Overview: CDT is currently seeking a skilled Information System Security Engineer to execute the implementation of security standards to a diverse set of systems for Lexington, KY. An advanced understanding of engineering principles and Security Technical Implementation Guides (DoD) is required. A working understanding of the Radio Frequency spectrum is desired.
Clearance Requirements: An active Top Secret with SCI eligible clearance is required. All candidates must be U.S. Citizens. Applicants who do not meet these requirements will not be considered.
Responsibilities:
Applies knowledge and understanding of Information Assurance (IA) concepts, practices, and procedures using established DoD security policies and standards to mitigate RMF security risks.
Support the establishment of end-to-end Cyber Security processes and procedures to streamline AO/DAO approvals and to establish IT security standards in accordance with current DOD and IC policy guidance
Identify and mapping NIST 800-53 controls, DISA Control Correlation Identifiers (CCI), and Security Requirements Guides (SRGs) families to appropriately tailor controls to submit new systems and capabilities for review by Authorizing Officials (AO)
Ability to implement/engineer security safeguards (e.g. STIGs) on enterprise and embedded systems to a variety of hardware platforms
Implement security monitoring solutions as required to meet IA requirements for Risk Management Framework (RMF) as applies to systems and sensors allocated to regions/AORs as outlined by end customer & users.
Guide projects and programs through successful assessment and authorization of systems components for Authority to Operate (ATO)
Perform system hardening utilizing STIGs
Focuses on threats, vulnerabilities, and the security of programs, systems, and devices.
Provides special consideration for intrusion detection, identifying and mitigating vulnerabilities, and ensuring that remote access points are secure
Create security test cases and assist in the performance general security testing
Technical Areas of Expertise:
Experience with RMF process and requirements
Heavy Security Technical Implementation Guide (STIG) experience
Experience with Vulnerability Management (Nessus, NexPose, OpenVAS, etc)
ELINT, Radio Frequency, Electronic Warfare, and/or SIGINT experience a plus
Translating technical customer requirements into business process and tasking
Technical consulting both buyer and end user customer personnel in a complex environment
Required Qualifications:
7 + years of experience in RMF
7+ years of experience as a Cyber Security Engineer
Cyber Security Certifications desired (CISSP, CISM, CISA, CompTIA Security+, CEH etc.)
Desired Qualifications:
Experience using tactical sensors and technologies within the United States Special Operations Command (SOCOM) and special operations community
Bachelor's Degree in Computer Science or a related technical discipline preferred, or the equivalent combination of education, professional training or work experience
CDT is committed to diversity and inclusion. We are proud to be an Equal Opportunity Employer, making decisions without regard to age, race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, veteran status, disability, or any other protected class under federal, state, or local laws.