Cyber Security Engineer II
Scientific Research Corporation · Portsmouth, Virginia, US
Description - Supporting the information system owner to complete security assessments, achieve system authorizations, continuous monitoring, and configurati...
Job description
Description: - Supporting the information system owner to complete security assessments, achieve system authorizations, continuous monitoring, and configuration management, through eMASS - Performing cybersecurity testing, analysis, and reporting by conducting the following: Assured Compliance Assessment Solution (ACAS) scans, Security Technical Implementation Guide (STIG) checks, port scanning, application code review, Risk Management Framework (RMF) control review, and Plan of Action and Milestone (POAM) - Providing in depth analysis on cybersecurity test results, remediation steps, and potential mitigating factor(s) - Assessing NSWC systems in accordance with Navy, NIST, DoD, and DISA guidance - Reporting security incidents in accordance with the Command's Incident Response Plan - Verifying configuration management and tracking security update implementation to the systems using existing automated tools - Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systemsEnsuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and...