SIGN IN
Cyber Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Bering Straits Native Corporation (BSNC) · 1 day ago

Cyber Security Engineer

Bering Straits Native Corporation (BSNC) is seeking a Cyber Security Engineer to join their team. The role involves ensuring system security measures comply with government policies, monitoring security controls, and providing guidance on cybersecurity regulations while collaborating with various stakeholders.
FinanceConsultingProperty & Casualty InsuranceFinancial ServicesInsurance
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Identify efforts of development and cyber security teams to build and maintain VITL-BMA applications
Collaborate with the Office of Naval Research (ONR) to implement and sustain VITL-BMA efforts
Monitor security controls as they are incorporated into the VITL-BMA application/programs
Ensure system security measures comply with applicable government policies
Provide configuration management and accurately assess the impact of modifications and vulnerabilities for each system
Provide advice and guidance to technical team and client regarding adherence to Federal and DoD Cybersecurity regulations and policies including the Risk Management Framework (RMF) as well as document implementation in Security Controls Tractability Matrix (SCTM)
Conduct policy reviews and technical inspections to identify and mitigate potential security weaknesses and ensure that all security features applied to a system are implemented and functional
Research, configure, analyze and/or use software applications for security vulnerability monitoring, security automation and alerting
Identify policy conflicts and recommend possible mitigations or solutions
Maintain awareness of upcoming customer / government driven changes and challenges and suggests approaches to meet those challenges
Regulatory Compliance: Stay up-to-date with relevant cybersecurity frameworks, regulatory standards (FISMA, NIST, etc.), and security best practices. Ensure that security posture aligns with current government and industry compliance requirements
Incident Response and Reporting: Report cyber incidents to the ISSM/ISSO and participate in incident response activities and investigations, supporting the Incident Response Team lead as required
Training and Awareness: Provide guidance and support to system owners and other stakeholders on RMF processes, system security requirements, and risk management practices
Documentation and Reporting: Develop and maintain comprehensive documentation including System Security Plans (SSPs), Risk Assessment Reports (RAR), and POA&Ms (Plans of Action and Milestones). Provide detailed risk assessments, audit reports, and authorization packages to senior leadership. Use MCCAST as the official Marine Corps Governance, Risk Management, and Compliance (GRC) tool to build and maintain system packages and authorizations

Qualification

Cybersecurity frameworksRisk Management Framework (RMF)Security vulnerability monitoringIncident responseSailPoint IdentityIQCyberArk PASRadiant LogicPingIdentityAgile Development methodologyPERSEC experienceCOMSEC experienceFortifySonarQubeJiraConfluenceCommunication skillsTime management

Required

Bachelor's Degree Computer Science or Information Technology or relevant work experience
5+ years' experience in government cyber security, preferably with RMF and ATO
Must qualify for DoD Directive 8140.01's (722)
Must be a US Citizen
Security Test Plan Knowledge
Gather, analyze Security Test Results (STIG checks, scans, manual tests)
Advocate for appropriate IA design decisions for N-Tier architectures
Ability to evaluate, build and implement policies and security processes as well as suggest solutions, compromises and improvements
Excellent time management skills
Excellent communications skills (written & oral)
Expert ability to summarize complex information and communicate at appropriate levels
Experience in PERSEC, COMSEC and/or program security roles

Preferred

Experience in the following tools highly preferred: SailPoint IdentityIQ, CyberArk PAS, Radiant Logic, PingIdentity
Experience using any, or all, of the following tools (Preferred): Fortify, SonarQube, Jira, Confluence
Working knowledge of the Agile Development methodology (Preferred)

Company

Bering Straits Native Corporation (BSNC)

twittertwitter
company-logo
Bering Straits Native Corporation is an investment management company that offers resource development and business opportunities.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Greg Schmidt
Senior COOP Administrator
linkedin
leader-logo
Malorie Lomer
Sr. Human Resources Business Partner
linkedin
Company data provided by crunchbase