Cybersecurity Engineer

US-VA-McLean

External

Req #: 6536
Type: Full-Time
logo

Steampunk

Connect With Us:
Connect To Our Company
				Overview:

As a Cybersecurity Engineer, you will provide technical expertise and solutions to remediate persistent and challenging portfolio-wide vulnerabilities.  We're looking for someone who has passion for IT, resourceful problem-solving abilities, and a desire to learn our indicators of success in this role.  The ideal candidate will have a breadth of experience over a variety of technologies that are typically used to build and run enterprise applications.  The candidate will not necessarily have deep experience in all domain areas but should have a good understanding of how the various layers of an enterprise application stack interact with one another.  You will work directly with system admin teams to assist and remediate vulnerabilities and harden environments, while providing recommendations on ways to enhance vulnerability management. Additionally, you will work in a team environment to develop proactive solutions to improve overall enterprise security posture through process streamlining and automation. 

Responsibilities:

Responsibilities include:

* Provide subject matter expertise in various risk assessments, working in an Agile environment with an understanding of the full software development lifecycle.
* Advocate for and ensure appropriate security practices are communicated and implemented within application development portfolios.
* Ability and proven experience in implementing, configuring, and securing multiple areas of an enterprise application stack, including the OS, Database, Application Server, Load Balancer, and Web Server layers.  Understanding how PKI/TLS certificates work is a must.
* Integrate with both the application development and security assurance divisions to ensure vulnerability findings are understood, remediated or baselined as appropriate
* Document security findings and remediations in an enterprise knowledge base
* Support Information System Security Officers (ISSO) with activities such as security scan analysis and partner with development teams to facilitate a common understanding of security findings and applicability.

Qualifications:

Required:

* Ability to obtain a U.S. government Security Clearance
* Master's Degree and 3 years of relevant experience; OR
* Bachelor's Degree and 5 years of relevant experience; OR
* No degree and 9 years of relevant experience

* Possesses at least one professional certification relevant to the technical service provided. Maintain a certification relevant to the product being deployed and/or maintained.

Preferred:

* Former Developer or Systems Administrator experience
* Working knowledge of technologies used for building and deploying enterprise applications, such as, Maven, Grade, GIT, Jenkins, Ansible, Java, C#/.NET, Apache Tomcat, Apache HTTP Server, IIS, F5, Oracle,  MSSQLSEVER, PostGres
* Working knowledge and experience in AWS and Azure GovClouds
* Ability to analyze DISA STIG audit compliance scan results and provide recommendations for resolution
* Analyze security environment, provide recommendations
* Working knowledge of JIRA, Service Now or equivalent
* Working knowledge of operating system and dynamic application security testing scan tools - Tenable and MicroFocus WebInspect
* Experience using Python to automate tasks

Certifications:

* AWS or Microsoft Cloud certifications
* Certified Information Systems Security Professional (CISSP)
* Other Cybersecurity technology specific certifications
			
Share this job: