We use essential cookies

Please Accept our Privacy Policy

Information Systems Security Engineer (ISSE)

DPG Solutions LLC

Job Description

Job Description

Required: An active TS/SCI with CI Polygraph

DoD 8570/8140 IAT level 2 or greater cybersecurity certification (i.e. Security+ , CISSP)

Information Systems Security Engineer (ISSE):

DPG Solutionshas an immediate career-growthopportunity for acollaborativeand highly skilled Information Systems Security Engineer.The ISSE will join our ISA program engineering team in Aurora, CO,supportinga high priority 24x7 operational system. The ISSE performs core activities to include providing certifiedservicesandsupportfor Information Assurance/Program Protection efforts for compliance with governing DoD Cybersecurity directives. This position willsupportactivities of the program to target, assess, and reportrisksandvulnerabilitiesof IntelligenceCommunity organizationsystems in order to provide seniordecisionmakers with actionable data to make strategic decisions. The ISSE shall perform, or review, technical security assessments of computingenvironmentsto identify points ofvulnerabilityand non-compliance with established Information Assurance (IA) standards, regulations and recommend mitigation strategies. This position isresponsiblefor the maintenance and administration of multiple domains, including a 24/7 operational system and a test environments. Must be willing to occasionally provide after­ hoursupportto the 24/7 operational system.

Duties andResponsibilities:


  • Implement Information Assurance (IA) processes, provide guidance, anddevelopdocumentation throughout the system development life-cycle via the RMF resource in ServiceNOW.

  • Develop, implement, and document formal security policies and System Security Plans (SSP) throughout the program and monitor compliance to these policies during all phases of theRiskManagementFramework (RMF) process.

  • UtilizeEnterpriseSecurityServicesto provide analysis ofvulnerabilitiesand compliancerisksin ACAS,EnterpriseIT audit logs in Splunk, and McAfee Host-Based SecurityServices(HBSS).

  • Monitor Heat Map Score matrix and evaluate cyberriskdata, keeping the score at acceptablerisklevels for the security categorization of the asset(s) and theirRiskEvaluation Lanes (REL).

  • Carefor and deliver system authorization and accreditation packages, for an asset that supports 24x7 operations across geographically separated data centers.

  • Review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.).

  • Assess/calculateriskbased on threats,vulnerabilities, and shortfalls uncovered in routine analyzation of Continuous Monitoring (ConMon) controls and provide those results as Body of Evidence (BoE) to be evaluated in 7, 30, 90 and 365 day increments as the control metrics require.

  • Direct activities desired to remediate system-level information security weaknesses tracked via the POA&M process. Document the elements of the plans, milestones for correcting the weaknesses, and scheduled completion dates for the milestones, periodically reporting remediation progress as necessary.

  • Brief guidance, asneeded, on the status of action items and/or results of activities affecting the security posture of the program.

  • Able tocollaborateand communicate effectively with other system engineers, system administrators, software developers, and information assurance professionals.

Qualifications:


  • Minimum of 4-6years' related experience in Cybersecurity, Systems or Software Engineering, for the government or government contractor, if other than IC position.

  • A Bachelor's Degree in Information Technology, Information Systems Security, Cybersecurity, or related field.

  • DoD 8570/8140 IAT level 2 or greater cybersecurity certification per DoD 8570/8140

  • Experience in security systems engineeringinvolvingLinux operation systems and applicationsolutionsin bothstand-alone and LAN/WAN configurations.

  • Must be a US Citizen with current/activeTS/SCI with polygraph.

RequiredSkills:


  • Experience developing Security Authorization Requirements, performingvulnerabilityassessments, and implementingthreatmitigation updates on embedded systems and products.

  • Experience configuring and hardening COTS/FOSS components with STIGs.

  • Continuous Monitoring and Network monitoring experience.

  • Experience with product development including architecture, requirements, design, integration and testing.

  • Experience with compliance implementation of security requirements (i.e.RiskManagementFramework and other A&A processes).

  • Experience participating in technical reviews with both external and internalcustomers.

  • Coordinate with ISSO/ISSM to update POA&M and reflect openvulnerabilitiesassociated with servers and workstations,developremediation plans to include milestone completion dates and status updates, and include mitigation process for closedvulnerabilities.

  • Participate in Configuration Control Board (CCB).

Desired Skills:


  • Experience implementing DISA Security Technical Implementation Guides (STIGs).

  • Experienceonboardingassets to centrally managedEnterprisesolutions.

  • Experience conductingriskanalysis on products and system components through review of CVEs, plugins, IAVAs.

  • Experience in conducting software duediligencewith COTS/GOTS and proprietarysolutions.

  • Positive, self-motivatedindividualwho can complete tasksindependently.

  • Experience with any form of containerization, Docker, Podman, or Kubernetes.

  • Experience working in Systems Engineering oncomplexembedded systems.

RequiredEducation (including Major):


  • Bachelor’s Degree in Engineering, or related Science, Technology, Engineering, Mathematics (STEM) degree program.

  • 8years’ experience in lieu of formal degree.

Location: Aurora, CO

Benefits at a glance:

Competitive Salary
Company Funded/Immediately vested 25% 401k Profit Sharing Plan
All Benefits and Premiums paid by company and with company HSA contribution
Quarterly Equity Share Bonuses
250 hours of Leave Annually
2 x Company Sponsored Annual Events for the employees and their families
Education Benefits
120k-145k$ base pay