Systems Engineer
Crimson Phoenix - herndon, VA
Apply NowJob Description
The work requires a healthy mix of technical and policy knowledge. The work also requires support in understanding and implementing standards like ICD 503, NIST Risk Management Framework, and cloud technologies. We need polished skills in information system security engineering, and security control assessment. Required Skills: Demonstrated experience with Kubernetes Demonstrated experience of general knowledge of cloud architecture and design Demonstrated experience facilitating TEMs with cloud service providers to review cloud service architectures Demonstrated experience maintaining assessment and authorization (A&A) packages across multiple services or systems in accordance with FIPS-199, NIST 800-53, and CNSS 1253 requirements Demonstrated experience designing, implementing, assessing or reviewing systems that utilize cloud technology with either Amazon Web Services, Oracle Cloud, Google Cloud, IBM Cloud, or Microsoft Azure cloud architecture Demonstrated experience with continuous monitoring requirements to include scan analysis for critical or high findings with common scan tools such as Rapid 7, Nessus, and Qualys Demonstrated experience with analyzing scans from common scan tools such as Rapid 7, Nessus, and Qualys Demonstrated experience utilizing or reviewing cross domain technology and common architecture designs Demonstrated experience consulting project teams on system architecture and security posture Demonstrated experience creating, monitoring, or closing system or service Plans Actions and Milestone items (POA&Ms) Demonstrated experience utilizing compliance tools to track assessment and authorization activities such as Xacta 360, Risk Vision, RSA Archer Demonstrated experience with the common control provider concept within the NIST Risk Management Framework and Security Control Frameworks Demonstrated experience with security control assessments to include working with SCAs and preparing security packages for SCAs Demonstrated experience conducting information system security engineering activities Desired Skills: Demonstrated experience using the Sponsors or IC element A&A process Demonstrated experience creating or reviewing A&A body of evidence documentation in a cloud security environment Demonstrated experience identifying, implementing, or reviewing appropriate information security controls Demonstrated experience working in Xacta 360
Created: 2024-11-12