Jobs and Careers
AU

Cybersecurity Engineer 3

Auria
Colorado Springs, United Statesfull_timeVerifiedPosted 19 Jul 2024
💰 $110,000/yr($99,000/yr$110,000/yr)

About the role

 

Auria is looking to hire a Cybersecurity Engineer 3 to join our Command and Control, Battle Management, and Communications (C2BMC) program.  This position will be based in Colorado Springs, CO.

This position will assess systems and networks within a virtual environment and identify where those systems deviate from acceptable configurations, enclaves, or local policies. This is achieved through passive evaluations, such as compliance audits using STIG Viewer, SCAP, etc., and active evaluations, such as vulnerability assessments utilizing ACAS. Perform Security Technical Implementation Guide (STIG) assessments and hardening for both Windows, Red Hat Enterprise Linux (RHEL) systems, and networking equipment utilizing ConfigOS.  Establish strict program control processes to ensure risk mitigation and support obtaining system assessment and authorization. Includes support of process, analysis, coordination, control certification test, compliance documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.

Essential Functions:

  • Process and track DD Form 2875 user account forms and required training for privileged and non-privileged accounts, validate annual accounts, and work with the system administrator to create, modify, and remove accounts.
  • Develop test plans reflecting how STIG checks are implemented and be able to show the expected outcomes of those checks.
  • Update the Risk Management Framework (RMF) artifact documentation to ensure non-compliant system hardening is tracked and remediated.
  • Assist in implementing the required government policy (i.e., NISPOM, NIST, DoD), making recommendations on process tailoring, and participating in and documenting process activities.
  • Perform analyses to validate established cybersecurity controls and requirements and to recommend cybersecurity safeguards.
  • Support program test milestones through pre-test preparations, participation in the tests, analysis of the results, and preparation of required artifacts supporting authorization.
  • Prepare artifacts such as Test Results (TR), Authorization Boundary Diagrams (ABD), Network Topologies, Flow-diagrams, Hardware and Software listings, Ports, Protocols, and Services Management documentation, supporting Assessment and Authorization activities and maintain the Plan of Actions and Milestones (POA&M).
  • Periodically review each program support and operational system's audits and monitor corrective actions until all actions are closed.
  • Coordinate across the program to address identified deficiencies during RMF assessment activities.

Basic Qualifications:

Please note your updated security clearance and IAT/relevant certifications on your resume, if applicable.

  • An active Top-Secret clearance is required to start.
  • 5 years with a Bachelor’s degree in a related field; 9 years experience in lieu of a degree.
  • Must possess a DoD 8140 certification at IAT Level II / IAM Level I or higher (Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA)
  • Must have working experience with Security Technical Implementation Guide (STIG) and SCAP.
  • Must possess security engineering skills and a working knowledge of cybersecurity technology and DoD/federal cybersecurity policy (i.e., DoDI 8500.01, NIST SP 800-53, etc.).
  • Must understand and utilize Enterprise Mission Assurance Support Service (eMASS).
  • Must possess an understanding of the Risk Management Framework (RMF) Cybersecurity Lifecycle to include identifying controls and overlays, generating testable requirements, identifying resilient architecture design, configuring, running, and scripting audit tools, providing analysis of vulnerability analyses, conducting verification testing for compliance assessment.
  • Must know Software Assurance (SwA) static and dynamic code analysis (e.g. Fortify/SonarQube).

Preferred Qualifications:

  • Windows and Red Hat Enterprise Linux (RHEL) systems administration skills are highly desired.
  • Previous background working in a virtual environment is preferred.
  • Background working with dockers and containers is highly desired.
  • Administering ACAS and ESS (formally HBSS) is highly desired.
  • Previous experience with ConfigOS is highly desired.

Salary Range: The salary offered will be based on the selected candidate’s qualifications - skills, education & experience - and the position level ($99,000 - $110,000).

About Auria

Auria is a provider of solutions and software in support of complex Space, National Security, and Cyber missions of federal, international, and commercial customers. Headquartered

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Auria

View company profile →