Sr. Systems Security Engineer
EffectualAbout the role
Position Summary
Effectual Systems Security Engineer, Senior are members of the Public Sector Program Management team responsible for ensuring that customer-facing projects are delivered with customer satisfaction. Effectual Systems Security Engineer, Senior are “Brand Ambassadors” and are expected to stay current on leading practices to deliver high-quality, well-conceived solutions to customers.
A Glimpse into the Daily Routine of a Senior Security Engineer
Lead and perform Information Technology Security Services including Security Assessment and Authorization (SA&A), Vulnerability Management, Diagnostics and Mitigation, and Project Management initiatives. Collaborate with teams, external agencies, internal customer teams to maintain a compliant security posture. Provide expert guidance on security and compliance considerations specific to the agency. Respond to security incidents, handle forensics, and enforce compliance with security policies. Collaborate with teams, troubleshoot security issues, and document all activities and findings. Report to higher-ups and maintain a proactive stance to promptly address any unforeseen incidents. Stay updated on emerging security and industry best practices.
Responsibilities
- Works with the ISSO to respond to agency’s Information Security data calls, inquiries, and surveys. Provide proactive communications to agency IT Management or Information Security Program regarding status, issues, or questions
- Participate in and provide notes (if needed) regarding agency OCIO and Security meetings, workgroups, or training events as applicable
- Collaborate with the agency ISSO to provide progress and update reports (weekly, monthly, data calls) includes managing all activities performed or lead by the contractor
- Experience working in IT operations, system administration, applications development, change, and configuration management including asset tracking, backup technologies, and other maintenance procedures
Security Assessment and Authorization (SA&A) Specific Responsibilities:
- Has strong analytical, task management, time management, and communication skills necessary for handling SA&A initiatives, tasks and deadlines affecting the agency environment. Analyze, correlate, and present agency SA&A data from the agency SA&A tools
- Use and build upon existing agency ATO data stored in the agency specific tool to accommodate evolution observing the latest guidance provided by NIST and the agency’s Information Security Program
- Work with the agency’s ISSO to perform and help accomplish scheduled SA&A activities or the development of associated documentation
- Work, collaborates, supports, and assists other agency staff (internal system owners, developers, administrators, and engineers) or external contractor staff (contractor-hosted systems) with the development of their SA&A package documentation and review and revise said documentation for accuracy and quality. Conducting interviews, site walk-throughs, and assessment of security. Documentation activities include - updates to system operation manuals, updates to system inventory lists, evaluation of system status using the agency’s vulnerability management tools, updates to SOPs, creation of forms to support SOPs, and other varied documentation
- Ensure all packages are uploaded to the agency system within the deadlines and timeframes set by the agency. Work and collaborate with the agency’s Information Security Program as they review the agency SA&A packages. Work with the agency staff or external contractor staff to revise documentation,
- Review monthly vulnerability reports provided by external contractor staff for the agency contractor-hosted systems. Work with the contractor staff by monitoring the remediation of critical, high, and medium findings within the agreed-upon timeframe
- Technical writing skills experience writing Contingency Plans, Security Plans, Privacy Impact Assessments, Security Test and Evaluation/Security Control Assessment Plans and report, POA&Ms and analysis and preparation of implementation strategies for new initiatives as introduced by the agency’s Information Security Program
Vulnerability Management Specific Responsibilities:
- Have strong analytical, task management, time management, and communication skills necessary for handling Vulnerability Management initiatives, tasks and deadlines affecting the agency’s environment. Analyze, correlate, and present agency vulnerability data from a variety of agency-hosted tools including the analysis of multilevel security risks and problems and compensating controls to the agency’s IT management and staff
- Work and collaborate with developers, engineers, administrators, and Service Desk technicians
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s