Quick Overview
Job Description
StraitSys Inc Regular PRIMARY FUNCTION The Security Engineer provides cybersecurity engineering and technical security support for enterprise application modernization efforts supporting the Executive Office for Immigration Review (EOIR). This individual is responsible for supporting the design, implementation, configuration, testing, and ongoing security of applications, systems, and supporting environments.
The Security Engineer works closely with project management, solution architects, developers, system administrators, testing personnel, and Government stakeholders to ensure security requirements are incorporated throughout the system development lifecycle. This individual supports the identification and remediation of security vulnerabilities, implementation of security controls, and development and maintenance of security documentation necessary to support Department of Justice (DOJ) and Federal cybersecurity requirements. This position is contingent upon contract award ESSENTIAL FUNCTIONS
- Support the design, implementation, configuration, and maintenance of security controls for applications, systems, and supporting environments.
- Collaborate with solution architects, developers, system administrators, and Government stakeholders to incorporate security requirements throughout the system development lifecycle.
- Review system designs, configurations, interfaces, and technical implementations to identify potential security risks and vulnerabilities.
- Support security assessments, vulnerability scanning, remediation activities, and validation of corrective actions.
- Identify, document, track, and assist with the remediation of security findings and vulnerabilities.
- Support implementation and maintenance of identity and access management, authentication, authorization, least privilege, and role-based access controls.
- Assist with security configuration and hardening of applications, cloud resources, databases, integrations, and supporting infrastructure.
- Support security testing throughout development, integration, testing, deployment, and ongoing operations.
- Collaborate with development and operations personnel to incorporate secure development and DevSecOps practices into application development and deployment processes.
- Support security monitoring and assist with the identification, analysis, response, and remediation of security incidents as required.
- Develop and maintain security-related technical documentation, procedures, configuration information, and supporting artifacts.
- Support the preparation and maintenance of documentation required for system security, authorization, assessment, and ongoing compliance activities.
- Monitor security risks and vulnerabilities and communicate potential impacts and recommended mitigation actions to technical and project leadership.
- Support compliance with applicable DOJ and Federal cybersecurity policies, standards, and requirements.
- Participate in technical reviews, security reviews, project meetings, and other activities necessary to support secure system implementation and operations.
SUPERVISORY RESPONSIBILITIES: No DESIRED KNOWLEDGE, SKILLS, & ABILITIES
- Experience supporting the Department of Justice (DOJ), EOIR, or other Federal civilian agencies.
- Experience providing cybersecurity engineering support for enterprise application modernization or digital transformation initiatives.
- Experience securing cloud-based, hybrid, and Microsoft technology environments.
- Knowledge of Federal cybersecurity requirements, security controls, risk management, and system authorization processes.
- Familiarity with the NIST Risk Management Framework (RMF) and NIST security controls.
- Experience with vulnerability assessment, security scanning, remediation, and security configuration management.
- Knowledge of identity and access management, authentication, authorization, least privilege, and role-based access controls.
- Familiarity with application security, database security, API and integration security, and secure software development practices.
- Familiarity with Microsoft Azure, Microsoft 365, and related enterprise technologies.
- Experience working within Agile software development and DevSecOps environments.
- Strong analytical, troubleshooting, and problem-solving skills.
- Ability to effectively communicate cybersecurity risks and technical information to technical and non-technical stakeholders.
QUALIFICATIONS
- Must be a US Citizen.
- Must be able to successfully obtain and maintain the appropriate Department of Justice (DOJ) Public Trust Investigation (PTI) as required for the position.
- Bachelor's degree from an accredited college or university and relevant professional experience in cybersecurity, information security, systems security engineering, information technology, computer science, or a related discipline.
- Ability to successfully pass a pre-employment drug test and background check.
Similar jobs
- BO
Cybersecurity Analyst - Product Security with Security Clearance
NewBoeing
Aurora, CO🇺🇸$124.1k - $167.9k/yrHybrid10 hours agoTechnology - ZP
Security Engineer - Tool Integration (Secret Clearance) - 172483 with Security Clearance
NewZachary Piper Solutions, LLC
Raleigh, NC🇺🇸$125k - $170k/yrOn-siteYesterdaySplunkPythonTechnology - DO
INFORMATION SECURITY SPECIALIST (Title 32) with Security Clearance
NewDepartment of the Air Force
Fort Smith, AR🇺🇸HybridYesterdayAdministrative - TA
IT Information Assurance Cyber with Security Clearance
NewTENICA and Associates LLC
Chantilly, VA🇺🇸HybridYesterdayPenetration TestingTechnology - IN
Digital Network Exploitation Analyst Level 2 with Security Clearance
NewIntelliGenesis
Annapolis Junction, MD🇺🇸$111k - $152k/yrHybridYesterdayPenetration TestingTechnology - AG
Cyber Data Analysis Engineer with Security Clearance
NewAbile Group, Inc.
Springfield, VA🇺🇸HybridYesterdayOpenStackAWSSplunk+6Technology