Information Systems Security/Cybersecurity Engineer
AUSGAR Technologies IncAbout the role
Description
JOB TYPE: FULL-TIME
COMPETITIVE SALARY, COMPREHENSIVE BENEFITS AND A COMPANY THAT CARES!
Relocation May Be Considered
AUSGAR Technologies, Inc., an EOE Minorities/Females/Disabled/Veterans employer, is an established Service-Disabled Veteran-Owned Small Business (SDVOSB) Department of Defense, government contractor with core competencies in Information Assurance, Cyber Security and Systems Engineering. With offices on both the East and West coasts, an inviting culture and above-standard benefits, opportunity abounds for the right individual!
Information Systems Security/Cybersecurity Engineer (ISSE) – 24-020– San Diego, California
AUSGAR Technologies has an exciting opportunity for an Information Systems Security/Cybersecurity Engineer (ISSE) to join our team of smart and innovative technical team members working in the Point Loma area of San Diego, California.
Support the execution of Risk Management Framework (RMF) in support of an Authority to Operate (ATO) for a Navy Science (CSI) system. Responsible for creating and updating RMF packages in accordance with NAVINTEL and NSA requirements. Work with the program to develop RMF artifacts to include system diagrams, hardware/software lists, ports and protocol lists and develop policy documents as required and document the system’s NIST 800-53 Security Control Implementation utilizing the XACTA tool. In addition, conduct cybersecurity testing to include conducting ACAS scans, DISA Security Technical Implementation Guides (STIGs)/Security Requirements Guide (SRG) testing and other automated tools as required.
The day-to-day tasking involves the following activities:
- Develop and maintain an RMF Assessment and Authorization (A&A) package IAW NIST 800-37 Risk Management Framework (RMF) requirements using the XACTA tool and ensure the RMF package meets NAVINTEL/NSA requirements.
- Participate in system design reviews during the development cycle to ensure NIST 800-53 security controls and applicable DISA STIGs/SRGs are incorporated and implemented during system hardware and software development.
- Evaluate the system to ensure it meets Intelligence Community Directive (ICD) 503, NIST 800-53 security controls, Committee on National Security System Instruction (CNSSI) 1253 and other NAVINTEL requirements.
- Develop policy and procedures detailing the secure employment and authorized use of the system (e.g., Access Control Policy, Media Control Policy and Vulnerability Management Policy).
- Conduct vulnerability and ACAS scans every 90 days to identify vulnerabilities and provide recommended remediations.
- Support program system administrators as needed, for software patch installation and antivirus updates.
- Conduct RMF Continuous Monitoring (CONMON) requirements as required.
Requirements
The physical demands and work environment described here are representative of those that must be met by an employee to successfully perform the essential functions of the job. Reasonable accommodation may be made for individuals with disabilities to perform the essential functions.
- Must have a current TS/SCI clearance upon hire.
- Must have a DoD 8140 IAM Level I cert upon hire. A DoD 8140 IAM Level II or higher cert is preferred.
- BS in Cybersecurity, Computer Science or Information Assurance or related field from an accredited college/university and 5+ years of applicable experience with cybersecurity and two years plus applicable experience as an ISSE, ISSO or ISSM.
- Experience with ACAS/Nessus scanner and DISA STIGs.
- Experience with XACTA or eMASS.
- Experience with the DoD RMF Assessment and Authorization (A&A) process and activities.
- Knowledge of Intelligence Community Directive (ICD) 503, Director of Central Intelligence Directive (DCID) 6/3, Security Technical Implementation Guides (STIGs), Risk Management Framework (RMF) process and associated National Institute of Standards and Technology (NIST) publications.
- Prefer experience working with NAVINTEL or NSA on RMF processes and procedures.
- Prefer experience with HBSS/ESS/Trellix epolicy Orchestrator (ePO).
- Prefer previous experience as an IT or system administrator.
- Travel: Up to 10%.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s