Senior Information Security Engineer (A&A Engineer)

2018-07-23
ManTech (www.mantech.com)
Other

/yr

  full-time   employee   contract


Washington

United States

Entering ManTech?S 50th year, we hold the distinct honor of being named A ?Top 100 Global Technology Company? by Thomson Reuters. We have earned this and many other accolades over the years for our dedication to serving the missions of our nation?S most important customers: U.S. Intelligence, Defense and Federal Civilian agencies. All know us as A trusted partner offering best-in-class solutions in cyber, data collection & analytics, enterprise IT, and systems and software engineering tailored to meet their specific requirements.

Become an integral part of A diverse team in the Mission, Cyber and Intelligence Solutions (MCIS) Group. Currently, ManTech is seeking A motivated, mission oriented Information Security Assessor and Authorization, in the Washington, DC, with strong Customer relationships. At ManTech, you will help protect our national Security while working on innovative projects that offer opportunities for advancement.

The FSS Division provides cyber solutions to A wide range of Defense and Intelligence Community customers. This division consists of A team of technical leaders that deliver advanced technical solutions to government organizations. Our customers have high standards, are technically adept, and use our products daily to support their mission of protecting national Security. Our contributions to our customer?S success is driving our growth.

Responsibilities include:

  • The Information Security Assessor will be A key team member of A Security assessment team that will conduct monthly on-site IT Security assessments for A federal government client.
  • Conducting interviews with key client stakeholders to evaluate the current information Security practices.
  • Evaluate management, operational, and technical Security policies and procedures.
  • Reviewing Security policy and procedural documentation.
  • Reviewing network architecture diagrams and evaluating network access controls.
  • Reviewing system configuration data to identify Security weaknesses.
  • Developing recommendations for Security issues and vulnerabilities identified during assessments.
  • Communicating results to clients ranging from technical staff to executive management.
  • Proficient in using various network/vulnerability scanning tools (e.g. Nessus, NMAP). Candidate should not only be able to run scans but also interpret scan results and make appropriate recommendations.
  • Provide ongoing subject matter expert support for clients.
  • Conduct approximately 12-18 assessments each year across the United States.
  • 25% travel involved.

Qualifications Requirements:

  • Must possess six plus years related IT Security experience and must involve broad range of Security technologies to include wide area networks, host and network IDS, virtual private networks,remote access, Web Application Firewalls and Static Code Analysis.
  • Must possess 6 years of experience performing Security assessments and compliance assessments with NIST, PCI DSS, ISO 27001/27002, or other Security control frameworks.
  • Experience must includeanalyzing Security controls and developing solutions to Security problems.
  • Must have experienceanalyzing configuration files of firewalls, routers and switches.
  • Requires one of the following certifications: CAP, Security+, Network+, CEH, CCNA, CISM, GSEC, OSCP, CCSP, CSA+, GSNA, ISSA, ISSM etc.
  • Must possess CISSP, CEH or Security+
  • Expertisewith Nessus or similar scanning tool (Wireshark, NMAP, Metasploit, AppScan,Burp, Nessus, Nexpose, Nikto, Retina, WebInspect, Nipper, etc).
  • Technical Background (Server Administration, Networking or other technical discipline)

Preferred:

Experience conducting interviews with client teams ranging from technical IT staff to Senior executives.

  • Experience performing assessments of information Security policies and procedures.
  • Experience evaluatingthe following IT Security disciplines: continuity planning, contingencyplanning, disaster recovery planning, incident response, personnel Security, accessmanagement, Security awareness training.
  • Strong verbal and written communication skills are highly preferred.
  • Candidates may be asked to provide A writing sample.


Security Requirements:

Applicants selected will be subject to A government Security investigation and must meet eligibility requirements for access to classified information. Must be clearable.
Advertisement