Information Systems Security Engineer Expert (TS/SCI with Poly Required) at GCI
GCI · Chantilly, United States Of America · Onsite
- Senior
- Office in Chantilly
GCI embodies excellence, integrity and professionalism. The employees supporting our customers deliver unique, high-value mission solutions while effectively leverage the technological expertise of our valued workforce to meet critical mission requirements in the areas of Data Analytics and Software Development, Engineering, Targeting and Analysis, Operations, Training, and Cyber Operations. We maximize opportunities for success by building and maintaining trusted and reliable partnerships with our customers and industry.
At GCI, we solve the hard problems. As an ISSE, a typical day will include the following duties:
This position is responsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration. The individual will work closely with other project managers and various software engineering, infrastructure, and technical operations teams to assess requirements, coordinate resources, and deliver information security updates for the customer. The ideal candidate will have experience performing industry-standard ISSE tasks, as well as experience in tailoring standard process lifecycles to function effectively in a small, fast-paced environment. S/he must have strong written and verbal individual and organizational communication skills and the ability to articulate technical project requirements to both customers and internal teams.
KEY RESPONSIBILITIES
- Develop and implement security designs for new or existing network system(s)
- Support the development, review, and maintenance of security documentation including System Security Plans (SSPs), POA&Ms, and Continuous Monitoring artifacts.
- Ensure system security controls are implemented, tested, and maintained in accordance with relevant customer directives.
- Attends customer meetings and serves as primary liaison to the customer ISSM
- Ensures system compliance with customer Assessment and Authorization (A&A) process
- Ensures system compliance with customer Certification and Accreditation policies
- Conducts system vulnerability scans
- Provides support to system patches and updates
- Provides assessments of the security impact of network changes
- Provides support to the management and control of system changes
- Implement and enforce information systems security policies ensuring system security requirements are addressed during all phases of the acquisition and system lifecycle
- Support the customer to resolve conflicting system security engineering requirements
- Develop and maintain processes and procedures to identify, track and mitigate customer system vulnerabilities
EDUCATION AND EXPERIENCE
Bachelor’s degree in a related business or technical discipline (Systems Security Engineering, Software Engineering, or Computer Science, etc.), and 10 years of experience or the equivalent combination of education, technical training, or work/military experience
REQUIRED QUALIFICATIONS
- Expert technical knowledge in security engineering and IT systems engineering
- Experience with testing methods, automated tools, plans, and procedures for verification of compliance and vulnerability requirements
- Demonstrated on-the-job knowledge experience with reviewing security concepts of operations, systems security plans, security control assessments, contingency plans, configuration management plans, incident response plans, vulnerability scanning, and/or vulnerability management plans
- Experience with modern networks, operating systems, databases, and virtual computing
- Experience conducting information system security control assessments (SCAs) and applying standard auditing techniques during systems security control assessments, including the proper interpretation of the control requirements, determining if the artifacts provided are sufficient and recommending remedial action to Government customer to ensure compliance
- Experience with using scanning applications
- Demonstrated on-the-job experience effectively communicating across programs and with customers, stakeholders, and other contractors
- Demonstrated on-the-job experience managing priorities across multiple projects (time management)
- Demonstrated ability to work independently and drive results with a small team
DESIRED QUALIFICATIONS
- Experience with modern networks, operating systems, databases, and multi-cloud environments
- Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP) CE, Certified Secure Software Lifecycle Professional (CSSLP), CISSP- Information System Security Engineering Professional (ISSEP), or CISSP- Information System Security Architecture Professional (ISSAP)
*A candidate must be a US Citizen and requires an active/current TS/SCI with Polygraph clearance.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Apply Now