Information System Security Engineer III

Centuria Corporation
  • Philadelphia, PA
    30+ days ago

    Job Description

    Job Title: Information System Security Engineer (ISSE) III

    Location: Philadelphia, PA

    Clearance: Secret

    Company/ Program Description:

    Centuria, a Service-Disabled Veteran-Owned Small Business (SDVOSB), has been delivering IT, Engineering, and Scientific solutions to the Federal Government since 2002. During our two decades of service, we have earned the trust and respect of our government clients for the simple reason that we have great people who are experts in their fields and take pride and ownership in everything they do.

    Job Responsibilities:

    • Assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans, which include System Categorization Forms, Platform Information Technology (PIT) Determina Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagram Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
    • Execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO). Identify and tailor IT and Cyber Security (CS) control baselines based on RMF guidelines and categorization of the RMF boundary.
    • Perform Ports, Protocols, and Services Management (PPSM). Perform IT and CS vulnerability-level risk assessments.
    • Execute security control testing as required by a risk assessment or annual security review (ASR). Mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements. Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
    • Develop and maintain system level IT and CS policies and procedures for respective RMF boundaries in accordance with guidance provided by the command ISSMs. Implement and assess STIG and SRGs.
    • Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Ev STIG.
    • Deploy security updates to Information System components.
    • Perform routine audits of IT system hardware and software components. Maintain inventory of Information System components.
    • Participate in IT change control and configuration management processes.
    • Upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM). Image or re-image assets that are part of the assigned RMF boundary.
    • Install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries' assets.
    • Assist with removal of Solid-State Drive (SSD), Hard Disk Drive (HDD) or other critical components of assets before destruction and removal from the RMF boundary.
    • Provide cybersecurity patching of assets in response to DoD and DoN TASKORDs, FRAGORDs, or as required by Command ISSM, ACIO, and/or Code 104 management.
    • Support configuration change documentation and control processes and maintaining DOD STIG Compliance.
    • Support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware. This includes assessing vulnerabilities, patching and meeting requirements the STIG for the hardware.
    • Report compliance issues of network hardware to management to avoid operational loss of the network.

    Job Requirements:

    • Education: Bachelor's degree in computer science, information technology, or an equivalent STEM l degree from an accredited college or university.
    • Experience: Seven (7) years professional experience capturing and refining information security operational and security requirements and ensuring those requirements are properly addressed through purposeful development, and configuration, and implementing security controls, configuration changes, software/hardware updates/patches, vulnerability scanning, and securing configurations.
    • Minimum Certification Requirement: IAT-III (CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP)

    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    Numbers & Facts

    LocationPhiladelphia, PA

    Skills

    • Artificial Intelligence (AI)unmatched
    • Asset Managementunmatched
    • Auditingunmatched
    • Automationunmatched
    • CCNP - Cisco Certified Network Professionalunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Change Controlunmatched
    • Cisco Network Hardwareunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Configuration Managementunmatched
    • Customer Support/Serviceunmatched
    • Disability Accommodationsunmatched
    • Federal Governmentunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • Hard Drivesunmatched
    • Hardware Componentsunmatched
    • IAT - Information Assurance Technicalunmatched
    • Information Systems Security Engineering (ISSE)unmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Inventory Managementunmatched
    • Maintain Complianceunmatched
    • Microsoft Windows Serverunmatched
    • Network Administration/Managementunmatched
    • Network System Hardwareunmatched
    • Operations Security (OPSEC)unmatched
    • Privacy Impact Assessment (PIA)unmatched
    • Risk Analysisunmatched
    • Risk Management Framework (RMF)unmatched
    • Secret Clearanceunmatched
    • Security Analysisunmatched
    • Security Protocolsunmatched
    • Small Businessunmatched
    • Software Administrationunmatched
    • Software Installationunmatched
    • Software Patchesunmatched
    • Solid State Drive (SSD)unmatched
    • Support Documentationunmatched
    • Systems Hardwareunmatched
    • Systems Maintenanceunmatched
    • Testingunmatched
    • United States Department of Defense (DoD)unmatched
    • VRAMunmatched
    • Vulnerability Scannersunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder