Careers
-
Information Systems Security Engineer (ISSE) – Huntsville, LA, Dalhgren
February 16, 2012Capable of desigining, develpoing, deploying, maintaining, and monitoring PL2 networks, inclusive of switches, routers, firewalls, IDSs for Unix and Windows environments. Possess 7-10 years documented, practical experience in networking design and architectures, as well as network management and a minimum of 5 years of experience in a SAP environment. Security Clearance requirements (TS, TS/SCI) Must possess at least 5-7 years of experience as a Network Engineer using CISCO , IOS CISCO PIX and CISCO ASA. CISCO certified network Engineer (CCNE) and CISCO Certified Network Administrator. Must possess a Bachelor’s Degree in Computer Science, Computer Information Systems, Management Information Systems, or related field; A masters degree is preferred.
-
PSO (Journeyman)-Huntsville, LA, Dalhgren
February 16, 2012Capable of developing and implementing a multi- disciplined security program for complex, major acquisitions Special Access Programs (SAPs). Knowledgeable of personnel, industrial physcial, IT/IA and information security principles. Has 3-10 years of experience as a PSO with at least 3 cumulative years i acquisition SAPs. The last SAP-related position must be within the last nine months. Strong writing ability. Education: BS/BA in related field or a combination of lower-level education, formal tranining and experiance beyond the Journeyman baseline. Security Cleareance: TS/SCI.
-
Motion Video Analyst (Deployed)
February 7, 2012Experience:
·
Four years imagery analysis experience
in the Intelligence Community at the national level.·
Have regional expertise as well as a
background in military and terrorism-associated issues.- Experience
exploiting Full Motion Video imagery
Required Education:
·
Minimum
of 2 years post High School level education or equivalent specialized
experience·
Attended either the Geospatial
Intelligence Training Program or equivalent.Required Skills:
·
Strong knowledge of soft copy imagery
exploitation functionalities.·
Demonstrated good oral and written
communication skills.·
Knowledge and proficiency in both
commercial and government software.·
Working knowledge of the following
systems and software programs: REMOTEVIEW, IEC, NES, MAAS, Socet GXP, ArcGIS
(desired), Jabber, MIRC Chat and common office software to include slide
presentations, spreadsheets, word processing, and email.·
Knowledgeable of the imagery collection
process.·
Knowledgeable of multi-spectral imagery
exploitation.Other Requirements:
·
Individual
will be willing to submit to random drug and alcohol testing·
Individual
will be willing to undergo medical evaluations to ensure they are medically fit
and capable of enduring the
rigors of deployment in support of a military operation.·
Individual
must be willing to receive Anthrax and Smallpox vaccines.·
Individual
must be willing to deploy for a period of 365 days·
Individual
will be willing and able to live and work in temporary facilities (e.g. tents,
warehouses, portable shelters).Clearance Requirement:
·
Individual
will possess at time of employment minimum TOP SECRET with access to Sensitive
Compartmented Information (TS/SCI) with NATO access - Experience
-
Information Systems Security Engineer-Huntsville, AL, Virginia, Los Angeles, CA
February 6, 2012Capable
of designing, developing, deploying, maintaining, and monitoring PL2 networks,
inclusive of switches, routers, firewalls, and IDSs for Unix and Windows
environments. Possess 7-10 years of documented, practical experience in
networking design and architectures, as well as network management and a
minimum of 5 years of experience in a SAP environment. Security clearance
requirements (TS, TS/SCI). Must possess at least 5-7 years of experience as a
Network Engineer using CISCO IOS, CISCO PIX and CISCO ASA. CISCO Certified
Network Engineer (CCNE) and CISCO Certified Network Administrator (CCNA)
certifications. Must possess a Bachelor’s Degree in Computer Science, Computer
Information Systems, Management Information Systems, or related field; a
Master’ Degree is preferred. -
Information Systems Security Help Desk Analyst – Huntsville, AL
February 6, 2012Capable
of providing critical Information Technology Help Desk functions (e.g. account
administration, password changes, group changes, account expiration date
changes, certification and accreditation support, support to patch management
and virus signature updates, coordinated LAN and email account creation and
email forwarding for all systems users, etc.). Windows desktop and Unix:
specifically, Trusted Solaris 8, experience required. Possess an Associate’s
degree in a technical field and be compliant with DoD 8570.01-M Information
Assurance Technical Level II requirements. A Bachelor’s degree in a technical
field, such as Information Security, Computer Science, etc. is preferred.
Possess at least 3-5 years in first and/or second tier support. Security
clearance requirements (TS, TS/SCI). Minimum of three years experience in end
user support. -
Information Systems Certification and Accreditation Engineer-Huntsville, AL
February 6, 2012–
Possess documented experience in IT and IA policy development within a SAP
environment, as well as project management. Be able to work independently with
little formal supervision. Possess 5-10 years of documented, practical
experience in IT security, with a minimum of 3-5 years of experience in IA, and
a minimum of 3 years of experience in a SAP environment. Security clearance
requirements (TS, TS/SCI). Possess an Associate’s degree in a technical field
and be compliant with DoD 8570.01-M Information Assurance Level II
requirements. A Bachelor’s degree in a technical field, such as Information
Security, Computer Science, etc. preferred. -
IT System Administrator-Eglin AFB, FL
February 2, 2012Description of Duties:•Provides daily administration, operation, and maintenance of all current and future secure networks and stand alone Automated Information Systems (AIS).• Establishes complex operational databases, software configuration controls and system interfaces for computer system(s) assigned.• Maintains file servers, network access, and system documentation.• Analyzes and troubleshoots system anomalies to ensure optimum equipment performance.• Prepares system for operational use and supports operational tests.Attributes:•Thorough knowledge of Microsoft Windows Server 2000/2003 and Microsoft Windows XP/Vista operating systems (OS) administration and technologies.• Working knowledge of Local Area Network (LAN) and Wide Area Network (WAN) technology to include communication security (COMSEC) integration.• Requires Bachelor’s degree (in Computer Science, Management Information Systems or related field) or at least four years of technical experience.• Must have a minimum of two years experience in Special Access Program (SAP) network security, and Information Security (IS).• The award and maintenance of a CompTIA Network+ certification or equivalent is strongly desired.• Must possess a Top Secret (TS) security clearance with eligibility for SCI and SAP accesses.
-
Information Assurance Manager-Bolling AFB, DC
February 2, 2012Information Assurance ManagerEnsure AIS and network nodes are operated, maintained, and disposed of in accordance witt security policies and practices. Perform Information Assurance Manager (lAM) duties in support of in-house and external customers. Duties include, but are not limited to reviewing and developing AIS accreditation/ certification support· documentation; notifying the customer when changes occur that might affect AIS accreditation/certification; performing system and network self-inspections; providing security coordination and review on all system test plans; review SSPs identifying and endorsing those found to be acceptable; ensure the development of system certification documentation by reviewing and endorsing such documentation and recommending actions by the DAA, AIS vulnerabilities and implementing countermeasures; maintain a repository for all system certification documentation and modifications; manage procedures for authorizing the use of software, hardware, and firmware on systems; representing the customer on various technical review teams; maintaining AIS security records; advising on and preparing Co-Utilization Agreements for network nodes operating in subordinate government and contractor facilities; and receiving direction from the government PSO staff.Must have a working knowledge of both JAFAN and DCID 6/3, ICD Se3, NIST SP8ee-~ 37, and current relevant experience with PL2, PL3 & PL4 cross domain solutions. Background with special programs and SCI is a plus. Knowledge of both IA (SSAA development, DITSCAP/DIACAP process, policies & procedures, etc.) and the technical side of security including network scanning, vulnerability management (lAVA’s), and Intrusion Detection is a plus. Experience with GFI EventsManager, Sanctuary, and VMWare Infrastructure is a plus. Must possess a minimum of 5 years experience in Information Systems Security with an empha~s on Certification and Accreditation (C&A) and/or Security policy development. Should have hands-on experience with developing relevant security policies and procedures and other relevant Security documentation including SSAA’s and related appendices. Experience developing and executing proper procedures for handling security incidents is required. Experience developing Accreditation documentation for classified applications and general support systems is required. Willingness to work in a team environment is a must. Member must have an active TS/SCI clearance and willing to take a CI polygraph.lAM will conduct periodic security reviews of all information systems, implement security safeguards and monitor attempts to test or circumvent security mechanisms. -
Program Security Officer-Generalist-Peterson AFB, CO
February 2, 2012The contractor
shall perform the following duties related to Program Security Officer Support: Provide technical advice and security support
to collateral and SAP programs and emerging mission areas. Provide classification guidance and assistance
for all security programs to include collateral and SCI Programs. Draft,
Coordinate, gain approval for, and implement Security Policy.
Research regulations, directives and policy for compliance. Recommend changes to OPSEC, INFOSEC and
classification policy. Oversee state of health of Program Security if needed
prepare and present suggestions for improvements. Manage Program Security Review and Self
Inspection Programs. Manage security incident investigation and reporting
program. Perform OPSEC analysis and
provide other OPSEC support. Provide
extensive, comprehensive security support to government and contractor
customers. Develop, review and staff for
approval general program security management documentation. Write, review and staff coordination of Security
Classification Guides (SCGs). Review and edit documents, plans, SOPs, OIs, etc. Plan, prepare and present security education
and training. Develop, maintain,
implement and train personnel on emergency actions procedures. Advise customer on TEMPEST/EMSEC requirements
and provide technical solutions for these requirements.Attend Program
CCRBs, CCBs, and IPTs to ensure changes to system baselines do not negatively
affect security and initiate actions to add mitigation where necessary.Assist program
managers and security personnel in performing SAP lifecycle analyses. Work with
individual program management personnel to assist them in the analysis and
development of solutions to unique and difficult situations. Assist in long term strategic planning. Represent the government at program
management and planning meetings andworking group
sessions. Prepare, conduct and assist in
classified document inventories to include program, SCI and collateral level
media. Assist in the destruction of
classified material. Provide periodic
in-processing document control training to assigned personnel. Check incoming and outgoing documents for
proper classification markings.Assist the
PSO/GSSO in the overall operation and management of an effective specialaccess security
oversight program. Provide
administrative security support for special access program document control
functions, including sending, receiving and logging correspondence as
required. Must maintain a document
accountability database. The contractor
must be willing and available to perform all legal, moral and ethical security
functions to enable the customer base. -
Information Assurance -Eglin AFB, FL
February 2, 2012Ø
Perform oversight of the development,
implementation and evaluation of information system security program policy;
special emphasis placed upon integration of existing SAP network
infrastructuresØ
Perform analysis of network security, based upon
the DCID 6/3, DITSCAP, DIACAP, and NISPOM Chapter 8 certification and
accreditation process; advise customer on IT certification and accreditation
issuesØ
Perform risk assessments and make
recommendations to customersØ
Advise government program managers on security
testing methodologies and processesØ
Evaluate certification documentation and provide
written recommendations for accreditation to government PM’sØ
Periodically reviews system security to
accommodate changes to policy or technologyØ
Evaluate IT threats and vulnerabilities to
determine whether additional safeguards are neededØ
When applicable, ensure that certification is
accomplished for each information systemØ
Develop and maintain a formal Information
Systems Security ProgramØ
Develop, implement, provide guidance, and
enforce AIS security policies and proceduresØ
Ensure that all ISSOs, network administrators,
and other AIS personnel receive the necessary technical and security training
to carry out their dutiesØ
Develop, review, endorse, and recommend action
by the designated approval authority (DAA) of system certification
documentationØ
Ensure approved procedures are in place for
clearing, purging, declassifying, and releasing system memory, media, and
outputØ
Conduct certification tests that include
verification that the features and assurances required for each protection
level fare functionalØ
Maintain a repository for all system
certification/accreditation documentation and modificationsØ
Coordinate AIS security inspections, tests, and
reviewsØ
Develop policies and procedures for responding
to security incidents, and for investigating and reporting security violations
and incidentsØ
Ensure proper protection or corrective measures
have been taken when an incident or vulnerability has been discovered within a
systemØ
Ensure that data ownership and responsibilities
are established for each AIS, to include accountability, access rights, and
special handling requirementsØ
Ensure development and implementation of an
information security education, training, and awareness program, to include
attending, monitoring, and presenting local AIS security training.Ø
Ensure that security testing and evaluations are
completed and documentedØ
Evaluate threats and vulnerabilities to
ascertain whether additional safeguards are neededØ
Assess changes in the system, its environment,
and operational needs that could affect the accreditationØ
Ensure that certification is accomplished on
each AISØ
Review AIS test plansØ
Conduct periodic testing of the security posture
of the AISØ
Ensure configuration management (CM) for
security-relevant AIS software, hardware, and firmware are properly documented.Ø
Ensure that system recovery processes are
monitored to ensure that security features and procedures are properly restoredØ
Ensure all AIS security-related documentation is
current and accessible to properly authorized individualsØ
Ensure that system security requirements are
addressed during all phases of the system life cycleØ
Participate in self-inspections; identify
security discrepancies and report security incidentsØ
Coordinate all technical security issues outside of area of expertise or
responsibility with SSEØ
Provide expert research and analysis in support
of expanding programs and area of responsibilityØ
Perform file transfers between local systems to
storage devices -
Adjudication Support-Wright-Patterson AFB, OH
February 2, 2012Conduct 1st and 2nd tier
reviews of Personnel Access Request (PAR) forms in accordance with Joint Air
Force Army Navy Manual 6/4, Special Access Tier Review Process. Establish process to submit, monitor and track
PAR forms and Letters of Compelling Need submitted to other offices for action,
including the Air Force Central Adjudication Office (CAO) for 3rd
tier reviews, and AFOSI PJ and Air Force SAPCO for waiver requests. Maintain liaison with security professionals
in CAO, AFOSI PJ, and Special Access Program Central Office (SAPCO). Provide tier guidance to Program Security
Officers and Contractor Program Security Officers. Conduct tier training for security personnel
involved in special access programs. Access
and update the Air Force Access Database System (AFADS) to ensure personnel
have properly documented personal, PAR, and Tier Review information supporting
program access. Access and review database entries in the Joint Personnel
Adjudication System and Defense Central Index of Investigations to insure
access eligibility requirements.
Identify issues of a counterintelligence nature regarding foreign travel
and foreign contacts requiring mitigation.
Participate in government security reviews. Prepare, send, and receive visitor
certifications. Bachelor degree preferred with 2 to 4 years experience and Top
Secret SCI security clearance. Will
require attendance at the DSS Academy Personnel Security Adjudications course
for certification training, if not already certified.Candidate must
have a minimum of four years related experience in general security experience
and five years in specialized security experience involving SAP/SCI activities.
Excellent verbal and written communication skills and attention to detail
required. Must be capable of working as a team member or independently with
little or no supervision. Must be capable of interacting with numerous
government and civilian customers in a dynamic environment, and have the
ability to perform numerous tasks simultaneously. Applicants selected will be
subject to a government security investigation and must meet eligibility
requirements for access to classified information.Applicants
selected will be subject to a government security investigation and must meet
eligibility requirements for access to classified information. -
Information Assurance Specialist-Bolling AFB, DC
February 2, 2012Ø
Perform oversight of the development,
implementation and evaluation of information system security program policy;
special emphasis placed upon integration of existing SAP network
infrastructuresØ
Perform analysis of network security, based upon
the DCID 6/3, DITSCAP, DIACAP, and NISPOM Chapter 8 certification and
accreditation process; advise customer on IT certification and accreditation
issuesØ
Perform risk assessments and make
recommendations to customersØ
Advise government program managers on security
testing methodologies and processesØ
Evaluate certification documentation and provide
written recommendations for accreditation to government PM’sØ
Periodically reviews system security to
accommodate changes to policy or technologyØ
Evaluate IT threats and vulnerabilities to
determine whether additional safeguards are neededØ
When applicable, ensure that certification is
accomplished for each information systemØ
Develop and maintain a formal Information
Systems Security ProgramØ
Develop, implement, provide guidance, and
enforce AIS security policies and proceduresØ
Ensure that all ISSOs, network administrators,
and other AIS personnel receive the necessary technical and security training
to carry out their dutiesØ
Develop, review, endorse, and recommend action
by the designated approval authority (DAA) of system certification
documentationØ
Ensure approved procedures are in place for
clearing, purging, declassifying, and releasing system memory, media, and
outputØ
Conduct certification tests that include
verification that the features and assurances required for each protection
level fare functionalØ
Maintain a repository for all system
certification/accreditation documentation and modificationsØ
Coordinate AIS security inspections, tests, and
reviewsØ
Develop policies and procedures for responding
to security incidents, and for investigating and reporting security violations
and incidentsØ
Ensure proper protection or corrective measures
have been taken when an incident or vulnerability has been discovered within a
systemØ
Ensure that data ownership and responsibilities
are established for each AIS, to include accountability, access rights, and
special handling requirementsØ
Ensure development and implementation of an
information security education, training, and awareness program, to include
attending, monitoring, and presenting local AIS security training.Ø
Ensure that security testing and evaluations are
completed and documentedØ
Evaluate threats and vulnerabilities to
ascertain whether additional safeguards are neededØ
Assess changes in the system, its environment,
and operational needs that could affect the accreditationØ
Ensure that certification is accomplished on
each AISØ
Review AIS test plansØ
Conduct periodic testing of the security posture
of the AISØ
Ensure configuration management (CM) for
security-relevant AIS software, hardware, and firmware are properly documented.Ø
Ensure that system recovery processes are
monitored to ensure that security features and procedures are properly restoredØ
Ensure all AIS security-related documentation is
current and accessible to properly authorized individualsØ
Ensure that system security requirements are
addressed during all phases of the system life cycleØ
Participate in self-inspections; identify
security discrepancies and report security incidentsØ
Coordinate all technical security issues outside of area of expertise or
responsibility with SSEØ
Provide expert research and analysis in support
of expanding programs and area of responsibilityØ
Perform file transfers between local systems to
storage devices -
Information Assurance Specialist-Bolling AFB, DC
February 2, 2012Ø
Perform oversight of the development,
implementation and evaluation of information system security program policy;
special emphasis placed upon integration of existing SAP network
infrastructuresØ
Perform analysis of network security, based upon
the DCID 6/3, DITSCAP, DIACAP, and NISPOM Chapter 8 certification and
accreditation process; advise customer on IT certification and accreditation
issuesØ
Perform risk assessments and make
recommendations to customersØ
Advise government program managers on security
testing methodologies and processesØ
Evaluate certification documentation and provide
written recommendations for accreditation to government PM’sØ
Periodically reviews system security to
accommodate changes to policy or technologyØ
Evaluate IT threats and vulnerabilities to
determine whether additional safeguards are neededØ
When applicable, ensure that certification is
accomplished for each information systemØ
Develop and maintain a formal Information
Systems Security ProgramØ
Develop, implement, provide guidance, and
enforce AIS security policies and proceduresØ
Ensure that all ISSOs, network administrators,
and other AIS personnel receive the necessary technical and security training
to carry out their dutiesØ
Develop, review, endorse, and recommend action
by the designated approval authority (DAA) of system certification
documentationØ
Ensure approved procedures are in place for
clearing, purging, declassifying, and releasing system memory, media, and
outputØ
Conduct certification tests that include
verification that the features and assurances required for each protection
level fare functionalØ
Maintain a repository for all system
certification/accreditation documentation and modificationsØ
Coordinate AIS security inspections, tests, and
reviewsØ
Develop policies and procedures for responding
to security incidents, and for investigating and reporting security violations
and incidentsØ
Ensure proper protection or corrective measures
have been taken when an incident or vulnerability has been discovered within a
systemØ
Ensure that data ownership and responsibilities
are established for each AIS, to include accountability, access rights, and
special handling requirementsØ
Ensure development and implementation of an
information security education, training, and awareness program, to include
attending, monitoring, and presenting local AIS security training.Ø
Ensure that security testing and evaluations are
completed and documentedØ
Evaluate threats and vulnerabilities to
ascertain whether additional safeguards are neededØ
Assess changes in the system, its environment,
and operational needs that could affect the accreditationØ
Ensure that certification is accomplished on
each AISØ
Review AIS test plansØ
Conduct periodic testing of the security posture
of the AISØ
Ensure configuration management (CM) for
security-relevant AIS software, hardware, and firmware are properly documented.Ø
Ensure that system recovery processes are
monitored to ensure that security features and procedures are properly restoredØ
Ensure all AIS security-related documentation is
current and accessible to properly authorized individualsØ
Ensure that system security requirements are
addressed during all phases of the system life cycleØ
Participate in self-inspections; identify
security discrepancies and report security incidentsØ
Coordinate all technical security issues outside of area of expertise or
responsibility with SSEØ
Provide expert research and analysis in support
of expanding programs and area of responsibilityØ
Perform file transfers between local systems to
storage devices -
Information Assurance Specialist-Hanscom AFB, MA
February 2, 2012Ø
Perform oversight of the development,
implementation and evaluation of information system security program policy;
special emphasis placed upon integration of existing SAP network
infrastructuresØ
Perform analysis of network security, based upon
the DCID 6/3, DITSCAP, DIACAP, and NISPOM Chapter 8 certification and
accreditation process; advise customer on IT certification and accreditation
issuesØ
Perform risk assessments and make
recommendations to customersØ
Advise government program managers on security
testing methodologies and processesØ
Evaluate certification documentation and provide
written recommendations for accreditation to government PM’sØ
Periodically reviews system security to
accommodate changes to policy or technologyØ
Evaluate IT threats and vulnerabilities to
determine whether additional safeguards are neededØ
When applicable, ensure that certification is
accomplished for each information systemØ
Develop and maintain a formal Information
Systems Security ProgramØ
Develop, implement, provide guidance, and
enforce AIS security policies and proceduresØ
Ensure that all ISSOs, network administrators,
and other AIS personnel receive the necessary technical and security training
to carry out their dutiesØ
Develop, review, endorse, and recommend action
by the designated approval authority (DAA) of system certification
documentationØ
Ensure approved procedures are in place for
clearing, purging, declassifying, and releasing system memory, media, and
outputØ
Conduct certification tests that include
verification that the features and assurances required for each protection
level fare functionalØ
Maintain a repository for all system
certification/accreditation documentation and modificationsØ
Coordinate AIS security inspections, tests, and
reviewsØ
Develop policies and procedures for responding
to security incidents, and for investigating and reporting security violations
and incidentsØ
Ensure proper protection or corrective measures
have been taken when an incident or vulnerability has been discovered within a
systemØ
Ensure that data ownership and responsibilities
are established for each AIS, to include accountability, access rights, and
special handling requirementsØ
Ensure development and implementation of an
information security education, training, and awareness program, to include
attending, monitoring, and presenting local AIS security training.Ø
Ensure that security testing and evaluations are
completed and documentedØ
Evaluate threats and vulnerabilities to
ascertain whether additional safeguards are neededØ
Assess changes in the system, its environment,
and operational needs that could affect the accreditationØ
Ensure that certification is accomplished on
each AISØ
Review AIS test plansØ
Conduct periodic testing of the security posture
of the AISØ
Ensure configuration management (CM) for
security-relevant AIS software, hardware, and firmware are properly documented.Ø
Ensure that system recovery processes are
monitored to ensure that security features and procedures are properly restoredØ
Ensure all AIS security-related documentation is
current and accessible to properly authorized individualsØ
Ensure that system security requirements are
addressed during all phases of the system life cycleØ
Participate in self-inspections; identify
security discrepancies and report security incidentsØ
Coordinate all technical security issues outside of area of expertise or
responsibility with SSEØ
Provide expert research and analysis in support
of expanding programs and area of responsibilityØ
Perform file transfers between local systems to
storage devices -
Information Assurance Specialist-Eglin AFB, FL
February 2, 2012Ø
Perform oversight of the development,
implementation and evaluation of information system security program policy;
special emphasis placed upon integration of existing SAP network
infrastructuresØ
Perform analysis of network security, based upon
the DCID 6/3, DITSCAP, DIACAP, and NISPOM Chapter 8 certification and
accreditation process; advise customer on IT certification and accreditation
issuesØ
Perform risk assessments and make
recommendations to customersØ
Advise government program managers on security
testing methodologies and processesØ
Evaluate certification documentation and provide
written recommendations for accreditation to government PM’sØ
Periodically reviews system security to
accommodate changes to policy or technologyØ
Evaluate IT threats and vulnerabilities to
determine whether additional safeguards are neededØ
When applicable, ensure that certification is
accomplished for each information systemØ
Develop and maintain a formal Information
Systems Security ProgramØ
Develop, implement, provide guidance, and
enforce AIS security policies and proceduresØ
Ensure that all ISSOs, network administrators,
and other AIS personnel receive the necessary technical and security training
to carry out their dutiesØ
Develop, review, endorse, and recommend action
by the designated approval authority (DAA) of system certification
documentationØ
Ensure approved procedures are in place for
clearing, purging, declassifying, and releasing system memory, media, and
outputØ
Conduct certification tests that include
verification that the features and assurances required for each protection
level fare functionalØ
Maintain a repository for all system
certification/accreditation documentation and modificationsØ
Coordinate AIS security inspections, tests, and
reviewsØ
Develop policies and procedures for responding
to security incidents, and for investigating and reporting security violations
and incidentsØ
Ensure proper protection or corrective measures
have been taken when an incident or vulnerability has been discovered within a
systemØ
Ensure that data ownership and responsibilities
are established for each AIS, to include accountability, access rights, and
special handling requirementsØ
Ensure development and implementation of an
information security education, training, and awareness program, to include
attending, monitoring, and presenting local AIS security training.Ø
Ensure that security testing and evaluations are
completed and documentedØ
Evaluate threats and vulnerabilities to
ascertain whether additional safeguards are neededØ
Assess changes in the system, its environment,
and operational needs that could affect the accreditationØ
Ensure that certification is accomplished on
each AISØ
Review AIS test plansØ
Conduct periodic testing of the security posture
of the AISØ
Ensure configuration management (CM) for
security-relevant AIS software, hardware, and firmware are properly documented.Ø
Ensure that system recovery processes are
monitored to ensure that security features and procedures are properly restoredØ
Ensure all AIS security-related documentation is
current and accessible to properly authorized individualsØ
Ensure that system security requirements are
addressed during all phases of the system life cycleØ
Participate in self-inspections; identify
security discrepancies and report security incidentsØ
Coordinate all technical security issues outside of area of expertise or
responsibility with SSEØ
Provide expert research and analysis in support
of expanding programs and area of responsibilityØ
Perform file transfers between local systems to
storage devices -
Information Assurance Specialist-Palmdale, CA
February 2, 2012Ø
Perform oversight of the development,
implementation and evaluation of information system security program policy;
special emphasis placed upon integration of existing SAP network
infrastructuresØ
Perform analysis of network security, based upon
the DCID 6/3, DITSCAP, DIACAP, and NISPOM Chapter 8 certification and
accreditation process; advise customer on IT certification and accreditation
issuesØ
Perform risk assessments and make
recommendations to customersØ
Advise government program managers on security
testing methodologies and processesØ
Evaluate certification documentation and provide
written recommendations for accreditation to government PM’sØ
Periodically reviews system security to
accommodate changes to policy or technologyØ
Evaluate IT threats and vulnerabilities to
determine whether additional safeguards are neededØ
When applicable, ensure that certification is
accomplished for each information systemØ
Develop and maintain a formal Information
Systems Security ProgramØ
Develop, implement, provide guidance, and
enforce AIS security policies and proceduresØ
Ensure that all ISSOs, network administrators,
and other AIS personnel receive the necessary technical and security training
to carry out their dutiesØ
Develop, review, endorse, and recommend action
by the designated approval authority (DAA) of system certification
documentationØ
Ensure approved procedures are in place for
clearing, purging, declassifying, and releasing system memory, media, and
outputØ
Conduct certification tests that include
verification that the features and assurances required for each protection
level fare functionalØ
Maintain a repository for all system
certification/accreditation documentation and modificationsØ
Coordinate AIS security inspections, tests, and
reviewsØ
Develop policies and procedures for responding
to security incidents, and for investigating and reporting security violations
and incidentsØ
Ensure proper protection or corrective measures
have been taken when an incident or vulnerability has been discovered within a
systemØ
Ensure that data ownership and responsibilities
are established for each AIS, to include accountability, access rights, and
special handling requirementsØ
Ensure development and implementation of an
information security education, training, and awareness program, to include
attending, monitoring, and presenting local AIS security training.Ø
Ensure that security testing and evaluations are
completed and documentedØ
Evaluate threats and vulnerabilities to
ascertain whether additional safeguards are neededØ
Assess changes in the system, its environment,
and operational needs that could affect the accreditationØ
Ensure that certification is accomplished on
each AISØ
Review AIS test plansØ
Conduct periodic testing of the security posture
of the AISØ
Ensure configuration management (CM) for
security-relevant AIS software, hardware, and firmware are properly documented.Ø
Ensure that system recovery processes are
monitored to ensure that security features and procedures are properly restoredØ
Ensure all AIS security-related documentation is
current and accessible to properly authorized individualsØ
Ensure that system security requirements are
addressed during all phases of the system life cycleØ
Participate in self-inspections; identify
security discrepancies and report security incidentsØ
Coordinate all technical security issues outside of area of expertise or
responsibility with SSEØ
Provide expert research and analysis in support
of expanding programs and area of responsibilityØ
Perform file transfers between local systems to
storage devices -
Information Assurance Specialist-Wright-Patterson AFB, OH
February 2, 2012Ø
Perform oversight of the development,
implementation and evaluation of information system security program policy;
special emphasis placed upon integration of existing SAP network
infrastructuresØ
Perform analysis of network security, based upon
the DCID 6/3, DITSCAP, DIACAP, and NISPOM Chapter 8 certification and
accreditation process; advise customer on IT certification and accreditation
issuesØ
Perform risk assessments and make
recommendations to customersØ
Advise government program managers on security
testing methodologies and processesØ
Evaluate certification documentation and provide
written recommendations for accreditation to government PM’sØ
Periodically reviews system security to
accommodate changes to policy or technologyØ
Evaluate IT threats and vulnerabilities to
determine whether additional safeguards are neededØ
When applicable, ensure that certification is
accomplished for each information systemØ
Develop and maintain a formal Information
Systems Security ProgramØ
Develop, implement, provide guidance, and
enforce AIS security policies and proceduresØ
Ensure that all ISSOs, network administrators,
and other AIS personnel receive the necessary technical and security training
to carry out their dutiesØ
Develop, review, endorse, and recommend action
by the designated approval authority (DAA) of system certification
documentationØ
Ensure approved procedures are in place for
clearing, purging, declassifying, and releasing system memory, media, and
outputØ
Conduct certification tests that include
verification that the features and assurances required for each protection
level fare functionalØ
Maintain a repository for all system
certification/accreditation documentation and modificationsØ
Coordinate AIS security inspections, tests, and
reviewsØ
Develop policies and procedures for responding
to security incidents, and for investigating and reporting security violations
and incidentsØ
Ensure proper protection or corrective measures
have been taken when an incident or vulnerability has been discovered within a
systemØ
Ensure that data ownership and responsibilities
are established for each AIS, to include accountability, access rights, and
special handling requirementsØ
Ensure development and implementation of an
information security education, training, and awareness program, to include
attending, monitoring, and presenting local AIS security training.Ø
Ensure that security testing and evaluations are
completed and documentedØ
Evaluate threats and vulnerabilities to
ascertain whether additional safeguards are neededØ
Assess changes in the system, its environment,
and operational needs that could affect the accreditationØ
Ensure that certification is accomplished on
each AISØ
Review AIS test plansØ
Conduct periodic testing of the security posture
of the AISØ
Ensure configuration management (CM) for
security-relevant AIS software, hardware, and firmware are properly documented.Ø
Ensure that system recovery processes are
monitored to ensure that security features and procedures are properly restoredØ
Ensure all AIS security-related documentation is
current and accessible to properly authorized individualsØ
Ensure that system security requirements are
addressed during all phases of the system life cycleØ
Participate in self-inspections; identify
security discrepancies and report security incidentsØ
Coordinate all technical security issues outside of area of expertise or
responsibility with SSEØ
Provide expert research and analysis in support
of expanding programs and area of responsibilityØ
Perform file transfers between local systems to
storage devices -
Senior System Engineer (SSE)
January 25, 2012Description: The SME shall determine, teach, and
assess appropriate Tactics, Techniques, and Procedures (TTP’s) to conduct
operations (802.1x, GSM, CDMA, and emerging wireless technologies) in a SOF
environment to SOF SIGINT personnel. The SSE shall conduct course instruction
and enforce student academic standards for both urban and austere training
scenarios. SSE’s shall also assess individual capabilities and recommend
certification of students preparing to conduct real-world and combat Area of
Responsibility (AOR) missions based on standards set forth by the government.Requirements: Shall have a minimum of 5 years of
experience in SOF SIGINT operations. No
training experience required for this position. Hands-on expertise and
experience with SOF tactical SIGINT beyond the FOB operations in theatre.
Position requires a full understanding of special areas of tactical SIGINT to
include 802.1x, tactical network analysis, Linux, signals survey, signals
mapping, geolocation, and target analysis. Understands operations,
capabilities, limitations, and security principles of SIGINT systems. CONUS
travel may be required up to 20%.Clearance Requirement:
TS/SCI (NSA
approved CCA, prior to ability to begin work)Primary Location:
Maryland
-
Expeditionary SOF SIGINT Subject Matter Expert (SME)
January 25, 2012Description: The SME shall determine, teach, and
assess appropriate Tactics, Techniques, and Procedures (TTP’s) to conduct
operations (802.1x, GSM, CDMA, and emerging wireless technologies) in a SOF
environment to SOF SIGINT personnel. SME’s shall also assess individual
capabilities and recommend certifications of students preparing to conduct
real-world and combat Area of Responsibility (AOR) missions based on standards
set forth by government. The SME may also be required to travel to CONUS,
OCONUS, and/or hostile locations to provide training sessions, feedback,
re-evaluations, and supplemental support in relation to the training
curriculum.Requirements: Shall have a minimum of 8 years of
experience conducting SIGINT operations in a SOF environment, and 2 years teaching
or leading SOF personnel in comprehensive scenario-based mobile SIGINT
operations in a live environment. Position requires a full understanding of
special areas of tactical SIGINT to include 802.1x, tactical network analysis,
Linux, signals survey, signals mapping, geolocation, and target analysis. CONUS
travel may be required up to 20%.Clearance Requirement:
TS/SCI (NSA
approved CCA, prior to ability to begin work)Primary Location:
Maryland
-
SCADA SME – Winchester, VA
January 4, 2012SCADA Expert will draw up his/her working knowledge of SCADA communications;
MODBUS, LON, OPC ,etc and Energy Management Control Systems (EMCS),
Building Automation Systems (BAS) particularly in Honeywell, Johnson Controls and Tridium
Control systems to provide recommendations on SCADA security, familiarity with and ensure
proper implementation of Government patches.In addition to deep familiarity with SCADA, must be familiar with:
Operating systems: Windows desktop and server OS, Linux and Unix
Networks (including protocols and standards); LAN, WAN, Wired and wireless Ethernet
Hardware; desktop, servers, PLC
Software languages; Java, C+
Databases; SQL, mySQL
Graphical user interface (GUI) design; HTML
Troubleshooting; Desktop, Network, Servers, PLC
Business knowledge; Business lines and processes
SCADA security; Physical, systems and network
Soft skills (communications – oral and written — leadership.Requires a minimum of 5 years relevant experience with SCADA.
Candidates will be subject to a government background investigation and must meet eligibility
criteria for access to classified information. Must meet DCID 6/4 standards. Current or
within scope SSBI required.AN EQUAL OPPORTUNITY EMPLOYER
All employment decisions are made without regard to race, color, religion, sex, sexual
orientation, national origin, age, creed, ancestry, marital status, non-job-related handicap or
disability, veteran status, or any other legally protected status. -
Subject Matter Expert – GSM
December 2, 2011The SME shall determine, teach, and assess appropriate Tactics, Techniques, and Procedures (TTP’s) to conduct operations (802.1x, GSM, CDMA, and emerging wireless technologies) in a SOF environment to SOF SIGINT personnel. SME’s shall also assess individual capabilities and recommend certifications of students preparing to conduct real-world and combat Area of Responsibility (AOR) missions based on standards set forth by government. The SME may also be required to travel to CONUS, OCONUS, and/or hostile locations to provide training sessions, feedback, re-evaluations, and supplemental support in relation to the training curriculum.
Requirements: Shall have a minimum of 8 years of experience conducting SIGINT operations in a SOF environment, and 2 years teaching or leading SOF personnel in comprehensive scenario-based mobile SIGINT operations in a live environment. Position requires a full understanding of special areas of tactical SIGINT to include 802.1x, tactical network analysis, Linux, signals survey, signals mapping, geolocation, and target analysis. CONUS travel may be required up to 20%.
Clearance Requirement: TS/SCI (NSA approved CCA, prior to ability to begin work)
Primary Location: Maryland -
Cyber Threat Analyst
December 2, 2011Cyber Threat Analyst
Security Clearance: Top Secret
Location: Charleston, SC
Summary:
The candidate shall provide support for the ongoing analysis of threats capable of impacting resources being serviced by the NSOC CND SP activity based on review of programmatic, technical, and IA Certification and Accreditation documentation and daily review of open source / unclassified and classified threat warnings and bulletins.
Overview:
- Review IA certification and accreditation documentation, programmatic, and technical documentation for the NSOC and Network Protection Suites
- Review IA certification and accreditation documentation, programmatic, and technical documentation for each system or program of record serviced by the NSOC CND SP
- Review the SOPs and CND SP programmatic documentation for the NSOC
- Perform daily review of cyber threat warnings, bulletins, alerts, and incident reporting documentation and databases produced by the Director of National Intelligence (DNI), National Intelligence Counsel (NIC), Defense Intelligence Agency (DIA), National Security Agency (NSA), United States Strategic Command (USSTRATCOM), Joint Task Force Global Network Operations (JTF-GNO), military service cyber intelligence support activities, Central Intelligence Agency, Department of Homeland Security, US Computer Emergency Response Team, and coalition and allied partners.
- Perform daily review of open source / unclassified sources of cyber threat warnings, vulnerability announcements, from the DoD Information Assurance Vulnerability Management program, National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD), SANS Institute and Internet Storm Center, security vendor advisories, and other cyber security new media sources for information that may impact operations
- Perform analysis and identify threats, vulnerabilities, or change to the level of risk associated with continued operations. Assess the level of threat associated with the circumstances and provide reporting to CND SP management. Reporting shall include specific information and sources used in the analysis, summary information, threat content, and recommendations for managing, mitigating, or avoiding the associated risk associated with the threat.
- Communicate to CND SP subscribers the results of the threat analysis and the associated reporting. Assist CND SP subscribers with comprehending the reporting, perform supplemental research, and guidance on implementing the prescribed risk mitigation strategy.
- Coordinate and deconflict threat analysis activities and reporting with existing NSOC IAVM program infrastructure.
- Coordinate the results of threat analysis with the current network monitoring resources for the creation of user defined signatures and other alerting capabilities as necessary to manage risks
- Obtain ‘known-bad’ file hash value lists of malicious activity from classified and open source resources and coordinate with NSOC HBSS and network monitoring resources the incorporation of this new data for continued monitoring
- Mentor junior cyber threat analysts and assist with construction of a robust cyber threat analysis capability in the NSOC
- Provide on-call support for mission critical activities during non-core business hours consistent with CND SP requirements
Obtain and maintain compliance with applicable DoD 8570.01-M requirements. Cyber threat analyst support requires at least IAT Level II and CND Analyst certifications.
-
Intrusion Defense System (IDS) Analyst
December 2, 2011Security Clearance: Top Secret (S) Required
Location: Charleston, SC
Summary:
The candidate will provide network intrusion detection and monitoring, correlation analysis, and support for the fielded CND analysis suite for subscribers of the SPAWAR Network Security Operations Center (NSOC) Computer Network Defense Service Provider (CND SP) and other supported components. Also assist with the preparation of NSOC CND SP accreditation application to the DoD CND Chief Architect and execute prescribed CND SP duties while maintaining associated support for current components. This includes executing, drafting, and editing standard operating procedure (SOP) documentation. Provide coordination of significant incidents with JTF-GNO and supported entities to ensure proper analysis is performed and timely and accurate reporting of the incident is affected. Ensure incidents are properly entered into appropriated automated reporting systems.
Overview:
- Provide, develop, and maintain a network forensic analysis capability to enhance response to, support of, and investigation into significant incidents in order to provide a clearer view of the exploits, vulnerabilities, and tactics, techniques, and procedures (TTPs) used to cause the incident.
- Provide on-call support for intrusion detection activities during non-core business hours consistent with CND SP requirements.
-
Sr. Network Engineer
December 1, 2011Sr. Network Engineer
The Network Engineer will participate as part of a team to conduct vulnerability assessments of enterprise network systems. Position requires a TS/SCI and 25% travel both CONUS and OCONUS (Non-Austere Locations). Work location is Herndon, VA.
Roles and Responsibilities include, but are not limited to:
1) Network Engineer will support the Network Assessment Team with Network and Security Configuration Analysis as a component of the Enterprise Vulnerability Assessment Program
2) Providing network engineering services for a USG customer
3) Gathering configurations from network devices such as routers, switches and firewalls
4) Performing network infrastructure vulnerability analysis based on identified configuration weaknesses
5) Analyzing ACLs and rulesets to determine trust relationships and traffic flow for possible security compromises
6) Developing detailed network diagrams based on collected configurations
7) Providing other duties as assigned/required for mission accomplishment
Minimum Qualifications:
1) Active TS/SCI clearance.
2) Bachelor’s degree and 5 years applicable experience or 8 years experience in lieu of degree
3) In depth knowledge of the network OSI model with emphasis on Layers 3 & 4
4) Knowledge of Layer 2 Spanning Tree Protocol (STP) and Layer 3 static/dynamic routing protocols (RIP, EIGRP, OSPF) and Cisco Virtual Routing and Forwarding (VRF) and/or Juniper Routing Instances
5) Ability to analyze configurations from Cisco, Juniper and other well-known network device manufacturers
6) Proficient with MS® Office suite of products
7) Superior writing and speaking communication skills
Desired Qualifications:
1) Security+
2) CISSP
3) Cisco Certification (CCNA, CCNP, CCSP)
4) 2+ years experience in networks engineered with multiple security zones
-
Incident Response (IR) Analyst – Computer Incident Response Team (CIRT)
December 1, 2011Client / Program Requirement:
Incident Response (IR) Analyst will provide assistance to client managers in review and evaluation of cyber security threats identified by the agency using personal knowledge of government IT policy, standards, and experience in implementation, administration and operation of various IT security monitoring technologies. The candidate will assist client management in developing, maintain, and communicating requirements for IT Security Operations, and Monitoring within the CIRTCandidate Requirements:
- Excellent writing skills, and a proven capability to document procedures used in IT Security Operations
- Minimum of five (5) years of experience in IT administration and/or security operations
- Minimum of four (4) years of experience in Computer Security
- Incident Response Team (CSIRT), Network Intrusion Detection
- Systems (NIDS), Host Intrusion Detection Systems (HIDS), Vulnerability Scanning Systems (VSS), and Security Information Management Systems (SIMS)
- Minimum of (2) years of experience in each of the following:
- Procedure development and documentation of IT Security Operations
- Analysis and report development
- Operation and tuning of NIDS, HIDS and SIMS (prefer ArcSight)
- Cyber Forensics
Education:
- College degree in IT or related field
- Industry certification is desired (CISSP and/or CEH)
Clearance:
Citizenship: U.S. Citizens only
Clearance: Secret with current SSBI (less than 5 years old)
Polygraph: NoLocation:
Silver Spring, Md
-
Information Assurance Vulnerability Manager (IAVM)
November 8, 2011Experience Required:
- Risk Management skills; the ability to take technical facts, perform some analysis, creatively identify means of introducing technical or policy adjustments to overcome the presence of vulnerabilities (specifically introduce IDS/IPS signatures or define a new audit process), describe exactly how mitigating circumstances have been introduced, and be able to defend that argument to a technophobe grandmother.
- Above average skill with Vulnerability Management System (VMS); VMS is the tool in which MHS IAVM is organized and we need to establish an entirely new architecture for our new MHS Intranet. Ability to run reports and familiar with VMS roles and responsibilities is needed for what amounts to a VMS Architect type of need.
- Retina skills. Able to performing scans, collect results and enter those results in VMS, running associated reports, and some skill with the REM database and SQL. Some O&M skills associated with keeping a Retina infrastructure up and running helpful.
- HBSS/ePO related skills. Work in some capacity with HBSS is helpful.
Key Skills:
- Security or product certifications – Retina (required), Nessus (preferred), and Gold Disk Scans
- Knowledge of TCP/IP
Education:
- Bachelors degree plus 5 years of applicable experience or 8 years of experience in lieu of a degree
Clearance:
Citizenship: U.S. Citizens only
Clearance: Secret with current SSBI (less than 5 years old)
Polygraph: NoLocation:
Charleston, SC
-
Junior Network Engineer
November 8, 2011Dependable Global Solutions (DGS) is seeking a Junior Network Engineer for an Intelligence Community customer in the Chantilly area. Responsible for, but are not limited to: 1) gathering network and host information and performing a vulnerability analysis on the entire system 2) identifying configuration weaknesses on routers, switches, firewalls and other network devices 3) performing physical site surveys 4) developing detailed network diagrams 5) Analyze ACL and firewall rulesets for security related issues 6) analyze network data flow for inherent trust relationships which could lead to compromise 7) provide other support as needed in order to complete the mission. May perform other duties as assigned.
Experience Required:
- (Some/All) experience in analyzing configurations from Juniper, Symantec, Cisco, Foundry, Secure Computing, Extreme Networks, ISS, UNIX, LINUX, Microsoft and Network Associates
- Knowledge of Spanning tree protocol, static routing protocols, and dynamic routing protocols (OSPF, EIGRP, RIP)
- Knowledge of NSA SNAC, TCP/IP
- Demonstrated project engineering experience.
- Expertise in a service provider network with multiple security zones.
Education:
- Bachelors degree or 5 years of experience in lieu of a degree
- Cisco Certifications (CCNA, CCNP, CCSP)
Clearance:
Citizenship: U.S. Citizens only
Clearance: Top Secret with current SSBI (less than 5 years old)
Polygraph: Yes (Current CI)Location:
Chantilly, Va
Travel:
Yes; 30% – all travel is planned/scheduled in advance
-
Network Engineer
November 8, 2011Dependable Global Solutions (DGS) is seeking a Network Engineer for an Intelligence Community customer in the Chantilly area. Responsible for, but are not limited to: 1) gathering network and host information and performing a vulnerability analysis on the entire system 2) identifying configuration weaknesses on routers, switches, firewalls and other network devices 3) performing physical site surveys 4) developing detailed network diagrams 5) Analyze ACL and firewall rulesets for security related issues 6) analyze network data flow for inherent trust relationships which could lead to compromise 7) provide other support as needed in order to complete the mission. May perform other duties as assigned.
Experience Required:
- (Some/All) experience in analyzing configurations from Juniper, Symantec, Cisco, Foundry, Secure Computing, Extreme Networks, ISS, UNIX, LINUX, Microsoft and Network Associates
- Knowledge of Spanning tree protocol, static routing protocols, and dynamic routing protocols (OSPF, EIGRP, RIP)
- Knowledge of NSA SNAC, TCP/IP
- Demonstrated project engineering experience.
- Expertise in a service provider network with multiple security zones.
Education:
- Bachelors degree plus 5 years of applicable experience or 9 years of experience in lieu of a degree
- Cisco Certifications (CCNA, CCNP, CCSP)
Clearance:
Citizenship: U.S. Citizens only
Clearance: Top Secret with current SSBI (less than 5 years old)
Polygraph: Yes (Current CI)Location:
Chantilly, Va
Travel:
Yes; 30% – all travel is planned/scheduled in advance
-
Wireless Intrusion Detection Systems (IDS) Engineer/Administrator
November 8, 2011Client/Program Requirement:
Address security issues ranging from misconfigured wireless access points (WAPs), session hijacking, Denial of Service (DoS), and TCP/IP-based attacks native to wired and wireless networks.
Strong understanding and familiarity of the standard 802.11 encryption method, Wired Equivalent Privacy (WEP)
Ability to configure and deploy Intrusion Detection Systems (IDS); identify computer system and network intrusions and misuse by gathering and analyzing data on wireless networks. Configure devises to monitor and analyze user and system activities, recognize patterns of known attacks, identify abnormal network activity, and detect policy violations for WLANs.
Key Skills:
- Airdefense, RogueWatch, Realsecure,
- Linux OS
- Open source tools (e.g Snort-Wireless, WIDZ)
Education:
- College degree in IT or related field
- Industry certification is desired (CISSP and/or CEH)
Clearance:
Citizenship: U.S. Citizens only
Clearance: Top Secret with current SSBI (less than 5 years old)
Polygraph: No