Vacancy expired!
Please review the job details below.
Maxar is currently seeking an independent, creative, and driven Information Systems Security Engineer (ISSE) to join our big-data platform team in Herndon, VA. The office location for this position can be either our Herndon, VA or Ypsilanti, MI office. In this role, you will support a massive National Security platform supporting large-scale analytics on various customer data sources. If you are an ideal candidate, you are passionate about technology and have an ability to learn quickly. Why us?- We build advanced algorithms to gain analytic insights from a large range of open source and government data.
- We enable machine learning systems, automate workflow, and design and develop custom applications for unique national-security mission.
- We operate an end-to-end predictive analytics platform unlike any other within the U.S. Government.
- We provide training to expand your skills and challenges to develop them.
- Our clients' missions are vital to national security, so we are mission-first always.
- Our work environment is relaxed and business casual.
- At our core, we believe in our practice of social responsibility.
- Contribute to team success by building out and maintaining a large-scale customer hosted OpenStack platform, enabling massive analytics for platform users.
- Analyze existing and future systems, review security architectures, and develop engineering solutions that integrate information security requirements to proactively manage information protection.
- Engineer and deploy network defense countermeasures such as anti-virus, anti-spam, and intrusion detection and prevention system solutions.
- Analyze Information Assurance (IA) security events, including threat model development and resulting security risk analysis of systems.
- Review and assess information security events and logs via sophisticated security information and event manager.
- Must be a U.S. Citizen with a current/active TS/SCI and be willing and able to obtain a CI polygraph
- Bachelor's degree in Engineering, Computer Science, or related field. 4 additional years of experience may be substituted in lieu of a degree
- Minimum of 8 years of relevant experience
- One of the following certifications is required: Certified Cloud Security Professional | CCSP (ISC)2, AWS Certified Security - Specialty, AWS Security Fundamentals, CompTIA Cloud+, Azure Security Engineer Associate
- Experience with the following ACAS/Nessus/Tenable, Splunk, ServiceNow, SCAP Scans
- Knowledge and experience working with NIST 800-53, NIST 800-171 , IASD Rev C
- Demonstrated expertise in IC policy and able to interact at senior levels to ensure requirements are met while preserving the most feasible security posture
- Apply NIST, DOD, and other government standards, policies and regulations (e.g., NIST 800-137, NIST 800-53, 800-37 and 800-39)
- Must be able to manage security configs and communicate with others on the platform who are impacted by security decisions/direction
- Must be a highly motivated, self-driven team player who can interact well with others and advise/consult with other team members and customers on system security-related issues
- CompTIA Security+ certification or CISSP certification
- Demonstrated expertise in Cloud Security Architecture (specifically AWS service catalog), Implementation, Compliance, to include Authority to Operate (ATO) for Hybrid Cloud hosted infrastructure and applications
- Experience with reviewing security scan results and determining the risk and impact of vulnerabilities
- Demonstrated experience administering Linux and Windows operating systems in accordance with applicable security controls
- Skilled in managing complex regulatory and audit program, focusing on secured cloud capabilities, to include Authorization to Operate (ATO) in multi-tenant environment
- Experience configuring and securing systems to achieve compliance with Security requirements and determining the risk/impact of vulnerabilities (e.g., Nessus Scanner, Security Center, Splunk, McAfee EPo Server)
- Experience conducting Assessment and Authorization (A&A) using Risk Management Framework (RMF) activities; across all 6 steps.
- Experience producing accurate Configuration records through the life-cycle of the asset
- Develop weekly ConMon Reports to customer and capture metrics as security control assessments are conducted. Detail findings, provide status, recommended mitigations, metrics, and evidence.