What are the responsibilities and job description for the Information Security SME position at 4A-Consulting?
Job Details
Job Title: Information Security Engineer II
Experience Required: At Least 3 Years
Job Summary:
We are seeking a highly skilled and detail-oriented Information Security Engineer II to provide technical expertise in multilevel security (MLS) and contribute to the design, development, and implementation of security solutions across various levels of an organization. The candidate will assess security needs, evaluate existing security products, and support ongoing security programs to ensure the confidentiality, integrity, and availability of critical systems. This role requires strong analytical skills, problem-solving abilities, and effective communication with stakeholders, including Program Managers, Project Managers, contractor management, and government representatives.
Key Responsibilities:
< data-start="947" data-end="1001">1. Security Analysis & Technical Expertise:- Provide technical expertise in multilevel security (MLS) to safeguard sensitive and classified information.
- Assess an organization s mission, security goals, and infrastructure to identify vulnerabilities and risks.
- Research and evaluate security technologies, products, and emerging trends to enhance the security posture.
- Design, develop, and engineer multilevel security solutions to meet federal and organizational compliance requirements.
- Implement security controls, authentication mechanisms, and encryption protocols to ensure data protection.
- Configure, monitor, and maintain firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM solutions, and VPNs to enhance network security.
- Develop and maintain security policies, procedures, and technical documentation related to multilevel security initiatives.
- Support ongoing security programs by assessing risk, identifying vulnerabilities, and implementing mitigation strategies.
- Ensure compliance with government security frameworks such as NIST, RMF, FISMA, and other federal security policies.
- Conduct security assessments, penetration testing, and vulnerability scans to ensure MLS solutions meet regulatory standards.
- Assist in the implementation of Zero Trust Architecture (ZTA) and Identity & Access Management (IAM) best practices.
- Provide security awareness training and guidance to internal teams and end-users to ensure compliance with security policies.
- Prepare and deliver technical reports, security assessments, and compliance documentation for stakeholders.
- Communicate security requirements, risks, and mitigation strategies to technical and non-technical audiences, including senior leadership and government representatives.
Qualifications & Requirements:
< data-start="3043" data-end="3077">Education & Experience:- Bachelor s degree in Computer Science, Information Security, Cybersecurity, or a related field (or equivalent experience).
- Minimum of 3 years of experience in information security, cybersecurity, or multilevel security engineering.
- Strong understanding of multilevel security (MLS) principles, architectures, and implementations.
- Proficiency in security technologies, including firewalls, IDS/IPS, SIEM, endpoint security, and encryption mechanisms.
- Knowledge of security frameworks and compliance standards (NIST 800-53, RMF, FISMA, DoD STIGs, CIS benchmarks).
- Experience with secure network architecture, access control models, and authentication protocols.
- Ability to develop and implement risk-based security strategies and incident response plans.
- Familiarity with cloud security best practices (Azure, AWS, or Google Cloud) is a plus.
- Security (CompTIA)
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- GIAC Security Certifications (GSEC, GCIH, GCIA, etc.)
- Strong problem-solving and analytical skills to address security challenges.
- Excellent written and verbal communication skills to prepare technical reports and briefings.
- Ability to work independently and collaboratively in high-stakes, mission-critical environments.