Education:BA/BS Clearance: TS
Industry: Information Technology (Computers)
Job Type: Professional
Experience Level: Senior Level (> 11 years)
Job Responsibilities:
Provides security engineering design, implementation and test support in all aspects of Information Assurance and Information Security (InfoSec) Engineering at all stages of the Systems Development Life Cycle (SDLC) process.
Additional responsibilities:
Validates system security requirements definition and analysis.
Assesses and mitigates system security threats/risks throughout the program life cycle.
Verifies security requirements
Determines/analyzes and decomposes security requirements at the level of detail that can be implemented and tested.
Reviews and monitors security designs in hardware, software, data, and procedures.
Performs system certification and accreditation planning and testing and liaison activities; supports secure systems operations and maintenance
Perform security engineering analysis, risk and vulnerability assessment, etc.
Monitor and analyze security functional tests.
Familiarity with C&A documentation such as SSP, SCONOPS, ST&E plans and reports, etc.
Requirements:
BS Degree in a related discipline, or equivalent experience combined with 2 years of professional experience; or no experience w/related Masters Degree.
Knowledge of information security engineering and design concepts and principles.
Well versed in information security standards, policies and practices - NIST, DOD, DCID, etc. Must be able to apply these principles to a project that is in the development stage (i.e. ensure that information security aspects are considered during the development life cycle).
Ability to research information security issues as required be an authority on the subject.
Must be a team player with "can do" attitude.
Must be able to work independently to resolve issues.
Ability to provide guidance and liaise among the various program teams - requirements, architecture and design, development, testing, customer.
Familiarity with web-based system security issues.
Excellent writing and oral presentation skills.
Desired skills: Knowledge of PKI; Familiarity with SOA and XML security issues.
|