What are the responsibilities and job description for the Information Security Engineer (Senior) position at ECS Federal, LLC?
Want to make an application Make sure your CV is up to date, then read the following job specs carefully before applying.
ECS is seeking an Information Security Engineer (Senior) to work in our Morgantown, WV office. Please Note : This position is contingent upon [contract award].
ECS is seeking a qualified Information Security Engineer (Senior) to support transformative science and technology solutions for the Department of Energy.
This is a unique opportunity to join a rapidly growing company and contribute to the development and maintenance of an enterprise-wide cybersecurity framework.
Roles and Responsibilities :
- Review and update existing information security policy, standards, and procedures based on federal and departmental regulations.
- Perform independent security and privacy control assessments in support of Security Assessment & Authorization (SA&A).
- Conduct assessments of existing and new FISMA systems, including subsystems in the respective system boundary, and communicate the results and potential implications of identified control weaknesses.
- Review and analyze Assessment & Authorization (A&A) packages to include System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Back-up Standard Operating Procedures (SOP), Incident Response Plans (IRP), Configuration Management Plans (CMP), Hardware / Software lists, Network Diagrams, Data Flows, System Change Requests / Proposals, Vulnerability scan reports, test reports, and Plan of Actions & Milestones (POA&Ms) for completeness, accuracy, and document effectiveness of controls, plans, and procedures implementation.
- Create and maintain test cases for security assessment testing and perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server / instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.).
- Develop and execute a security and privacy assessment plan in accordance with NIST SP 800-53A, as amended, requirements, for each security assessment project. SA&A activities shall include support for RMF steps 4-6.
- Document and provide findings and recommendations that are concise, system-specific, and actionable.
- Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings.
Requirements :
J-18808-Ljbffr