logo

JobNob

Your Career. Our Passion.

System Engineer VIRGINIA


2HB Incorporated


Location

Herndon, VA | United States


Job description

This is a full-time position, and MUST HAVE a TS/SCI/Full Scope Polygraph Clearance.

2HB Incorporated is seeking a Systems Engineer in order to support its government customer in Herndon, VA. 

The work requires a healthy mix of technical and policy knowledge. The US Government (USG) requires support in understanding and implementing standards like ICD 503 , NIST Risk Management Framework, and cloud technologies. The Sponsor needs polished skills in information system security engineering, and security control assessment. The work will be driven by the Sponsors needs and priorities.

Work requirementS The USG will direct priorities and delegate tasks.
  • The Candidate Team shall manage security assessment, security compliance, change management, and continuous monitoring activities across 5 cloud service providers (Amazon Web Services, Google Cloud, Oracle Cloud, Microsoft Azure, and IBM Cloud) through the Sponsor’s office.
  • The Candidate Team shall assess cloud security technologies for security gaps and weaknesses according to industry standards.
  • The Candidate Team shall analyze security scan findings and perform risk analysis on security scan findings.
  • The Candidate Team shall review cloud security body of evidence packages for completeness and accuracy.
  • The Candidate Team shall collaborate with other internal components and security peers to determine security and potential weaknesses of cloud infrastructure and cloud services.
  • The Candidate Team shall advise Sponsor leadership on cloud security services.
  • The Candidate Team shall analyze system alerts to determine if a security weakness exists and document risk mitigation procedures.
  • The Candidate Team shall sustain and evolve the Sponsor’s standard operating procedures to meet Program Objectives.
  • The Candidate Team shall facilitate technical exchange meetings (TEMs) with cloud service providers to review cloud service architectures.

required skills and demonstrated experience The Candidate Team shall have the following required skills, certifications, and demonstrated experience:
  • Demonstrated experience facilitating TEMs with cloud service providers to review cloud service architectures
  • Demonstrated experience maintaining assessment and authorization (A&A) packages across multiple services or systems in accordance with FIPS-199, NIST 800-53, and CNSS 1253 requirements.
  • Demonstrated experience designing, implementing, assessing or reviewing systems that utilize cloud technology with either Amazon Web Services, Oracle Cloud, Google Cloud, IBM Cloud, or Microsoft Azure cloud architecture.
  • Demonstrated experience utilizing or reviewing cross domain technology and common architecture designs.
  • Demonstrated experience consulting project teams on system architecture and security posture.
  • Demonstrated experience with continuous monitoring requirements to include scan analysis for critical or high findings with common scan tools such as Rapid 7, Nessus, and Qualys.
  • Demonstrated experience creating, monitoring, or closing system or service Plans Actions and Milestone items (POA&Ms).
  • Demonstrated experience utilizing compliance tools to track assessment and authorization activities such as Xacta 360, Risk Vision, RSA Archer.
  • Demonstrated experience with the common control provider concept within the NIST Risk Management Framework.
  • Demonstrated experience with security control assessments to include working with SCAs and preparing security packages for SCAs.
  • Demonstrated experience conducting information system security engineering activities.

Highly Desired skills and demonstrated experience Skills and demonstrated experiences that are highly desired but not required to perform the work include:
  • Demonstrated experience using the Sponsors or IC element A&A process.
  • Demonstrated experience creating or reviewing A&A body of evidence documentation in a cloud security environment.
  • Demonstrated experience identifying, implementing, or reviewing appropriate information security controls.
  • Demonstrated experience working in Xacta 360.

This is a full-time position, and MUST HAVE a TS/SCI/Full Scope Polygraph Clearance.


Job tags

Full time


Salary

All rights reserved