Security Officer

Remote: 
Full Remote
Contract: 

Offer summary

Qualifications:

Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or related field, or equivalent experience., Minimum of 4 years of related experience in security and information technology., Familiarity with Agile methodologies and experience with AWS security tools., Strong analytical, problem-solving, and communication skills..

Key responsibilities:

  • Provide guidance on security policy implementation and collaborate with stakeholders.
  • Conduct vulnerability assessments and monitor systems for potential breaches.
  • Educate users on security requirements and recommend process improvements.
  • Support the development of security documentation and respond to security incidents.

eSimplicity logo
eSimplicity Scaleup http://www.esimplicity.com/
51 - 200 Employees
See all jobs

Job description

Job Type
Full-time
Description

About Us:

eSimplicity is modern digital services company that work across government, partnering with our clients to improve the lives and ensure the security of all Americans—from soldiers and veteran to kids and the elderly, and defend national interests on the battlefield. Our engineers, designers and strategist cut through complexity to create intuitive products and services that equip Federal agencies with solutions to courageously transform today for a better tomorrow for all Americans.


Responsibilities: 

  • Work closely with the Product Owners, ISSOs, engineering and infrastructure staff to provide guidance on implementation if security policies, standards, and procedures  
  • Analyze new or updated security requirements, collaborate with stakeholders, and develop responses that are clear and accurate  
  • Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analysis, and more  
  • Interpret security risk assessment, review security scan results, assess security vulnerabilities and support the development and remediation of vulnerability and compliance issues via Plan of Action and Milestones (POA&Ms)  
  • Support the development of implementation and design documentation relating to security feature implementation  
  • Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues  
  • Analyze and interpret agency security requirements and provide governance communication to non-security personnel  
  • Collaborate with product teams, ISSOs and other stakeholders in support of continuous monitoring and ATO efforts  
  • Conducts vulnerability assessments and monitors systems, networks, databases and Web-based assets for potential system breaches. Recommends and takes the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities.  
  • Responds to alerts from information security tools. Reports, investigates, and resolves higher level security incidents.   
  • Responds to security tool outages, degradations in service, tune security rules and alerts, and setup/maintain security tool dashboards and reporting.  
  • Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach. Ensures compliance with regulations and privacy laws. Conducts research to identify new attack vectors.  
  • Educates and communicates security requirements and procedures to all users and new employees.  
  • Recommend process improvements to the information system for risk mitigation.  
  • Applies iterative security automation to all program aspects increasing overall security posture iteratively and never accepts the status quo.  
  • Provide audit log review in Splunk, present any findings to ISSO, and plan for any investigation or remediation activities.   
  • Periodic user and privileged access reviews. 
Requirements
  • Minimum of 4 years related experience.  
  • A Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or other related scientific or technical discipline. With six years of general information technology experience and at least four years of specialized experience, a degree is not required.  
  • Familiarity with Agile Methodologies.  
  • Experience implementing security controls/changes from security scans, security frameworks. 
  • Experience working with developers to translate and understand changes required by scans, security controls and or ad-hoc security bulletins/mandates. 
  • Working knowledge of AWS Security tools, their functionality, and purpose  
  • Assist customer with defining appropriate change management processes (Responsible for documenting application criticality, privacy, and security impact analysis)  
  • Knowledge of hardening standards (DISA STIG, CIS)  
  • Understanding of NIST Risk Management Framework and NIST 800-53 rev5  
  • Experience with CI/CD, defining security decision gates and DevSecOps  
  • Know the difference between SAST, DAST, IAST, OAST tools and their functions, benefits, and weaknesses within CI/CD   
  • Understanding of business security practices and procedures; knowledge of current security tools available; hardware/software security implementation; different communication protocols; encryption techniques/tools; familiarity with commercial products; and current Internet technology.  
  • Understands continuous automated security practices applied to data and application engineering teams.  
  • Prior experience managing systems in AWS cloud environments, familiarity with AWS Tools and Services  
  • Experience with designing security “baked-in” to any architecture: Cloud and IaC, Applications, Web application, Data Processing, Data Centric Applications, AI/ML, CICD Pipelines; seeks automation driven designs.  
  • Demonstrated work experience with the following: computer networking, cryptography, security engineering and architecture, vulnerability assessments, or operating systems required.   
  • Broad experience using cloud services, Linux systems, and Development/Data engineering core tools Github, GitHub Actions, Security Tools, etc.  
  • Demonstrated working knowledge of vulnerability and compliance scanning tools.  
  • Understands how to assess vulnerabilities and provide recommendations regardless of first-hand knowledge of the application or system.  
  • Proven ability to work effectively both independently and/or in a team setting.   
  • Must possess strong analytical and problem-solving abilities; and strong critical-thinking skills in complex communication environments.   
  • Strong attention to detail. Required to manage/follow-through of multiple independent tasks, dependencies across intra/inter-project teams  
  • Excellent organizational and time-management skills in a fast-paced environment.   
  • Excellent customer service skills with the ability to deal tactfully, confidently, and ethically with both internal and external customers.  
  • Experience with Government Agency Security Assessment Process in support of maintaining and/or establishing an ATO and the appropriate security boundary.  
  • Experience with Atlassian Jira & Confluence  
  • Excellent command of written and spoken English.    
  • Ability to obtain and maintain a Public Trust, residing in the United States  
  • Federal Government contracting work experience 

Clearance Requirements and Contingency Language

This position is contingent upon the ability to obtain a Moderate Risk Public Trust (MRPT) clearance

This position is contingent upon award


Working Environment:
eSimplicity supports a remote work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by your manager.
Occasional travel for training and project meetings. It is estimated to be less than 25% per year.

Benefits:
We offer highly competitive salaries and full healthcare benefits.

Equal Employment Opportunity:
eSimplicity is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender, age, status as a protected veteran, sexual orientation, gender identity, or status as a qualified individual with a disability.

Salary Description
96,100-142,000

Required profile

Experience

Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Analytical Skills
  • Time Management
  • Critical Thinking
  • Customer Service
  • Organizational Skills
  • Detail Oriented
  • Problem Solving

Security Engineer Related jobs