Your Impact:
Provide input into the automation of the RMF process.
Responsibilities:
The Senior Information Systems Security Engineer will perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.
· Validates and verifies system security requirements definitions and analysis and establishes system security designs.
· Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing, and enclave environments to include those with multiple enclaves and with differing data protection/classification requirements.
· Builds IA into systems deployed to operational environments.
· Assists Architects and Systems Developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
· Supports the building of security architectures.
· Enforce the design and implementation of trusted relations among external systems and architectures.
· Assesses and mitigates system security threats/risks throughout the program life cycle.
· Contributes to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations.
· Reviews certification and accreditation (C&A) documentation, providing feedback on completeness and compliance of its content.
Here’s what you’ll need :
· U.S. Citizen with a current TS/SCI w/Poly security clearance.
· Master’s Degree in Computer Science or IT Engineering is desired and may be substituted for 6 years’ experience
· 14 years’ experience with System Architect and Engineer (IASAE). Within the last 5 years: Defense-in-Depth principles and technology, including access/control, authorization, identification and authentication, Public Key Infrastructure (PKI), network and enterprise security architecture.
· 2 years’ experience applying security risks assessment methodology to system development, including threat model development, vulnerability assessments, and resulting security risk analysis.
· Knowledge of Federal, NSA, IC, and DOD Information Security regulations, publications, and policy. Experience with Cloud and Cross Domain Solutions (CDS)
· DOD 8570 IASAE Level III certification (CISSP-ISSAP or CISSP-ISSEP) Certification.
Jacobs is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, religion, creed, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, medical condition, marital or domestic partner status, sexual orientation, gender, gender identity, gender expression and transgender status, mental disability or physical disability, genetic information, military or veteran status, citizenship, low-income status or any other status or characteristic protected by applicable law. Learn more about your rights under Federal EEO laws and supplemental language.