Information System Security Engineer III
Core
Develop, maintain, and execute Risk Management Framework (RMF) processes to obtain and maintain security authorizations (IATT, ATO) for federal IT systems.
Role type
Senior IC Information System Security Engineer (RMF specialist)
Builds
Authorized and compliant federal information systems
Domain
Federal Government / Cybersecurity / Risk Management
Required skills
RMF process execution, vulnerability risk assessment, STIG/SRG implementation, security control testing, vulnerability scanning, patch management, configuration management, asset inventory management, compliance reporting
Preferred skills
N/A
Technologies
ACAS, SCAP, Ev STIG, eMASS, VRAM, Windows Server, Cisco networking hardware
Responsibilities
Develop and maintain system security plans, policies, and procedures; Execute security control testing and vulnerability assessments; Mitigate and remediate system vulnerabilities per STIG requirements; Deploy security updates and manage patching; Perform routine audits and maintain hardware/software inventories; Support change control and configuration management processes; Report compliance issues to management
Seniority
Senior, hands-on IC