This position is located in our VA, Chantilly facility
Vulnerability Assessment/Security Engineers act as an integral part of the certification and accreditation process. Support the security requirements definition of new, upgraded, and reconfigured ISs. Provide applicable security engineering input to development project documentation, requirements reviews, and design reviews and testing of the systems in the field. Provide security engineering advice and guidance to the ISSO in support of the Program Manager/s. Maintain a working knowledge of system functions, security policies, technical security safeguards, and operational security measures. Develop and maintain a formal Information Systems Security Program. Test and enforce IS security policies. Scanning is completed using accepted scanning tools (software and hardware) used either remotely or locally on the systems to ensure compliance and to identify security holes, risks, threats and gaps. Write reports as a result of scanning that identifies security issues on the system that is helpful to the Information System Security Representative (ISSR), System Administrator (SA) and PM for remediation and informational purposes.
Review System Security Plans (SSPs) (described in DCID 6/3 Appendix C), test the documented systems and endorse those found to be acceptable. Establish testing requirements, coordinate and conduct formal certification testing.
Perform vulnerability assessments, determine residual security risks, prepare certification test finding reports, and provide formal accreditation recommendations.
This position requires an active TS/SCI security clearance.
Requires BS in Computer Science or a related science degree.
- Minimum of 5 years experience in computer science or software engineering
- Minimum of 5 years experience in information security fundamental/principles
- Minimum of 3 years technical experience in client/server
- Experience with Penetration Testing and Analysis
- In-depth knowledge of DCID 6/3 and other applicable policies governing accreditation of IS operating in Protection Levels 1, 2, 3, 4 and 5.
- Experience with developing and writing security policy and procedures
- Must have strong written and verbal skills
- Must be able to work well with team members, with other contractors, and independently
Submit Your Resume Online Now