This position supports Raytheon's DOMino contract, a single-award IDIQ worth over $1 billion. This contract delivers full lifecycle development and sustainment for the Department of Homeland Security’s (DHS) National Cybersecurity Protection System (NCPS). The NCPS assists more than 100 federal civilian government agencies with the protection of their networks against advanced cyber threats. Under this contract, Raytheon will support the government in the design, development, operations and maintenance services for the NCPS. Raytheon will build the mission critical cybersecurity solutions that will enable the timely dissemination of threat warnings and improve information sharing across DHS's stakeholder community.
The Information System Security Analyst applies current technologies to the design, development, evaluation and integration of computer information systems and networks to maintain system security. May work with commercial computer product vendors in the design and evaluation of state-of-the-art secure COTS applications, operating systems, networks and database products and technology. Provides security engineering and integration services to internal customers. Involved in a wide range of issues including secure architectures, secure electronic data traffic, network security, information security and privacy. Uses encryption technology, penetration, risk management and vulnerability analysis of various security technologies and information technology security research. Develops security systems for any manual or automated systems environments. Responsible for ensuring the protection of company data against unauthorized disclosure, accidental or intentional loss of data, or unauthorized modification. May prepare security reports.
•Must be a U.S. Citizen
•A current Top Secret clearance and must be able to obtain a TS/SCI clearance. Must be able to obtain DHS suitability prior to starting employment.
•Strong written and verbal communication skills
•Ability to convey system risks/assessments/vulnerabilities to all technical levels to include administrative staff, management staff and subject matter expert technical staff
•Validate security posture for the program to ensure information systems security policies, standards, and procedures are established and followed
•Assist with the management of security aspects of the information system and perform day-to-day security risk analysis on the system
•Evaluate security posture to ensure security requirements for processing in a unclassified and classified information are being maintained
•Perform vulnerability/risk assessment analysis to support certification and accreditation
•Prepare and review documentation to include System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, etc. This includes System Test and Evaluation (ST&E) and Pre and Post Deployment Security, Vulnerability and Risk (PDSV) assessments of new technological deployments in the test, preproduction and production environments.
•Experience and/or familiarity with NIST and DHS Authorization and Accreditation (A&A)
•Experience and/or familiarity with the following network protection devices: firewalls, intrusion detection and prevention systems (IDS/IPS), log analysis, malware analysis, network traffic flow and packet analysis
•Experience and/or familiarity with Secure Technical Implementation Guides (STIGs), ISVM, DCID 6/3, Federal Information Security Management Act (FISMA) and other tools using NIST Framework
•Experience with operation and maintenance of Information Assurance Tools to including configuration and maintenance
•Acts as SME for Windows Platforms (Knowledge of LINUX/Network/Databases would be beneficial)
•Perform analysis on large data sets
•Provide security services for Authorization and Accreditation (A&A) requirements, including developing and maintaining information assurance documentation for all network components
•Support continuous monitoring and FISMA compliance
•Conduct Information Assurance Vulnerability scanning to include Adhoc and specialized request scans and assist team members in to reconcile results, and report all findings
•Understand and utilization of SPLUNK would be beneficial
•Understanding and utilization of HBSS/McAfee ePO to analyse risk assessments within the application and network
•Experience with the following:?Acunetix WVX
?App Detective Pro
?Burp Suite Professional
?Core Impact Pro
?HexRay and IdaPro
?IBM Appscan Source
?Microfocus HP WebInspect
Desired Certification(s): CISSP, Security+, Network+, Cisco Certified Network Professional (CCNP), Cisco Certified Security Professional (CCSP) or similar certification
Required Education (including Major):
• Eight years of cyber security or similar experience with a Bachelor's degree in Information Security, Cyber Engineering, Engineering or a related discipline is required
• A Master’s degree in a related discipline may be substituted for two (2) years of experience
• Relevant experience may be considered in lieu of a degree.
This position requires a U.S. Person who is eligible to obtain any required Export Authorization.
Raytheon is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, age, color, religion, creed, sex, sexual orientation, gender identity, national origin, disability, or protected Veteran status.