Agensys Corporation
Agensys Corporation is hiring: Lead Security Engineer with Security Clearance in
Agensys Corporation, Fort Belvoir, VA, United States, 22060
RESPONSIBILITIES
- Act as an independent and impartial assessor to determine and certify aggregate cybersecurity risk for recommendation to the SCA.
- Experience in helping federal agencies manage risks associated with operating an on-premise and cloud-based information system while using RMF.
- Conduct security control validation and assessment of technical security features of a system or network to address known threats and vulnerabilities. The evaluation must consider and identify impacts as well as consideration of existing risk mitigation strategies.
- Validate and assess security controls in accordance with NIST SP 800-53, CNSSI-1253 and with the DoD Risk Management Framework (RMF) process.
- Conduct required vulnerability analysis to support mitigation and residual risk determination.
- Ensure traceability of all vulnerabilities from raw assessment results to the POA&M.
- Support updates of the RAR and POA&M based on the assessment results.
- Advise the AODR, AO, CISO of all DoD RMF matters related to associated systems based on the evaluation of associated security controls and artifacts.
- Identify, communicate and deliver concise, coherent narratives on key controls and technical details of nuanced issues.
- Convey findings, recommendations and ideas on complex IT systems to functional leaders and executives.
- Possess in-depth knowledge of all NIST and CNSSI publications related to RMF and security controls for national security systems (NSS) and non-NSS systems.
- Possess working knowledge of DoD Risk Management Framework (RMF), DoD IA guidance and policies, and NIST 800 series standards.
- Possess in-depth knowledge and hands-on experience with eMASS software supporting the RMF process.
- Possess working knowledge of ACAS Security Center to include report generation and evaluation of vulnerability and discovery scans.
- Possess experience with developing and briefing DoD Cybersecurity Scorecard and Key Performance Indicators (KPI).
- Possess working knowledge of STIG Viewer to validate STIG checklists and SCAP scans.
- Ability to work effectively within a team environment as well as independently.
- Strong verbal and written communication skills.
REQUIRED QUALIFICATIONS
- BS 8-10 Years, MS 6-8, PhD 3-5
- eMASS Training and Experience
- Minimum of DOD IAM II or III
- Minimum Top-Secret Clearance
- Bachelor's Degree