Senior Security Engineer (Compliance)

Versar, Inc.
Washington, DC, US
Full-time

Job Description

Job Description

Position Summary

Versar, Inc., is seeking a Senior Security Engineer (Compliance) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO).

This candidate will be a member of a high functioning team supporting cybersecurity countermeasures to strengthen DHS enterprise and HQ networks, to include the overseeing and providing strategic and tactical direction with security compliance.

This candidate will work directly with team of network and security engineers, data center specialists, ISSOs, industry vendors, and DHS stakeholder groups that includes 20+ DHS Components.

This effort is responsible for providing support for the following Homeland Security Enterprise Network (HSEN) services along with Security Engineering Compliance to include :

  • Design and development of cyber security technology along with integration of new architectural features into existing infrastructures while maintaining the integrity and security of enterprise-wide cyber systems and networks.
  • Responsibility for DHS Security ATO and RMF compliance support ensuring systems are documented, security control implementation / documentation, self-inspection (STIG / vulnerability / compliance) auditing and issue remediation.
  • Strong working relationship with ISSOs and technical teams to ensure NIST Compliance and RMF ATO Security Authorization.

Additional Duties / Responsibilities

  • Provide DHS Security Authorization Support
  • Assist and support the SOC Security Authorization Process following National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 including, but not limited to, the following elements :
  • Security Plan
  • Security Risk Assessment
  • Security Controls Assessment
  • Continuity of Operations Plan (COOP)
  • Development of POA&Ms
  • Provide assistance and support to the SOC System ISSO, to document that documents and maintains the SOC Security Authorization documentation in the Information Assurance Compliance System (IACS), conducts NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information Systems assessment, and tracks NOSC Cyber (SOC) POA&Ms.
  • Develop and document a comprehensive COOP which ensures that the Contractor maintains
  • Maintain appropriate NOSC Cyber infrastructure backups, and documents priorities and procedures for re-instantiating critical functions in the event of a failure.
  • Test the DHS NOSC Cyber COOP capabilities in conjunction with internal test procedures and the DHS Information Technology Disaster Recovery Plan.
  • Provide support to Government management by establishing POA&Ms and process for tracking the correction of internal self-assessment and external audit findings relating to security authorization of NOSC operations and activities.

Minimum Qualifications / Requirements

  • At least six (6) years of professional experience in an IT Services environment, providing technical support with emphasis on security compliance for federal networks.
  • Prior experience with NIST FIPS Standards, Contingency Plans, Network Infrastructures, Security Impact Analysis, Privacy Impact security Assessments & Analyses, Standard Operating Procedures.
  • U.S. Federal government consulting experience preferred.
  • Must be resourceful in learning a very complex and dynamically changing network
  • Must be able to work independently in fast paced, dynamic environment.
  • Past experience within the Department of Homeland Security or other government agency is preferred.
  • U.S. citizenship required and eligibility for a DHS EoD is required to be considered for this position.

Education

BS degree in Information Systems, Computer Engineering, Computer Science, or Cyber Security, or equivalent experience

Certifications Desired

Security Certifications : CISSP, CCSP, CISM, GSLC, CISA, CASP, or equivalent

Software / Hardware Desired

  • IBM AppScan, HP WebInspect, Nexpose, Splunk, Nessus, HP Fortify, McAfee SECURE, McAfee Virus Scan, Enterprise, ArcSight Sourcefire, Nagios, Saint, Solarwinds, Remedy, Primavera, Xacta, CSAM
  • 30+ days ago
Related jobs
Promoted
QinetiQ
Washington, District of Columbia

QinetiQ US’s dedicated experts in defense, aerospace, security, and related fields all work together to explore new ways of protecting the American Warfighter, Security Forces, and Allies. FRLE is looking for a Sr Technical Security and Signals Countermeasures (TSSC) Engineer to conduct all technica...

Promoted
VirtualVocations
Washington, District of Columbia

A company is looking for a Senior Engineer, NERC O&P Compliance. ...

Promoted
T-Rex Solutions
Washington, District of Columbia

T-Rex Solutions is looking to select a Senior Cloud Security Engineer to play a critical role in the management, enhancement, and security of our Department of Treasury TCloud environments. Apply security administration expertise to manage identity and access management (IAM), implement network secu...

Promoted
VirtualVocations
Washington, District of Columbia

A company is looking for a Senior Principal Security Engineer (Applied Cryptography and Authentication). ...

Promoted
Educology Solutions
Washington, District of Columbia

ESI is seeking a Senior Cloud Security Engineer to support work one of our customers. Certifications in the any of the following are strongly preferred : Certified Information Systems Security Professional (CISSP) • Certified Cloud Security Professional (CCSP) • Certified Information Secur...

Versar
Washington, District of Columbia

Senior Security Engineer (Compliance) to support the Department of Homeland Security’s Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO). This effort is responsible for providing support for the following Homeland Security Enterprise Network (HSEN) servi...

California Creative Solutions Inc.
Washington, District of Columbia

Work may encompass one or more specialty areas of cyber security, cyberspace, and cyber operations, including providing expert knowledge and insight into compliance, cyber hunt, incident response, risk and vulnerability assessment, and emerging cyber threats requirements; guiding technical support t...

ST2 ManTech Advanced Systems Intl
Washington, District of Columbia

Network Security Computer Systems Engineer. Develops and provides training to junior Network Security Computer Systems Engineers. The applicant will be required to answer certain questions for export control purposes, and that information will be reviewed by compliance personnel to ensure compliance...

CoStar Group
Washington, District of Columbia

Oversee and mentor other offensive security team members. Share knowledge with all members of the security team. Oversee all internal penetration testing efforts as both a player and a coach to other penetration testing engineers to cover penetration testing of all critical infrastructure (ie CI/CD ...

Mindlance
Washington, District of Columbia

DevOps and IT Security Engineer Standard III –. Monitor and ensure the performance, availability, and security of applications and infrastructure. Strong experience with security tool like SonarQube. Cloud network principle and security controls. ...