal mobility team dedicated to helping you own your career
Professional growth opportunities including paid education and certifications
Cutting-edge technology you can learn from
Rest and recharge with paid vacation and holidays
The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
Less than 10%
Telecommuting Options:
Onsite
Work Location:
USA VA Herndon
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$159k-215.1k yearly Auto-Apply 3d ago
Information System Security Officer (ISSO)
T-Rex Solutions 4.1
Security architect job in Ashburn, VA
Job Description
T-Rex Solutions is seeking a results-driven Information System Security Officer (ISSO) to support our U.S. Customs and Border Protection (CBP) Network Operations Center (NOC). The program objective is to provide ongoing support for CBP's NOC and Wireless Network Operations Center (WNOC), which are critical components within the Office of Information and Technology. These centers perform real-time monitoring, proactive maintenance, incident detection and response, problem resolution, and network performance reporting across CBP's nationwide enterprise. They ensure network stability, availability, and the rapid escalation and resolution of technical issues. This is a 24x7x365 operation with work performed on-site in Ashburn, VA.
Responsibilities:
The ISSO shall ben assigned to one or more existing FISMA Systems of Record as well as new IT Systems that are slated as new work products to develop an Authority to Operate (ATO) and follow-on Continuous Monitored system.
Develop and maintain all required FISMA system documentation.
Ensure systems adhere to Technical Reference Architecture (TRA) foundational and supplemental documents as additional security specifications, when applicable (available upon request).
Use approved security tools for continuous monitoring and management of security baselines.
Implement audit tools or processes for auditing and reporting services that support Continuous Diagnostics and Monitoring (CDM).
Provide engineering services and participation in Continuity of Operations Planning (COOP) and Disaster Recovery (DR) planning and exercises.
Develop and implement Configuration Management and Change Management plans when necessary.
Perform or participate in threat and vulnerability management for applicable FISMA systems.
Perform POA&M management.
Requirements:
Bachelor's degree in related technical field such as Management Information Systems, Computer Science, Engineering, IT, Networking and Telecommunications.
A minimum of ten (10) plus years of related experience
Certifications, such as Network+ and Security +, CISSP and Security auditing are recommended.
Proficient in network and information system security principles and best practices.
In-depth knowledge of the Risk Management Framework (RMF), the NIST publications, and the DHS 4300A Policy Directive.
Experience with implementing the NIST 800-53 Security Controls in an Assessment & Authorization (A&A) process.
Experience reviewing Nessus scans, managing vulnerability mitigation and the information security process in an Enterprise environment.
Basic understanding of Enterprise networking concepts.
Ability to work well within a team environment and build reports with government and customer organizations.
US citizenship required
Ability to obtain and maintain a CBP public trust clearance
Desired Skills:
Experience directly supporting DHS, CBP or ICE Network Operations
Active CBP clearance, or DOD Secret clearance or higher
T-Rex Overview
Established in 1999, T-Rex Solutions, LLC is a proven mid-tier business providing data-centric mission services to the Federal government as it increasingly tries to secure and leverage the power of data. We design, integrate, secure, and deploy advanced technical solutions for our customers so they can efficiently fulfill their critical objectives. T-Rex offers both IT and professional services to numerous Federal agencies and is a leader in providing high quality and innovative solutions in the areas of Cloud and Infrastructure Services, Cyber Security, and Big Data Engineering.
T-Rex is constantly seeking qualified people to join our growing team. We have built a broad client base through our devotion to delivering quality products and customer service, and to do that we need quality individuals. But more than that, we at T-Rex are committed to creating a culture that supports the development of every employee's personal and professional lives. T-Rex has made a commitment to maintain the status of an industry leader in compensation packages and benefits which includes competitive salaries, performance bonuses, training and educational reimbursement, Transamerica 401(k) and Cigna healthcare benefits.
T-Rex is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex (including pregnancy and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors.
In compliance with pay transparency guidelines, the annual base salary range for this position is $120,000 - $160,000. Please note that the salary information is a general guideline only. T-Rex considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer.
T-Rex offers a diverse and collaborative work environment, exciting opportunities for professional growth, and generous benefits, including: PTO available to use immediately upon joining (prorated based on start date), paid parental leave, individual and family health, vision, and dental benefits, annual budget for training, professional development and tuition reimbursement, and a 401(k) plan with company match fully vested after 60 days of employment among other benefits.
$120k-160k yearly 13d ago
Network Security Architect - Herndon, Virginia ( Only GC or Citizens )
Info. Services Inc. 4.2
Security architect job in Herndon, VA
Role: Network SecurityArchitect Duration: 6+ Months BGV will be done for the selected candidates. Job Functions (Network & SecurityArchitect) Performs analysis of network security needs and contributes to design, integration, and installation of hardware and software.
Analyzes, troubleshoots, and corrects network problems remotely and on-site.
Maintains and administers perimeter security systems such as firewalls and intrusion detection systems.
Modifies and maintains network security policy.
Installs and maintains Cisco routers and Cisco switches
Hands on experience on Cisco Nexus switches, Cisco ASR series routers, Cisco Fabric switches.\
Implements and administers IP load balancing with Citrix NetScaler, F5 load balancers and Big/IP, hardware SSL accelerators, and other software/hardware as necessary.
Designs and implements remote connectivity solutions including IPsec VPN, PPTP, and SSLVPN
Design, configure, and implements Citrix Presentation Server solutions
Troubleshoots Windows 2012/2008/2003 permission and other related issues
Builds and integrates new application servers including file and print, database, web, mail, and servers to support call center applications.
Monitors security system logs (i.e. intrusion detection system, firewall system logs, etc.) and reports on discovered anomalies or problems (i.e. insufficient disk space, inappropriate access patterns) on a weekly basis.
Meet with Business and Engineering teams to develop understanding of network & security requirements. Based on these requirements design the overall changes to the network solution across both Public and Private cloud including VPC & VLAN configuration, ports to be opened, ACLs, firewall rule changes.
Tests new computer/router/switch hardware and software solutions prior to implementation.
Administers and configures Windows 2008, Windows 2003, and Unix-based systems, as needed.
Uses sniffers and other tools to troubleshoot and isolate network problems.
Assists with network security assessments for potential business partners.
Keeps fully abreast of trends and changing technologies as they relate to IT and Network Engineering and Information Security fields. Engages in continuous process improvement.
Performs other related duties as may be required.
Prior hands-on professional experience must include Windows 2008, Windows 2003, Windows XP, Juniper Firewalls, and Checkpoint Firewalls. Cisco ASA and/or Linux experience would be a plus.
Working knowledge of operating systems including Windows 2008, Windows 2003, Windows 2000, Windows XP, and UNIX.
Expertise on network security, Juniper firewalls, Checkpoint firewalls, intrusion detection systems, authentication mechanisms, encryption technologies, and networking protocols including SMTP, HTTP, DNS, TCP/IP, and SNMP
Strong analytical, reasoning, and organizational skills are essential.
Excellent verbal and written communications skills are essential.
Ability to establish and maintain effective work relationships with all levels of personnel both internally and externally; e.g. leadership, executives, clients, vendors, and agencies.
Ability to work in and constructively contribute to team work environment and meet stringent deadlines.
Ability to prioritize and handle multiple tasks simultaneously.
Attention to detail and follow through including the ability to document work.
Ability to maintain the confidentiality of information is essential.
Minimum of 10-12 years directly related work experience in network, security administration\ engineering.
Acquire a complete understanding of a company's technology and information systems to be able to advice on overall security and network challenges. Review and address all vulnerabilities and security incidents, recommending strategies and solutions for risk mitigation.
Develop and build security posture with respect to: user administration, privileged identity management, intrusion detection, firewall configuration, DDOS, WAF and other security related components; continuously update Somos on new vulnerabilities; assess risks and solutions and engage with third parties and OEMs as needed. Develop concrete plans.
Reviewing results of monthly Vulnerability Scans, engaging infrastructure and application teams as needed to address vulnerabilities.
Support for ISO27002 security audit and updates to security policy, security training program and vendor security requirements as required.
Manage Antivirus policies on servers and Endpoints. Update server and antivirus clients.
Plan, research and design robust securityarchitectures for any IT project.
Manage Network Firewalls, Web Application Firewalls and IDS/IPS.
Research security standards, security systems and authentication protocols Infrastructure and Operations Services Statement of Work.
Develop requirements for local area networks (LANs), wide area networks (WANs), virtual private
Networks (VPNs), routers, firewalls, and related network devices.
Review and approve installation of firewall, VPN, routers, IDS and servers.
Test final security structures to ensure they behave as expected
Provide technical supervision for (and guidance to) a security team.
Define, implement and maintain security policies and procedures.
Oversee security awareness programs and educational efforts.
Please respond with your word resume and requested details:
Full Name :
Work Authorization:
Contact Number :
Email ID :
Skype ID:
Current location:
Willing to relocate :
Rate/hr :
Additional Information
All your information will be kept confidential according to EEO guidelines.
$106k-144k yearly est. 3d ago
Network Security Architect - Herndon, Virginia ( Only GC or Citizens )
Info-Ways
Security architect job in Herndon, VA
Role: Network SecurityArchitect Duration: 6+ Months BGV will be done for the selected candidates.
Job Functions (Network & SecurityArchitect) Performs analysis of network security needs and contributes to design, integration, and installation of hardware and software.
Analyzes, troubleshoots, and corrects network problems remotely and on-site.
Maintains and administers perimeter security systems such as firewalls and intrusion detection systems.
Modifies and maintains network security policy.
Installs and maintains Cisco routers and Cisco switches
Hands on experience on Cisco Nexus switches, Cisco ASR series routers, Cisco Fabric switches.\
Implements and administers IP load balancing with Citrix NetScaler, F5 load balancers and Big/IP, hardware SSL accelerators, and other software/hardware as necessary.
Designs and implements remote connectivity solutions including IPsec VPN, PPTP, and SSLVPN
Design, configure, and implements Citrix Presentation Server solutions
Troubleshoots Windows 2012/2008/2003 permission and other related issues
Builds and integrates new application servers including file and print, database, web, mail, and servers to support call center applications.
Monitors security system logs (i.e. intrusion detection system, firewall system logs, etc.) and reports on discovered anomalies or problems (i.e. insufficient disk space, inappropriate access patterns) on a weekly basis.
Meet with Business and Engineering teams to develop understanding of network & security requirements. Based on these requirements design the overall changes to the network solution across both Public and Private cloud including VPC & VLAN configuration, ports to be opened, ACLs, firewall rule changes.
Tests new computer/router/switch hardware and software solutions prior to implementation.
Administers and configures Windows 2008, Windows 2003, and Unix-based systems, as needed.
Uses sniffers and other tools to troubleshoot and isolate network problems.
Assists with network security assessments for potential business partners.
Keeps fully abreast of trends and changing technologies as they relate to IT and Network Engineering and Information Security fields. Engages in continuous process improvement.
Performs other related duties as may be required.
Prior hands-on professional experience must include Windows 2008, Windows 2003, Windows XP, Juniper Firewalls, and Checkpoint Firewalls. Cisco ASA and/or Linux experience would be a plus.
Working knowledge of operating systems including Windows 2008, Windows 2003, Windows 2000, Windows XP, and UNIX.
Expertise on network security, Juniper firewalls, Checkpoint firewalls, intrusion detection systems, authentication mechanisms, encryption technologies, and networking protocols including SMTP, HTTP, DNS, TCP/IP, and SNMP
Strong analytical, reasoning, and organizational skills are essential.
Excellent verbal and written communications skills are essential.
Ability to establish and maintain effective work relationships with all levels of personnel both internally and externally; e.g. leadership, executives, clients, vendors, and agencies.
Ability to work in and constructively contribute to team work environment and meet stringent deadlines.
Ability to prioritize and handle multiple tasks simultaneously.
Attention to detail and follow through including the ability to document work.
Ability to maintain the confidentiality of information is essential.
Minimum of 10-12 years directly related work experience in network, security administration\ engineering.
Acquire a complete understanding of a company's technology and information systems to be able to advice on overall security and network challenges. Review and address all vulnerabilities and security incidents, recommending strategies and solutions for risk mitigation.
Develop and build security posture with respect to: user administration, privileged identity management, intrusion detection, firewall configuration, DDOS, WAF and other security related components; continuously update Somos on new vulnerabilities; assess risks and solutions and engage with third parties and OEMs as needed. Develop concrete plans.
Reviewing results of monthly Vulnerability Scans, engaging infrastructure and application teams as needed to address vulnerabilities.
Support for ISO27002 security audit and updates to security policy, security training program and vendor security requirements as required.
Manage Antivirus policies on servers and Endpoints. Update server and antivirus clients.
Plan, research and design robust securityarchitectures for any IT project.
Manage Network Firewalls, Web Application Firewalls and IDS/IPS.
Research security standards, security systems and authentication protocols Infrastructure and Operations Services Statement of Work.
Develop requirements for local area networks (LANs), wide area networks (WANs), virtual private
Networks (VPNs), routers, firewalls, and related network devices.
Review and approve installation of firewall, VPN, routers, IDS and servers.
Test final security structures to ensure they behave as expected
Provide technical supervision for (and guidance to) a security team.
Define, implement and maintain security policies and procedures.
Oversee security awareness programs and educational efforts.
Please respond with your word resume and requested details:
Full Name :
Work Authorization:
Contact Number :
Email ID :
Skype ID:
Current location:
Willing to relocate :
Rate/hr :
Additional Information
All your information will be kept confidential according to EEO guidelines.
$102k-141k yearly est. 60d+ ago
Information Systems Security Officer (ISSO)
Contact Government Services
Security architect job in Rockville, MD
ISSO Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities.
Skills and attributes for success:
* Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
* Maintain responsibility for managing cybersecurity risk from an organizational perspective.
* Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
* Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
* Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
* Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
* Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
* Provide subject matter expertise for cyber security and trusted system technology.
* Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
* Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes.
* Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.
* Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.
Qualifications:
* Bachelor's Degree.
* A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
* eMASS experience.
* Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
* Strong desktop publishing skills using Microsoft Word and Excel.
* Experience with industry writing styles such as grammar, sentence form, and structure.
* Ability to multi-task in a deadline-oriented environment.
Ideally, you will also have:
* CISSP, CASP, or a similar certificate is preferred.
* Master's Degree in Cybersecurity or related field.
* Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.
* Demonstrated ability to work well independently and as a part of a team.
* Excellent work ethic and a high commitment to quality.
Our Commitment:
Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems.
For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work.
Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come.
We care about our employees. Therefore, we offer a comprehensive benefits package.
Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dependent Care, and Commuter)
Paid Time Off and Observance of State/Federal Holidays
Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Join our team and become part of government innovation!
Explore additional job opportunities with CGS on our Job Board:
*************************************
For more information about CGS please visit: ************************** or contact:
Email: [email protected]
#CJ
$92,213.33 - $125,146.66 a year
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$92.2k-125.1k yearly 60d+ ago
Security Systems Engineer (i2G) - CAD
Kastle Systems 3.6
Security architect job in Sterling, VA
Together, We Enhance Innovation and Growth i2G specializes in advanced physical electronic security and life safety solutions. I2G has proven experience in surveillance, access control, and intrusion detection systems, biometrics, fence sensors, radars, ground sensors, anti-drone technologies, and more. We excel in design, project management, commissioning, and enterprise technology integrations.
i2G's mission is to provide the products and services that meet our customers' needs to give them a vital advantage in today's market, helping to protect what matters most.
This position will provide engineering design and support for security solutions for new and existing clients while working alongside internal teams, external teams, clients, and subcontractors to ensure project success.
Responsibilities
* Possess a thorough understanding of standard Electronic Security technology (ACS, IDS, FDS, CCTV) and supporting equipment such as computer software/hardware, databases, and networking infrastructure.
* Ability to review architectural, electrical, telecommunication, security engineering floor plans, riser drawings, device schedules, and detail drawings.
* Design, develop, and implement solutions for system installations, upgrades, repairs, and conversions.
* Review of Field Site Survey documentation and provide technical assistance with RFI/RFP responses.
* Create solution design documentation (drawings, BOMs, solution design summaries).
* Provide technical support for in-office and on-site team members.
* Support management in the process of creating documentation for implementing new technology with new and existing customers.
* Maintain familiarity with current and emerging electronic security technologies such as access control, video surveillance, intrusion detection, biometrics, etc. and industry leading vendors.
Qualifications
* A minimum of 3-7 years previous experience in the industry.
* Associate or bachelor's degree in relevant field preferred or applicable amount of experience in the appropriate field may be substituted for the educational background.
* Experience in the design and planning of access control and video systems.
* Professional Electronic Security Certifications or training (Lenel, Genetec, C-Cure. Avigilon, Axis, Bosch, Milestone, etc.) preferred.
Make a difference here. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams.
By creating continuously optimized identification, detection, and resilience from today's dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India.
UltraViolet Cyber is seeking a Senior Security (SOC) Analyst who will monitor and analyze security events and alerts reported by the SIEM on a 24x7 basis to identify and investigate suspicious or malicious activity, or other cyber events which violate policy. The Security Analyst will work with a large to team that rotates 3x12 or 4x12 hour shifts. The position requires a US Government issued Secret Clearance, and requires 5 days onsite per week in Herndon, VA.
The analyst will be responsible for analyzing logs and events from any other device types which may send logs or events to the SOC in the future. Non-traditional device feeds will deliver data to the SIEM architecture (e.g., Human Resources (HR) data, badging information, and physical security devices, etc.).
The analyst will provide documentation detailing any additional information collected and maintained for each security investigation.
The analyst will record all artifacts (i.e. emails, logs, documents, Uniform Resource Locators (URLs), screenshots, etc.) associated with all security events and incident investigations within the SOC incident and tracking application.
Must be legally allowed to work in the US, and the work must be done in the US.
No third-party candidates will be considered What You Have:
Active US Secret Security Clearance
5+ years of experience working in a Security Operations Center (SOC) or Network Operations Center (NOC) environment performing security event monitoring and analysis
Working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks.
Must possess a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.)
Familiarity with adversarial tactics, techniques, and procedures (TTPs)
Must be capable of analyzing security logs and events from the following types of devices such as, but not limited to:
Firewalls (FWs), Intrusion Detection Sensors/Intrusion Prevention Sensors (IDS/IPS)
Host-based Intrusion Detection System/ Host-based Intrusion Prevention System (HIDS/HIPS)
Additional: proxy/web filter, vulnerability scans, routers, router Internet Protocol (IP) accounting systems (i.e., Cisco NetFlow)
Virtual Private Network (VPN) gateways/concentrators, server event logs, e-mail and host anti-virus, desktop security monitoring agents, anti-virus servers, IP services (i.e. Domain Name System (DNS) Services, Dynamic Host Configuration Protocol (DHCP)
Additionally: network address translation devices, MDM (e.g. cellphones), Public Key Infrastructure (PKI), and cloud security infrastructure (e.g. Amazon Web Services (AWS), Azure, Oracle, Salesforce, etc.)
Education, Certification & Clearance Requirements:
8570 Certification(s): Security+ or equivalent
Clearance Requirements: Secret Clearance
High school diploma needed
Preferred Skills:
Certification(s): Security+, GCIH, CEH, or CYSA+ is desired
Experience with Splunk query language
Experience with IDS/IPS/firewall/security configurations and signature development
Experience with PCAP analysis
Experience with Tanium threat response
Ability and prior experience with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes the identification of malicious code present within a computer system as well identification of malicious activities that are present within a computer system and/or enterprise network
Experience working with a ticket management system to collect, document and maintain information pertinent to security investigations and incidents
Excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings
Experience in monitoring the operational status of monitoring components and escalating and reporting outages of the components
Conceptual understanding of Windows Active Directory is also desired
Experience working with various event logging systems and must be proficient in the review of security event log analysis. Previous experience with SIEM platforms that perform log collection, analysis, correlation, and alerting is also preferred
Experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment
Experience in collecting and maintaining information pertinent to security; investigations and incidents in a format that supports analysis, situational awareness reporting, and law enforcement investigation efforts
Benefits at UltraViolet Cyber!
401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
Group Term Life, Short-Term Disability, Long-Term Disability
Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
Participation in the Discretionary Time Off (DTO) Program
11 Paid Holidays Annually
We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable.
UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status.
If you want to make an impact, UltraViolet Cyber is the place for you!
$87k-118k yearly est. Auto-Apply 42d ago
Information Security Systems Engineer
Silveredgegs
Security architect job in Herndon, VA
SilverEdge is a premier provider of innovative cyber, software, and intelligence solutions, addressing mission-critical challenges for the Department of Defense (DoD), Intelligence Community (IC), and beyond. We are dedicated to delivering impactful results to meet mission goals through cutting-edge technology and expertise. We are seeking a Information Security Systems Engineer to join our dynamic team. This individual will play a pivotal role in developing innovative and effective solutions for our DoD customers within the IC sector.
Required Qualifications
We are actively seeking an Information Systems Security Engineer (ISSE) with a minimum of 11 years' experience with a Bachelor's Degree. Other degrees will be considered with the year's experience adjusted to accommodate. We are looking for a candidate with specific skills that may include the following:
• Implementation and validation of security controls that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation
• Developing architecture documentation and Systems Security Plans (SSP) to support Accreditation and Authorization (A&A) reviews
• POA&M development and implementation
• Coordinating with customer security organizations to achieve Authority to Operate (ATO).
• Knowledge of the complex environment involving shared networks and multiple security enclaves
• Engineering for Cyber engineering and integration services including security, authentication, identity management, authorization, and access control engineering.
• Self-starter able to work independently and build relationships with technical reps across divisions, comfortable with cyber security and able to brief issues to the customer
• Over 5 years of experience working on Government Agency enterprise infrastructure and engineering programs.
Preferred Education, Experience, & Skills:
• Nessus / Rapid7
• Security Development and Operations (SecDevOps)
• Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, Xacta
• Cloud security controls and implementation
• STIG compliance and vulnerability management
• CISSP
• AWS Certified Security Specialty
• Microsoft Office365
• Experience in one or more software products associated with cyber system engineering for data analytics including SQL security, TANIUM Endpoint Management Software, Powershell, MacAfee, App Blocker, Splunk ITSI.
• Experience with one or more software development environments supporting commercial or open source tools including but not limited to: Linux, Python, C, Bash Scripting, Perl, SQL, Splunk Phantom, UBA, and UIPath
• Experience in one or more cloud computing services and technologies including but not limited to: AWS/C2S, Microsoft Azure, Nutanix, VMware. **Government issued clearance and poly are required** Desired Qualifications About SilverEdge
SilverEdge Government Solutions was founded on the belief that nurturing talent and collaborating closely with our customers enables us to think big and deliver the best for our country. Our mission is to bring top technology talent together to solve the world's most challenging problems while protecting the United States and our allies. SilverEdge Government Solutions, LLC is an Equal Opportunity Employer and applicants receive lawful consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
Not ready to apply? Connect with us for general consideration.
$80k-112k yearly est. Auto-Apply 7d ago
Cyber Security Systems Engineer - Full Performance
Beyond SOF
Security architect job in Herndon, VA
Cyber Security Systems Engineer - Full Performance Cyber Security Systems Engineers work on all systems and/or projects within the Sponsors organization responsible for providing Network Defense. Duties, Tasks, and Responsibilities • Beta testing when directed by COTR Conduct proof of concept testing
• Conduct tier III support of current infrastructure
• Design, test, and integrate new security products as directed by COTR
• Ensure all Network Defense capabilities are kept current, patched, and securely configured and management informed of status, working with O&M.
• Full time engineering support for all primary systems such as network based Intrusion Detection and Protection Systems (IDPS).
• Integration of security products, including designs for all Agency networks
• Maintain a network diagram for each Instruction Detection, CIRT capability and sensors and make available to all Sponsor personnel.
• Maintain system baselines and configuration management items, including security event monitoring "policies" in a manner determined and agreed to by the program management
• Provide engineering documentation and interaction with Analysts and O&M to ensure a complete and functioning system that meets requirements
• Software testing (patches, other updates)
Knowledge, Skills, and Abilities
• Familiarity with network security applications, protocols and associated hardware Good interpersonal, organizational, writing, communications and briefing skills.
• Strong analytical and problem solving skills.
Minimum Certifications
• Depending on the duties the incumbent may require Agency Certified Tempest Test Engineer.
• Depending on the duties the incumbent may require CISSP certification
Minimum Education
• A bachelor's degree in electrical engineering, computer engineering, computer science, or other closely related discipline.
Minimum Experience
• Some Linux experience
• Minimum of five years of progressively responsible experience in network engineering with emphasis in design, implementation, operations and maintenance of a variety of Windows Servers, Application and Database servers, relevant Network Security appliances and Endpoint Security products.
$80k-112k yearly est. 60d+ ago
Information Security Systems Engineer
Silveredge Government Solutions
Security architect job in Herndon, VA
SilverEdge is a premier provider of innovative cyber, software, and intelligence solutions, addressing mission-critical challenges for the Department of Defense (DoD), Intelligence Community (IC), and beyond. We are dedicated to delivering impactful results to meet mission goals through cutting-edge technology and expertise. We are seeking a Information Security Systems Engineer to join our dynamic team. This individual will play a pivotal role in developing innovative and effective solutions for our DoD customers within the IC sector.
Required Qualifications
We are actively seeking an Information Systems Security Engineer (ISSE) with a minimum of 11 years' experience with a Bachelor's Degree. Other degrees will be considered with the year's experience adjusted to accommodate. We are looking for a candidate with specific skills that may include the following:
• Implementation and validation of security controls that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation
• Developing architecture documentation and Systems Security Plans (SSP) to support Accreditation and Authorization (A&A) reviews
• POA&M development and implementation
• Coordinating with customer security organizations to achieve Authority to Operate (ATO).
• Knowledge of the complex environment involving shared networks and multiple security enclaves
• Engineering for Cyber engineering and integration services including security, authentication, identity management, authorization, and access control engineering.
• Self-starter able to work independently and build relationships with technical reps across divisions, comfortable with cyber security and able to brief issues to the customer
• Over 5 years of experience working on Government Agency enterprise infrastructure and engineering programs.
Preferred Education, Experience, & Skills:
• Nessus / Rapid7
• Security Development and Operations (SecDevOps)
• Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, Xacta
• Cloud security controls and implementation
• STIG compliance and vulnerability management
• CISSP
• AWS Certified Security Specialty
• Microsoft Office365
• Experience in one or more software products associated with cyber system engineering for data analytics including SQL security, TANIUM Endpoint Management Software, Powershell, MacAfee, App Blocker, Splunk ITSI.
• Experience with one or more software development environments supporting commercial or open source tools including but not limited to: Linux, Python, C, Bash Scripting, Perl, SQL, Splunk Phantom, UBA, and UIPath
• Experience in one or more cloud computing services and technologies including but not limited to: AWS/C2S, Microsoft Azure, Nutanix, VMware. **Government issued clearance and poly are required** Desired Qualifications About SilverEdge
SilverEdge Government Solutions was founded on the belief that nurturing talent and collaborating closely with our customers enables us to think big and deliver the best for our country. Our mission is to bring top technology talent together to solve the world's most challenging problems while protecting the United States and our allies. SilverEdge Government Solutions, LLC is an Equal Opportunity Employer and applicants receive lawful consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
$80k-112k yearly est. Auto-Apply 9d ago
Cyber Security Systems Engineer (ISSE)-TS/SCI Full Scope Polygraph Only!
5Ipro
Security architect job in Herndon, VA
We are actively seeking a Cyber Security System Engineer (ISSE) with a minimum of 16 years of experience. Bachelor's or Master's Degrees are preferred in one or more of the disciplines described below where specific skills may include the following: Engineering for Cyber engineering and integration services including security, authentication, identity management, authorization, and access control engineering. We engineer a large Splunk Data Lake, providing tools for software design, development, and test. This is an information technology-centric program supporting a large government customer in Information Technology Analytics. This is a fast-paced, challenging, and career-rewarding experience in one of the most complex and high-profile programs within the government. Splunk SME preferred but willing to consider a right candidate with familiarization, A&A, Windows and Linux OS, ISSE\Security Engineer experience, scanning tools such as Nessus and Rapid7, Xacta, GUI, and Front end support self-starter able to work independently and build relationships with technical reps across divisions, comfortable with cyber security and able to brief issues to the customer over 5 years of experience engineering data analytics solutions with an emphasis on Splunk data lake infrastructure and producing Enterprise IT situational awareness for a top tier US Intelligence Agency. Experience in one or more software products associated with cyber system engineering for data analytics including SQL security, TANIUM Endpoint Management Software, Powershell, MacAfee, App Blocker, Splunk ITSI.Experience with one or more software development environments supporting commercial or open-source tools including but not limited to: Linux, Python, C, Bash Scripting, Perl, SQL, Splunk Phantom, UBA, and UIPathExperience in one or more cloud computing services and technologies including but not limited to: AWS/C2S, Microsoft Azure, Nutanix, VMware.Over 5 years of experience working on Intelligence Agency enterprise infrastructure and engineering programs, including Agile development and SecDevOps methodologies including on-site customer engagement.Preferred Education, Experience, & Skills :
Security Development and Operations (SecDevOps) Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, XactaCloud security controls and implementation PKI implementation STIG compliance and vulnerability management virtualization experience (VDI & VMWare) Public, private and hybrid Cloud experience (AWS, Microsoft Azure, etc.) CISSPAWS Certified Security SpecialtyMicrosoft Office365
$80k-112k yearly est. 60d+ ago
Cyber Security Systems Engineer (ISSE)
Bcore
Security architect job in Herndon, VA
Overview Cyber Security Systems EngineerHerndon, VATS/SCI with Poly
At Bcore, our strength comes from how we deliver impact to the mission. Whether it's architecting critical IT solutions, producing actionable intelligence, or developing cutting edge technology, we succeed because of the expertise, collaboration, and agility of our teams. Our Mission Services division combines enterprise IT, cloud solutions, DevSecOps, systems engineering, software development, and operational support. Bcore accelerates decisive advantage for warfighters and intelligence professionals by fusing human insight, rapid-fire engineering, precision-measured outcomes, and relentless grit into mission-ready solutions.
Do you want to join a team that is building tailored technical solutions to modernize our government's mission and our client's business? Do you have a desire to change how people work? Are you interested in helping to protect our nation's cyber interests? Join our growing team supporting customer missions as a Cyber Security Systems Engineer in Herndon, Virginia.
Qualifications
Required Qualifications:
We are actively seeking Cybersecurity Engineers with a minimum of eleven (11) years' experience.
Strong knowledge of Windows and Linux operating systems
Familiarity with system hardening, patch management, and configuration management tools
Experience supporting RMF or other accreditation frameworks (FedRAMP, NIST 800-53B, A&A, etc.)
Proficiency in scripting languages such as PowerShell, Python, or Bash
Hands-on experience with vulnerability scanning tools (e.g., Rapid 7), SIEM platforms (e.g., Splunk), and endpoint protection
Experience with patching and routine platform reboots across the hosting environment.
Ability to work in a high profile fast-paced environment.
Ability to test and deploy custom infrastructure as code using various DevOps tools such as: Jenkins, GitHub Ansible, PowerShell
Strong oral and written communication skills
Provide operations and maintenance support to the hosting platform solutions.
Conduct root cause analysis of noted system performance an operational issue.
Monitor the performance systems to analyze the metrics produced to identify areas of improvements and report potential anomalies.
Emergency after hours engineering support as needed.
Communicate to technical and non-technical audiences.
Desired Qualifications
Certifications: CISSP, CISM, Security+, CEH, GSEC, or Cloud Security certifications (e.g., AWS Security, Azure Security Engineer)
Experience working in air-gapped environments or with classified systems
Experience with Agile methodologies and working in sprint-based development cycles
Familiarity with security in CI/CD pipelines and container security (e.g., Docker, Kubernetes)
Knowledge of zero trust architecture and identity/access management strategiesT
Toolsets & Platforms:
Security Tools: Splunk, Rapid 7
Operating Systems: Windows Server, RHEL/CentOS, Ubuntu
Compliance Tools: Rapid 7, Greenlight, Illuminate
Cloud Platforms: AWS, Azure, GCP
Automation/Scripting: PowerShell, Python, Bash, Ansible
DevSecOps: Jenkins, Git, Docker, Kubernetes
Soft Skills:
Strong analytical and troubleshooting skills
Excellent communication and documentation abilities
Self-starter with ability to manage multiple tasks
What you can expect from us
BCore is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, sexual orientation or any other characteristic protected by law.
$80k-112k yearly est. Auto-Apply 8d ago
Information Systems Security Officer, Classified (#1882)
Battelle National Biodefense Inst
Security architect job in Frederick, MD
Job Description
BACKGROUND
The National Biodefense Analysis and Countermeasures Center (NBACC) is a one-of-a-kind facility located on Fort Detrick in Frederick MD and is dedicated to defending the nation against biological threats. Its work supports DHS and National biodefense preparedness planning, response, emerging threat characterization and bioforensic analyses. It is the first national laboratory created by DHS in response to biodefense gaps identified following the Amerithrax attacks of 2001 and has been operated by the Battelle National Biodefense Institute (BNBI) since 2006. Since its inception, NBACC and its staff have filled critical shortfalls in our scientific knowledge of biological agents needed to protect the public and defend the Nation from biological threats, whether naturally occurring, accidental, or deliberate and provided federal law enforcement with scientific data to support the investigation and attribution of biocrimes and protection of the US bioeconomy.
NBACC includes two centers: the National Bioforensic Analysis Center (NBFAC), which conducts the technical analyses in support of federal law enforcement investigations, and the National Biological Threat Characterization Center (NBTCC), which conducts experiments and studies to obtain data required for a better understanding of biological vulnerabilities and hazards. Together these centers offer a unique national resource for understanding the risks posed by biological agents and emerging technologies to inform biodefense policy and response planning and the operational capability to support the investigation, prosecution, and prevention of biocrimes and bioterrorism.
PRIMARY FUNCTION
The Information Systems Security Officer, Classified (ISSO, Classified) advises the Network Security Manager (NSM), IT Manager, and System Owner on NBACC Information Systems security matters for the systems assigned. This individual must ensure that NBACC IT Systems are compliant with DHS information security policies, regulations and requirements and must complete and maintain assigned system Authorization and Accreditation (A&A) requirements. The ISSO, Classified, serves as the primary point of contact for all security matters related to the assigned systems and supports the NSM to ensure implementation of an Information Security Program is maintained throughout NBACC.
MINIMUM REQUIRED QUALIFICATIONS
Bachelor's Degree (or equivalent), preferably in Cybersecurity and/or Computer and Information Systems related studies and a minimum of 4 years of related experience.
Certified Information Systems Security Professional (CISSP) preferred, although other security certifications will be considered.
Federal cybersecurity policy and compliance experience are required.
Experience working in a secure environment is desired.
Strong understanding and working knowledge of information security principles and risk assessment/risk management techniques.
Experience with security technologies including vulnerability scanning, firewalls & log analysis, host-based detection tools, Security Event and Incident Management (SEIM), antivirus, network packet analyzers, malware analysis, and forensics tools.
Ability to interpret, analyze, and report significant event findings and anomalies in accordance with computer network directives.
Experience managing COMSEC is highly desired.
Skills and experience to support laboratory activities and work in accordance with NBACC's management system (e.g., ISO).
Must be a citizen of the United States, able to obtain and maintain an interim secret clearance leading to a top-secret suitability for DHS. SCI clearance required.
Participation in the Immunization Program, Medical Surveillance Program and/or enrollment in the Personnel Reliability (PRP) is required.
May be required to participate in NBACC's alternative work and/or on-call schedule, dependent upon business needs.
PRIMARY RESPONSIBILITIES
Serves as the principal point of contact for all IT security aspects pertaining to the classified IT systems for which the ISSO is responsible.
Familiarity with 4300C policies.
Works closely with the Component ISSM and DHS CISO staff, as appropriate, to interpret and apply IT security policies and procedures.
Ensures that the NSM and the IT Manager are kept informed of all pertinent matters involving security or non-compliance of IT systems.
Works with other ISSOs and the NSM as needed, to maintain, enhance and optimize the technologies that are currently deployed within the organization.
Works with system owners to document system vulnerabilities and weaknesses in Plans of Action and Milestones (POA&Ms) and to initiate corrective actions.
Employs automated tools approved by the DHS CISO, such as Nessus, CSAM, SwimLane, Crowdstrike.
Ensures that all NBACC personnel receive computer security awareness training as part of the onboarding process and ensures that all security measures are in place with NBACC personnel offboarding. In addition, ensures that all security procedures are in place and performed in the case of terminated employee specifically to prevent unauthorized access.
Responsible for performing vulnerability scanning and analysis, eliminating false-positives, and providing administrators with relevant reports to assist in mitigating or removing actual threats.
Performs monitoring and data correlation to events of interest using multiple tools such as system event logs, IPS/IDS logs, network traffic, anti-virus console and client end-point software.
Maintains all documentation and security artifacts detailing the information systems purpose, implemented controls, inventory of hardware, firmware, and software, configurations and other security relevant details. Develops and maintains the system security plan for every IT system assigned.
Evaluates proposed modifications to assigned NBACC classified information systems, ensures modifications meet regulatory compliance and provides input on the impact of system changes to security to the NSM.
Assists in the development of system modifications and system change proposals and ensures that security procedures are in place and performed to prevent unauthorized access.
Performs tuning for security monitoring products and customizes tools to automate security processes and event correlation, as needed.
Audits and evaluates back-up and disaster recovery plans to identify weaknesses.
Researches the latest information technology security trends to increase the organization's situational awareness and stay up to date on the latest methods attackers are using to infiltrate computer systems.
Recommends tools and implementation of security controls based on directives, vulnerability matrix, and threat advisories. Provides summary reports of events and activities and delivers metric reports as needed.
Must be a team player, communicate clearly, be open to hearing ideas and suggestions from others, diffuse situations, and exercise empathy and patience with colleagues.
Must have the ability to multi-task, maintain composure under pressure, and utilize effective time management skills to prioritize tasks.
Must be a self-starter driven by an eagerness to succeed, maintain flexibility, adapt to change in a productive and positive manner, learn new concepts, and utilize critical thinking to resolve complex problems.
Maintains appropriate records.
Performs other duties as assigned/authorized.
$65k-88k yearly est. 26d ago
Information System Security Officer (ISSO)
T-Rex Solutions 4.1
Security architect job in Ashburn, VA
T-Rex Solutions is seeking a results-driven Information System Security Officer (ISSO) to support our U.S. Customs and Border Protection (CBP) Network Operations Center (NOC). The program objective is to provide ongoing support for CBP's NOC and Wireless Network Operations Center (WNOC), which are critical components within the Office of Information and Technology. These centers perform real-time monitoring, proactive maintenance, incident detection and response, problem resolution, and network performance reporting across CBP's nationwide enterprise. They ensure network stability, availability, and the rapid escalation and resolution of technical issues. This is a 24x7x365 operation with work performed on-site in Ashburn, VA.
Responsibilities:
The ISSO shall ben assigned to one or more existing FISMA Systems of Record as well as new IT Systems that are slated as new work products to develop an Authority to Operate (ATO) and follow-on Continuous Monitored system.
Develop and maintain all required FISMA system documentation.
Ensure systems adhere to Technical Reference Architecture (TRA) foundational and supplemental documents as additional security specifications, when applicable (available upon request).
Use approved security tools for continuous monitoring and management of security baselines.
Implement audit tools or processes for auditing and reporting services that support Continuous Diagnostics and Monitoring (CDM).
Provide engineering services and participation in Continuity of Operations Planning (COOP) and Disaster Recovery (DR) planning and exercises.
Develop and implement Configuration Management and Change Management plans when necessary.
Perform or participate in threat and vulnerability management for applicable FISMA systems.
Perform POA&M management.
Requirements:
Bachelor's degree in related technical field such as Management Information Systems, Computer Science, Engineering, IT, Networking and Telecommunications.
A minimum of ten (10) plus years of related experience
Certifications, such as Network+ and Security +, CISSP and Security auditing are recommended.
Proficient in network and information system security principles and best practices.
In-depth knowledge of the Risk Management Framework (RMF), the NIST publications, and the DHS 4300A Policy Directive.
Experience with implementing the NIST 800-53 Security Controls in an Assessment & Authorization (A&A) process.
Experience reviewing Nessus scans, managing vulnerability mitigation and the information security process in an Enterprise environment.
Basic understanding of Enterprise networking concepts.
Ability to work well within a team environment and build reports with government and customer organizations.
US citizenship required
Ability to obtain and maintain a CBP public trust clearance
Desired Skills:
Experience directly supporting DHS, CBP or ICE Network Operations
Active CBP clearance, or DOD Secret clearance or higher
T-Rex Overview
Established in 1999, T-Rex Solutions, LLC is a proven mid-tier business providing data-centric mission services to the Federal government as it increasingly tries to secure and leverage the power of data. We design, integrate, secure, and deploy advanced technical solutions for our customers so they can efficiently fulfill their critical objectives. T-Rex offers both IT and professional services to numerous Federal agencies and is a leader in providing high quality and innovative solutions in the areas of Cloud and Infrastructure Services, Cyber Security, and Big Data Engineering.
T-Rex is constantly seeking qualified people to join our growing team. We have built a broad client base through our devotion to delivering quality products and customer service, and to do that we need quality individuals. But more than that, we at T-Rex are committed to creating a culture that supports the development of every employee's personal and professional lives. T-Rex has made a commitment to maintain the status of an industry leader in compensation packages and benefits which includes competitive salaries, performance bonuses, training and educational reimbursement, Transamerica 401(k) and Cigna healthcare benefits.
T-Rex is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex (including pregnancy and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors.
In compliance with pay transparency guidelines, the annual base salary range for this position is $120,000 - $160,000. Please note that the salary information is a general guideline only. T-Rex considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer.
T-Rex offers a diverse and collaborative work environment, exciting opportunities for professional growth, and generous benefits, including: PTO available to use immediately upon joining (prorated based on start date), paid parental leave, individual and family health, vision, and dental benefits, annual budget for training, professional development and tuition reimbursement, and a 401(k) plan with company match fully vested after 60 days of employment among other benefits.
$120k-160k yearly Auto-Apply 20d ago
Security Systems Engineer (i2G) - CAD
Kastle Systems International 3.6
Security architect job in Sterling, VA
Together, We Enhance Innovation and Growth
i2G specializes in advanced physical electronic security and life safety solutions. I2G has proven experience in surveillance, access control, and intrusion detection systems, biometrics, fence sensors, radars, ground sensors, anti-drone technologies, and more. We excel in design, project management, commissioning, and enterprise technology integrations.
i2G's mission is to provide the products and services that meet our customers' needs to give them a vital advantage in today's market, helping to protect what matters most.
This position will provide engineering design and support for security solutions for new and existing clients while working alongside internal teams, external teams, clients, and subcontractors to ensure project success.
Responsibilities
Possess a thorough understanding of standard Electronic Security technology (ACS, IDS, FDS, CCTV) and supporting equipment such as computer software/hardware, databases, and networking infrastructure.
Ability to review architectural, electrical, telecommunication, security engineering floor plans, riser drawings, device schedules, and detail drawings.
Design, develop, and implement solutions for system installations, upgrades, repairs, and conversions.
Review of Field Site Survey documentation and provide technical assistance with RFI/RFP responses.
Create solution design documentation (drawings, BOMs, solution design summaries).
Provide technical support for in-office and on-site team members.
Support management in the process of creating documentation for implementing new technology with new and existing customers.
Maintain familiarity with current and emerging electronic security technologies such as access control, video surveillance, intrusion detection, biometrics, etc. and industry leading vendors.
Qualifications
A minimum of 3-7 years previous experience in the industry.
Associate or bachelor's degree in relevant field preferred or applicable amount of experience in the appropriate field may be substituted for the educational background.
Experience in the design and planning of access control and video systems.
Professional Electronic Security Certifications or training (Lenel, Genetec, C-Cure. Avigilon, Axis, Bosch, Milestone, etc.) preferred.
Other Eligibility Requirements
Ability to manage time and multiple tasks without supervision.
Organizational skills & detail oriented.
Good analytical and problem-solving skills.
Excellent presentation, writing skills, verbal, and written customer communication skills.
Experience in computer programs such as Microsoft Office, Adobe, etc. preferred. Microsoft Project, Visio, BlueBeam, AutoCAD, or Revit is a plus.
$100k-140k yearly est. Auto-Apply 60d+ ago
Cyber Security Systems Engineer
Bcore
Security architect job in Herndon, VA
Overview Cyber Security Systems Engineer (ISSE) Herndon, VATS/SCI with Poly
At Bcore, our strength comes from how we deliver impact to the mission. Whether it's architecting critical IT solutions, producing actionable intelligence, or developing cutting edge technology, we succeed because of the expertise, collaboration, and agility of our teams. Our Mission Services division combines enterprise IT, cloud solutions, DevSecOps, systems engineering, software development, and operational support. Bcore accelerates decisive advantage for warfighters and intelligence professionals by fusing human insight, rapid-fire engineering, precision-measured outcomes, and relentless grit into mission-ready solutions.
Do you want to join a team that is building tailored technical solutions to modernize our government's mission and our client's business? Do you have a desire to change how people work? Are you interested in helping to protect our nation's cyber interests? Join our growing team supporting customer missions as a Cyber Security Systems Engineer (ISSE) in Herndon, Virginia.
Qualifications
Required Qualifications:
We are actively seeking an Information Systems Security Engineer (ISSE) with a minimum of 11 years' experience with a Bachelor's Degree. Other degrees will be considered with the year's experience adjusted to accommodate. We are looking for a candidate with specific skills that may include the following:
Engineering for Cyber engineering and integration Implementation and validation of security controls in support of the Risk Management Framework (RMF), ICD 503 accreditation, and NIST 800-53B.
Developing architecture documentation and Systems Security Plans (SSP) to support Accreditation and Authorization (A&A) reviews
POA&M development and implementation
Coordinating with customer security organizations to achieve Authority to Operate (ATO).
Knowledge of the complex environment involving shared networks and multiple security enclaves
Services including security, authentication, identity management, authorization, and access control engineering
Self-starter able to work independently and build relationships with technical reps across divisions, comfortable with cyber security and able to brief issues to customer
Over 5 years of experience working on Government Agency enterprise infrastructure and engineering programs.
Security Development and Operations (SecDevOps)
Proven capability to work in a fast-paced environment while collaborating with cross-functional technical teams
Various security tool and processes such as Splunk, Nessus Security Center, WebInspect, Xacta
STIG compliance and vulnerability management
CompTIA Security+
Experience in one or more cloud computing services and technologies including but not limited to:AWS/C2S, Mircsoft Azure, Nutanix, VMware.
Desired Qualifications
Nessus / Rapid7
Greenlight
MS Office 365
Project Management
CISSP
JAVA
Powershell
Security Development and Operations (SecDevOps)
Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, Xacta
Cloud security controls and implementation
STIG compliance and vulnerability management
CISSP
AWS Certified Security Specialty
Microsoft Office365
Experience in one or more software products associated with cyber system engineering for data analytics including SQL security, TANIUM Endpoint Management Software, Powershell, Splunk.
Experience reviewing vulnerabilities and associated risk findings using tools such as Trellix and RunZero, and supporting overall vulnerability management activities
Experience viewing C2S Console.
Cloud security controls and implementation
Or other relevent vendor professional certifications, current within the last 3 to 5 years.
What you can expect from us
BCore is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, sexual orientation or any other characteristic protected by law.
How much does a security architect earn in Hagerstown, MD?
The average security architect in Hagerstown, MD earns between $89,000 and $188,000 annually. This compares to the national average security architect range of $92,000 to $179,000.
Average security architect salary in Hagerstown, MD