Cyber Security System Engineer - SME

Herndon, Virginia, United States

KDA Consulting Inc

KDA Consulting was founded to give technologists the flexibility to solve challenges, push boundaries, and deliver mission needs differently. We prioritize client success, reliability, innovation, and excellence.

View company page

KDA Consulting is a Disabled Veteran, Woman-Owned, Certified Disadvantaged Small Business, comprised of a diverse team of professionals driven to tackle the demanding National Defense and Intelligence challenges through IT solutions.  We emphasize teamwork and focus on achieving goals to complete deliverables efficiently, on-time, and under budget. 

We are currently seeking a Cyber Security Systems Engineer- SME to join our team.

 

Primary Job Duties & Required Experience

·        Document and obtain a general understanding of the architecture being developed or that was developed for each project in order to represent the systems architecture in the customers security tracking application.

·        Gather the information by working with various team members in order to write various additional A&A related documents such as Contingency Plan (CP), Configuration Management Plan (CMP), Privileged User Guide (PUG), Standard Operating Procedures (SOP’s), etc.

·        Support Accreditation and Authorization (A&A) reviews by ISSM, as well as the Security Controls Assessor (SCA), and auditors.

·        Document the Risk Elements coming out of the Assessment and make Plans of Actions and Milestones (POA&Ms) timeframe and plan recommendations, implementation responses or mitigations, as well as provide all required artifacts (i.e. evidence gathering from the teams)

·        Coordinating with various contractor and staff personnel to obtain the A&A content, as well as working with various customer organizations to navigate the customer’s A&A process in order to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), as well as Authority to Operate (ATO).

·        Keep track of where each of the various A&A projects are within the customer’s A&A process in order to know when it’s time to re-submit for accreditation or an accreditation extension.

·        Support all activities associated with the ATO Continuous Monitoring process.

·        Possess a proficiency in multi-tasking, as well as being a good communicator/facilitator. Comfortable communicating at all levels from engineer to senior staff.

·        Possess the ability to bridge the technical implementation (i.e. engineer talk), into commonly understood security wording and communicate security working to others not familiar with security. Often this is a skillset and is not an actual language, but frequently translation or a basic understand needs to be conveyed by the ISSE when speaking with others or in writing the documentation in order to ensure it’s easy to understand.

·        Possess a demonstrated skillset in documenting the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for various Assessment and Authorization (A&A) efforts

Highly Desired skills and demonstrated experience

·        Previous ISSE experience directly supporting the customer.

·        Various security tools and reports such as Xacta, RoadRunner, Rapid 7, WebInspect, App Detective, and Splunk

·        Public, private and hybrid Cloud experience (AWS, Microsoft Azure, etc.)​

 

Job Requirements

·        Active TS/SCI + Full Scope Poly U.S. Government Security is required

·        Bachelor’s Degree

·        11-15 years of relevant professional work experience

·        Ability to maintain discretion and confidentiality

·        Strong interpersonal skills, especially the ability to network and establish professional relationships

·        Ability to prioritize, demonstrated strong organizational skills, and ability to meet or exceed deadlines

 

Physical Demands: Position will require frequent sitting, standing, and/or mobility within an office setting.  Employee must be able to use hands to complete work at a workstation/computer, be able to reach, type and manipulate with hands, fingers, and arms; lift and/or move up to 20 pounds; talk, see and hear.

Work Environment: Work is performed on client site in a professional office environment with moderate stress and noise levels.  Position requires employee to effectively use a computer, potentially for long periods of time, and to accommodate potentially frequent interruptions.  Candidate should be both customer-focused and present a team approach to overall work.

Schedule:  Business core hours are Monday through Friday, from 8:30 a.m. to 5:00 p.m. ET. Standard work hours may vary for this position based upon contract requirements. Position will be located onsite at a customer facility in Herndon, VA. 

Americans with Disabilities Act (ADA): KDA is committed to the full inclusion of all qualified individuals. As part of this commitment, KDA will ensure that persons with disabilities are provided reasonable accommodations in the hiring process. We encourage qualified individuals with disabilities to apply. If a reasonable accommodation is needed to participate in the job application or interview process or to perform essential job functions, please contact our HR team by email hr@kda-consulting.com. For persons who are deaf, hard of hearing, deafblind, or deaf-disabled, KDA will provide an American Sign Language (ASL) interpreter where needed as a reasonable accommodation for the hiring processes.

EEOC: KDA is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status.

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: AWS Azure Cloud ICD 503 ISSE Monitoring Risk management RMF Splunk TS/SCI

Regions: Africa North America
Country: United States
Job stats:  5  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.