System Analyst/Server Security (Windows)
Integrated Computer Solutions is currently seeking a System Analyst/Server Security
in Montgomery, AL. This position will also serve in an Information Assurance role.
Primary Responsibilities:
· Ensuring the security over 250 Windows servers managed both locally and remotely by SMC Montgomery
· Identify security vulnerabilities; mitigate vulnerabilities by implementing security policies and procedures approved by the Information Assurance Manager; ensure recommendations from the Security Technical Implementation Guide (STIG)are implemented to ensure data and system integrity
· Ensure all new servers are STIG compliant; identify and resolve all Cat 1 and 2 vulnerabilities; coordinate Retina scan between Security Office and System Administrators; recommend IA Approval
· Ensure all DISA servers and workstations are identified in the Vulnerability Management System (VMS); utilize VMS to track, monitor, and control the mitigation of security vulnerabilities, apply IAVA recommendations, acknowledge and close vulnerabilities, and develop Plan of Actions and Milestones(POAM) based on customer requirements and effect of applying fix to applications
· Identified key issues with the recent VMS migration, ensuring Security Office elevated to the VMS Program Manager; then worked to ensure that VMS Program Manager's corrective actions were implemented across the board for the Unix environment, first on SIPRnet and then on NIPRnet
· Experienced in INFOSEC with applying National Security Agency Security Technical Inspection Guide(STIG) and DOD Vulnerability Management System (VMS) countermeasures. Performed DISA Windows/Web STIGs and VMS countermeasures on multiple AF and DOD. Used VMS to view findings identified by FSO during inspections and marked as fixed once resolved.
· Experienced with applying DISA Web STIG to IIS and Apache using config files such as httpd.conf.
· Responsible for correctly updating over 250 GCSS-AF servers in VMS within a 3 week period, ensuring over 105,000 VMS findings were addressed and document with proper POAMs.
· Routinely perform Security Readiness Reviews (SRRs) by executing self-healing scripts weekly, ensuring all security vulnerabilities are identified and corrected, and deviations are documented
· Extensive detailed knowledge in DOD Vulnerability Management System (VMS) and implementing proper corrective actions without affecting the operability of servers and applications.
· Assist Program Office personnel to ensure servers meet local SMC Montgomery policies, CSD policies, as well as higher DoD security requirements.
Company Benefits and Compensation Package:
ICS offers a very competitive compensation and benefit package. Health and
Dental, Life Insurance, Holidays, Vacation and Sick Leave, Long Term Disability and
a progressive retirement plan. Other insurance packages are available through
ndependent carriers at a Company sponsored rate. ICS is an equal
opportunity employer.
Integrated computer Solutions Inc.