
Cyber Security Software Integration Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Idaho.
• Assist in active cyber defense operations of the BMC3 AppFac within the DOD AWS CloudOne.
• Offer engineering analysis and security recommendations for both design implementation and operational execution.
• Conduct computer and network security vulnerability assessments to identify, evaluate, and mitigate risks, threats, and vulnerabilities using SD Element.
• Create the Authorization & Assessment (A&A) body of evidence to comply with DoD and Federal directives.
• Oversee security audit and intrusion detection logs for any system and network anomalies.
• Supervise technical access-control methods to ensure the integrity of systems and data.
• Successfully achieve CtFs or ATOs across multiple government clients with minimal oversight.
• Execute and manage continuous monitoring activities for designated systems.
• Collaborate with engineers to analyze software, interpret security requirements, and plan control implementations.
• Deliver exceptional customer service, policy expertise, and high-quality documentation.
• Act as the main in-person contact for U.S. Government clients regarding cybersecurity and compliance necessities.
• Perform network vulnerability scans, suggest remediation alternatives, and conduct security risk assessments.
• Translate high-level security requirements and policies into IT components and information systems through security design or configuration.
• Provide security consultation and engineering support to product owners, clients, system owners, and developers.
• Coordinate security processes within the Department’s lifecycle management and governance framework.
• Distinguish between technical and administrative cybersecurity and A&A requirements and formulate project plans and schedules.
• Analyze vulnerability scan results from ACAS (Tenable Nessus) and SCAP (STIG benchmark).
• Manage Plans of Action and Milestones (POA&Ms) for remediation findings.
• Assist clients in identifying security solutions for networks, VPNs, application systems, public key infrastructures, authentication, and directory services.
• A Bachelor’s degree with 5 or more years of experience, or a Master’s degree with 3 or more years of experience.
• Technical experience may be accepted in lieu of a degree.
• Familiarity with the DoD Risk Management Framework (RMF) lifecycle (Step 1–Step 6).
• Understanding of selecting and engineering security controls as per NIST SP.800-190.
• Proficiency in selecting and engineering National Security System security controls according to CNSSI 1253.
• Knowledge in assessing technical and administrative security control implementation in accordance with NIST.SP.800-190.
• Experience with the Enterprise Mission Assurance Support Service (eMASS).
• Capability to apply security controls to Unix variants, Microsoft operating systems, and Linux operating systems.
• Knowledge of networking, software development, scripting languages, software integration, or related expertise.
• Understanding of networking protocols and security technologies including encryption, IPsec, PKI, VPNs, firewalls, proxy services, DNS, and access-lists.
• Familiarity with DoD Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and industry best practices.
• Knowledge of Certificate to Field (CtF) policies.
• Must be a U.S. citizen.
• Must possess an active Secret clearance.
• Hold a DoD 8570 IAT Level II certification, such as Security+, or be able to obtain it within 60 days.
• Primarily remote work arrangement.
• Opportunity to mentor junior developers.
• Chance to leverage leadership capabilities.
• Exposure to advanced security and automation practices.
• Opportunity to collaborate with highly skilled engineers and architects.
Matrix Design Group, Inc.
n Human Resources & Management Systems [ nHRMS ]
Postmedia Solutions
General Dynamics Information Technology
Get handpicked remote jobs straight to your inbox weekly.