Security Engineer/Data Security Analyst III
Location: Lackland AFB, San Antonio, Texas
PRIMARY DUTY RESPONSIBILITIES:
- Conduct timely and in-depth research for policies and processes applicable to security engineering.
- Develop solutions and recommendations (with test plans) and provide POA&M and documentation support.
- Assessment methodologies
- Governance, Risk, and Compliance (GRC) platforms
- Risk Assessment Reports (RARs)
- Assessment and Authorization (A&A) workflow tools data
- Patch management
- IA Vulnerability Alerts (IAVA)
- Memorandums
- Interim Authorization To Test (IATT)
- Critical Design Review (CDR)
- Continuous Monitoring Review (CMR)
- Authority To Operate (ATO)
- Perform scans of systems and architectures using AF IC -approved scanning tools and related AFJWICS bases and stations ideal.
- Apply IT security control requirements to address the level of security required to protect the confidentiality, integrity and availability of system data and resources.
-
Ability to support global travel when needed for assessment support.
Security Clearance: Top Secret with SCI.
Education/Certifications: BS or MS degree in IT-related field and DoD 8570/8140 IAM or IAT Level III Certification required.
Relevant Experience:
- 4 – 5 years of experience with solid proficiency in use of Risk Management (RMF) methodology, its associated assessments and report requirements, understanding of the plans and policies, and conduct timely and in-depth research for policies and processes applicable to security engineering.
- Solid knowledge and experience with the NIST 800 Risk Management Framework (RMF) NIST 800 series 800-37 Rev 2, 800-53 Rev. 5.
- Demonstrated expertise in RMF processes and tools such as Xacta and eMASS, ensuring systems and applications to meet both AF IC and related IC policies and regulations.
- Ability to apply IT security control requirements to address the level of security required to protect the confidentiality, integrity and availability of system data and resources.
- Technical knowledge and experience system networking, Windows, Linux, and DoD or USAF Cloud desired.