What are the responsibilities and job description for the Cyber Security Engineer position at Byte Systems LLC?
Candidate MUST possess a TS/SCI clearance with Intel Polygraph
Overview:
The Sponsor requires subject matter expertise in technical risk analysis of enterprise and mission systems
Cyber Security EngineerThe Sponsor supports a diverse set of corporate goals across the organization by conducting technical risk assessments and providing technical risk mitigation guidance on the use of various enabling technologies. The Sponsor requires subject matter expertise in technical risk analysis of enterprise and mission systems, IT systems and networks, mobile and wireless networks, cloud-based computing, network management platforms, communication protocols, scripting or programming products, configuration scripts, and IT hardware and software products in support of Sponsor s technical risk assessment activities. The Cyber Security Engineer will perform technical risk assessments and provide technical risk mitigation guidance on the use of various enabling technologies and gather Body of Evidence (BOE) and assess artifacts, such as CONOPS, use cases, detailed network diagrams, technical design details, procurement methods, and System Security Plan (SSP) to get a holistic view of the interworking parts of a given technology implementation being evaluated, from which real insights can be derived to inform risk assessor s judgement. They will apply consistent and systematic investigative practices to comprehensively assess risks, identify and characterize threats and vulnerabilities; evaluate system or network operations using network management platforms, network scanning tools, auditing functions, PCAP captures, and log reviews; and analyze system, network, or cloud configurations for mis-configured settings, configurations not required for deployment, removal of test scripts to minimize the configuration to fulfill the specific deployment. The Cyber Security Engineer will analyze hardware and software used in a system or network for origin of manufacturer, known vulnerabilities, outdated hardware or software; remain current with existing and future technologies to assist the Sponsor with identifying associated risks of implementing proposed technologies; and provide guidance of potential cyber threats, attacks, and exploitations and advise decision-makers of the inherent risks and mitigation to the Sponsor s equities. They will also ensure appropriate risk mitigation considerations are baked in early in the development cycle, and risks and vulnerabilities are well understood and appropriately mitigated; organize and schedule work to effectively manage a case load; and track, document, and communicate progress status updates and weekly status updates on all technical risk assessment reports, cases describing potential security concerns and mitigations to enhance security posture.
1. (Mandatory) Demonstrated experience analyzing IT systems for cyber security vulnerabilities.
2. (Mandatory) Demonstrated experience developing IT system or network architecture design, conducting IP data flow analysis, encryption configuration, and vulnerability analysis using both open-source and commercial tools, such as Nmap, Wireshark, Metasploit, Canvas, Kismet, or BackTrack.
3. (Mandatory) Demonstrated experience analyzing IT network configurations of devices such as firewalls, routers, switches, VPNs, or Intrusion Detection/Prevention Systems for cyber security vulnerabilities.
4. (Mandatory) Demonstrated experience with communications protocols such as IP, TCP, UDP, HTTP, HTTPS, MPLS, OSPF, IGRP, BGP, SIP, H.232.
5. (Mandatory) Demonstrated experience with multiple OS s, including Windows, Linux, and OSX.
6. (Mandatory) Demonstrated experience with Microsoft Windows ver.; 7, 8, 10, 2008R2, 2012, 2012R2, or 2016.
7. (Mandatory) Demonstrated experience with cloud computing technology and hypervisors such as HyperV, VMWare ESX, or Virtual Box.
8. (Mandatory) Demonstrated experience with transitioning security domains and use of cross domain appliances.
9. (Mandatory) Demonstrated experience with network management systems, network storage, backup systems, and disaster recovery (DR) architectures.
10. (Mandatory) Demonstrated experience performing technical risk assessments and providing technical risk mitigation guidance.
11. (Mandatory) Demonstrated experience ensuring appropriate risk mitigation considerations, risks and vulnerabilities are well understood and appropriately mitigated.
12. (Mandatory) Demonstrated experience analyzing procurement processes of hardware, software and services to comply with cyber security and operational needs.
13. (Mandatory) Demonstrated experience creating concise and well-structured written assessments.
14. (Desired) Demonstrated experience with the Sponsor s IT review boards.
15. (Desired) Demonstrated experience with providing recommendations to IT architecture and design reviews.
16. (Desired) Demonstrated experience with the Sponsor s security policies and regulations.
17. (Desired) Demonstrated experience providing recommendations in technical standards, security standards, and operational assurance.
18. (Desired) Demonstrated experience with USG standards such as Intelligence Community Directive (ICD) 503, Federal Information Processing Standards (FIPS), National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, SP 800-39, SP 800-53, SP 800-53A, SP 800-60.
MUST be a US Citizen with a U.S. Government clearance - Intel with Polygraph
NOTE: Must have an active TS-SCI with poly. No sponsorships or upgrades are available. Submissions without this requirement will not be considered. H1-B holders will not be considered.
Benefits:
5 week paid vacation 10 gov't holidays
15% contribution to 401k
LTD, STD disability and life insurance
Paid health, dental, and vision for employee and family.
$5000 annual training expense reimbursement
Computer purchase plan
Overview:
The Sponsor requires subject matter expertise in technical risk analysis of enterprise and mission systems
Cyber Security EngineerThe Sponsor supports a diverse set of corporate goals across the organization by conducting technical risk assessments and providing technical risk mitigation guidance on the use of various enabling technologies. The Sponsor requires subject matter expertise in technical risk analysis of enterprise and mission systems, IT systems and networks, mobile and wireless networks, cloud-based computing, network management platforms, communication protocols, scripting or programming products, configuration scripts, and IT hardware and software products in support of Sponsor s technical risk assessment activities. The Cyber Security Engineer will perform technical risk assessments and provide technical risk mitigation guidance on the use of various enabling technologies and gather Body of Evidence (BOE) and assess artifacts, such as CONOPS, use cases, detailed network diagrams, technical design details, procurement methods, and System Security Plan (SSP) to get a holistic view of the interworking parts of a given technology implementation being evaluated, from which real insights can be derived to inform risk assessor s judgement. They will apply consistent and systematic investigative practices to comprehensively assess risks, identify and characterize threats and vulnerabilities; evaluate system or network operations using network management platforms, network scanning tools, auditing functions, PCAP captures, and log reviews; and analyze system, network, or cloud configurations for mis-configured settings, configurations not required for deployment, removal of test scripts to minimize the configuration to fulfill the specific deployment. The Cyber Security Engineer will analyze hardware and software used in a system or network for origin of manufacturer, known vulnerabilities, outdated hardware or software; remain current with existing and future technologies to assist the Sponsor with identifying associated risks of implementing proposed technologies; and provide guidance of potential cyber threats, attacks, and exploitations and advise decision-makers of the inherent risks and mitigation to the Sponsor s equities. They will also ensure appropriate risk mitigation considerations are baked in early in the development cycle, and risks and vulnerabilities are well understood and appropriately mitigated; organize and schedule work to effectively manage a case load; and track, document, and communicate progress status updates and weekly status updates on all technical risk assessment reports, cases describing potential security concerns and mitigations to enhance security posture.
1. (Mandatory) Demonstrated experience analyzing IT systems for cyber security vulnerabilities.
2. (Mandatory) Demonstrated experience developing IT system or network architecture design, conducting IP data flow analysis, encryption configuration, and vulnerability analysis using both open-source and commercial tools, such as Nmap, Wireshark, Metasploit, Canvas, Kismet, or BackTrack.
3. (Mandatory) Demonstrated experience analyzing IT network configurations of devices such as firewalls, routers, switches, VPNs, or Intrusion Detection/Prevention Systems for cyber security vulnerabilities.
4. (Mandatory) Demonstrated experience with communications protocols such as IP, TCP, UDP, HTTP, HTTPS, MPLS, OSPF, IGRP, BGP, SIP, H.232.
5. (Mandatory) Demonstrated experience with multiple OS s, including Windows, Linux, and OSX.
6. (Mandatory) Demonstrated experience with Microsoft Windows ver.; 7, 8, 10, 2008R2, 2012, 2012R2, or 2016.
7. (Mandatory) Demonstrated experience with cloud computing technology and hypervisors such as HyperV, VMWare ESX, or Virtual Box.
8. (Mandatory) Demonstrated experience with transitioning security domains and use of cross domain appliances.
9. (Mandatory) Demonstrated experience with network management systems, network storage, backup systems, and disaster recovery (DR) architectures.
10. (Mandatory) Demonstrated experience performing technical risk assessments and providing technical risk mitigation guidance.
11. (Mandatory) Demonstrated experience ensuring appropriate risk mitigation considerations, risks and vulnerabilities are well understood and appropriately mitigated.
12. (Mandatory) Demonstrated experience analyzing procurement processes of hardware, software and services to comply with cyber security and operational needs.
13. (Mandatory) Demonstrated experience creating concise and well-structured written assessments.
14. (Desired) Demonstrated experience with the Sponsor s IT review boards.
15. (Desired) Demonstrated experience with providing recommendations to IT architecture and design reviews.
16. (Desired) Demonstrated experience with the Sponsor s security policies and regulations.
17. (Desired) Demonstrated experience providing recommendations in technical standards, security standards, and operational assurance.
18. (Desired) Demonstrated experience with USG standards such as Intelligence Community Directive (ICD) 503, Federal Information Processing Standards (FIPS), National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, SP 800-39, SP 800-53, SP 800-53A, SP 800-60.
MUST be a US Citizen with a U.S. Government clearance - Intel with Polygraph
NOTE: Must have an active TS-SCI with poly. No sponsorships or upgrades are available. Submissions without this requirement will not be considered. H1-B holders will not be considered.
Benefits:
5 week paid vacation 10 gov't holidays
15% contribution to 401k
LTD, STD disability and life insurance
Paid health, dental, and vision for employee and family.
$5000 annual training expense reimbursement
Computer purchase plan
Salary : $5,000
Senior Security Engineer
UltraViolet Cyber -
Arlington, VA
Technical Privacy Engineer
Cyber Security Innovations -
Hyattsville, MD
Cyber Security Analyst
UltraViolet Cyber -
Arlington, VA