ISSE jobs in United States
cer-icon
Apply on Employer Site
company-logo

Peraton · 1 day ago

ISSE

Peraton is a next-generation national security company that drives missions of consequence spanning the globe. They are seeking an Information Systems Security Engineer to support an Intel Community customer, focusing on conducting information system security engineering activities and ensuring compliance with security standards and regulations.

Information TechnologyRobotics
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Defines information security requirements and their integration into information systems and its technology component through purposeful security design
Develops and implements security designs ensure that the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM)
Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies
Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects
Develop, customize, and configure Splunk applications and dashboards
Develop Security Test Procedure (STP) , conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs
Conducting risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborating with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed
Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements
Validate control implementations provide enforcement of the required data access and network flow restrictions align with the continuous monitoring strategy
Participates in Agile Planning Events to provide technical input
Support government activities and report to appropriate IC and DoD authorities (i.e., USCYBERCOM, IC-SCC)
Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering
Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions
Apply system security engineering expertise in one or more of the following to: system security design process; engineering life cycle; information domain; cross domain solutions; commercial off-the-shelf and government off-the-shelf cryptography; identification; authentication; and authorization; system integration; risk management; intrusion detection; contingency planning; incident handling; configuration control; change management; auditing; certification and accreditation process; principles of IA (confidentiality, integrity, non-repudiation, availability, and access control); and security testing

Qualification

CISSP CertificationNIST Risk Management FrameworkSplunkDISA STIG ImplementationLinux/RedHatWindows ServerScripting LanguagesSecurity Content Automation ProtocolVulnerability RemediationContinuous IntegrationTask AutomationProblem Solving

Required

Bachelor's degree in a relevant technical (STEM) field with 8+ years of relevant experience; Master's degree in a relevant technical (STEM) field with 6+ years of relevant experience; or 4+ additional years of experience in lieu of a degree
TS/SCI with polygraph clearance adjudication or ability to obtain SCI and pass a poly
Certified Information Systems Security Professional (CISSP) Certification is required
One (1) year of experience with IC Community
Proven experience in scripting languages, Linux/RedHat, Windows Server and/or Networking Appliances
Proven experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
Proven experience performing Systems Security tasks including: Security Information and Event Monitoring (Splunk); Endpoint security (HBSS); Compliance and vulnerability scanning (ACAS / Nessus)
Demonstrated experience with creating and validating evidence for NIST security controls

Preferred

Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems
Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
Possess a working knowledge of administrating servers, system and application security threats and vulnerabilities
Experience extending existing applications in areas such as security, monitoring, task automation, continuous integration, deployment, and performance optimization
Demonstrate writing of your own project in scripting/programming (use of Shell scripting, Python, Javascript, Powershell) in a Linux or Windows environment to support the various Cyber Security tools and applications required
Provide guidance on vulnerability and malware remediation
Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future

Benefits

Heavily subsidized employee benefits coverage for you and your dependents
25 days of PTO accrued annually up to a generous PTO cap
Eligible to participate in an attractive bonus plan
Medical
Dental
Vision
Life
Health savings account
Short/long term disability
EAP
Parental leave
401(k)
Paid time off (PTO) for vacation
Company paid holidays

Company

Peraton Fearlessly solving the toughest national security challenges.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Thomas Terjesen
Chief Information Officer
linkedin
Company data provided by crunchbase