- Tribalco
- Austin, TX
- Full-Time
- 5 days ago
Information Assurance Engineer II: our view in 3 lines...
- The Role: Provides information assurance and RMF-focused security services to support DoD systems and ensure compliance with military accreditation and certification standards.
- The Person: Work with system owners to manage POA&Ms, perform risk assessments, run incident response and forensic analysis, maintain PKI and COMSEC tasks, and validate system security plans and accreditation activities.
- Requirements: Requires experience with RMF IT security controls and policies, IT-I level certification IAW AR 25-2, IAT-II (Security+), Computing Environment Certifications, and an active SECRET clearance.
Job Description
- Work with system owners to close IAVMs/ICVMs and open Plan of Action and Milestones (POA&Ms) in a rapid fashion, in accordance with DoD instructions/directives. Review all POA&MS with the Program Manager on at least a quarterly basis and update the POA&Ms accordingly.
- Account Management of clients/users/customers with a 4-star command
- Create SOPs and verify the training of users to approve their SAAR as an ISSO.
- Provide Defense in Depth principles and technology in security engineering designs and implementation
- Analyze existing and future systems, reviewing security architectures, and developing engineering solutions that integrate information security requirements to proactively manage information protection
- Apply security risk assessment methodology to system development, including assessing and auditing network penetration testing, antivirus deployment, risk analysis
- Conduct Computer Incident Response Team (CIRT) activities, including forensic analysis
- Plan, implement, and manage a Defense In Depth for the total network and/or enclaves within the network to include such items as: scanning, remediation, host and network intrusion detection/prevention, firewalls, proxy servers, web cache, virus programs, vulnerability scanning, content filtering, remote dial in protection, Host Based Security Services, Directory Services, and Certification and Accreditation, DoD Instruction 5200.40, accreditation guidance and advice IAW AR 25-2 and IA Best Business Practices (BBPs). Plan, respond, investigate, and report undisclosed classified incident remediation.
- Assess and mitigate system security threats/risks throughout the program life cycle
- Validate system security requirements definition and analysis and review/approve System Security Plans for enterprise-wide architectures
- Maintain Agency public key infrastructure system Implement security designs in hardware, software, data and procedures
- Provide support for the Department of Defense (DoD) Public Key Infrastructure (PKI) service.
- Responsible for requesting, receiving, installation, and accountability of system (server) PKI certificates and providing technical support for PKI.
- Provide communications security (COMSEC) rekeying support within normal business hours or on-call, as required. Prepare and maintain secure communications devices and crypto keys. Provide Certification and Accreditation, as well as provide Automated Information System Accreditation support
- Provide Security Risk Assessment.
- Perform risk analysis of resources, controls, vulnerabilities, impact of losing systems’ capabilities and threats to the mission objective; provide analysis to facilitate decisions to implement security countermeasures or mitigate risk; implement countermeasures; periodically review program.
- Recognize possible threats and review evaluations for compliance and non-compliance.
- Ability to organize, prioritize and meet deadlines
- Capable of conveying complex information in a simplistic manner
- Strong critical thinking and problem- solving skills
- Strong self-starter requiring minimal supervision
- Able to take proactive measures to prevent problems rather than reactive by nature
- Strong verbal and written communication to effectively express concepts, plans, and proposals
- Must be a U.S. Citizen
- Bachelor’s degree in computer science, Cybersecurity, Computer Engineering, or related discipline.
- Comparable experience in lieu of degree may be considered.
- 3+ years of experience performing Information Assurance functions and using RMF IT security controls and policies
- Must possess and maintain an IT-I level certification IAW AR 25-2 and an IAT-II (Security +) or higher
- Must possess and maintain Computing Environment Certifications
- This position requires an active SECRET clearance
- Compensation will be hourly and is commensurate with experience.Â
- All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.Â
- Tribalco is an equal opportunity employer.Â
Â
Tribalco is headquartered in Maryland and maintains offices, warehouse operations, and points of presence in Florida, Nevada, South Korea, Germany, the Middle East, and Africa. For additional information, please visit tribalco.com.
