Cybersecurity Engineer

SAICSt. Louis, MissouriOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

SAIC® is a premier Fortune 500® mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, civilian and intelligence markets includes secure high-end solutions in mission IT, enterprise IT, engineering services and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are seeking a highly motivated Information System Security Officer (ISSO) to conduct research and analysis for our NGA N2W customer. This role is responsible for advising on network and information system security principles and best practices, advise on applicable government IC and Agency IT policies, procedures and operation instructions for IT, Information Assurance, and Information Management (IT/IA/IM), and perform periodic security scanning as required by the Office of the Under Secretary of Defense (OUSD).

Responsibilities will include the following:

- Operate within cleared environments to perform Information Assurance specific activities for customer needs and timelines.
- Perform assessments of systems and networks within the networking environment or enclave and identify where those systems or networks deviate from acceptable configurations, enclave policy, or applicable Agency policies and guidelines. Perform compliance audits (passive evaluation) and vulnerability assessments (active evaluation).
- Develop Risk Management Framework (RMF) process operating procedures, policies, and related documentation.
- Perform duties per NIST SP 900-137, Continuous Monitoring, and audit for anomalous or malicious user activity.
- Periodically review audits of all systems and monitor corrective actions to ensure closure of all action items.
- Manage media, including handling and control, labeling, virus-scanning solutions, and data transfers between classification domains via manual and automated processes.
- Create and enforce strict program control processes to ensure risk mitigation, system accreditation, and certification attainment support. Support will include process support, analysis support, coordination support, security certification test support, security documentation support, investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits.

Required Qualifications include:

- Active TS/SCI with Polygraph
- Meet requirements for DoD 8570 IAT Level 1 Professional Certification
- 9+ years of related overall professional experience

Desired Qualifications include:

- Meet requirements for or possess DoD 8570 IAT Level 2 Professional Certification.
- Demonstrated ability to conduct research and analysis for network and information system security principles and best practices.
- Knowledge of information security program management and project management principles and techniques.
- Familiarity with security violation mitigation measures and incident reporting actions.
- Proficiency in computer networking concepts and protocols and network security methodologies.
- Familiarity with host/network access control mechanisms. Knowledge of cybersecurity principles to manage risks tied to use, processing, storage, and transmission of data.