Job Information
Themis Insight Sr. Information Systems Security Engineer in Linthicum Heights, Maryland
Themis Insight solves difficult business, IT, and analytic problems by addressing the whole problem – not just the symptoms – using interdisciplinary approaches that are both practical and innovative. We provide fresh alternatives to ordinary, mainstream consulting firms through small, highly skilled, and hand-picked teams that can meet clients' needs in any industry. Our broad interdisciplinary understanding allows us to provide the right solution, even if it is from outside the industry or traditionally defined problem space. We bring Public and Private, Civilian and Military expertise to every case.
We are hiring a Sr. Information Systems Security Engineer to work in Linthicum Heights, MD. Position location is subject to change based on central MD client's needs.
Required: TS/SCI with a Polygraph
The Information Systems Security Engineer (ISSE) shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations, and recommend mitigation strategies. Validates and verifies system security requirements definitions and analysis and establishes system security designs. Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing, and enclave environments to include those with multiple enclaves and with differing data protection/classification requirements. Builds IA into systems deployed to operational environments. Assists architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions. Supports the building of security architectures. Enforce the design and implementation of trusted relations among external systems and architectures. Assesses and mitigates system security threats/risks throughout the program life cycle. Contributes to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations. Reviews certification and accreditation (C&A) documentation, providing feedback on completeness and compliance of its content. Applies system security engineering expertise in one or more of the following to: system security design process; engineering life cycle; information domain; cross domain solutions; commercial off-the-shelf and government off-the-shelf cryptography; identification; authentication; and authorization; system integration; risk management; intrusion detection; contingency planning; incident handling; configuration control; change management; auditing; certification and accreditation process; principles of IA (confidentiality, integrity, non-repudiation, availability, and access control); and security testing. Support security authorization activities in compliance with NSA/CSS Information System Certification and Accreditation Process (NISCAP) and DoD Risk Management Framework (RMF), the NIST Risk Management Framework (RMF) process, and prescribed NSA/CSS business processes for security engineering.
The Level 2 Information Systems Security Engineer (ISSE) shall possess the following
capabilities:
Participate as a security engineering representative on engineering teams for the design, development, implementation and/or integration of secure networking, computing, and enclave environments
Participate as a security engineering representative on engineering teams for the design, development, implementation and/or integration of IA architectures, systems, or system components
Participate as the primary security engineering representative on engineering teams for the design, development, implementation, evaluation, and/or integration of secure networking, computing, and enclave environments
Apply knowledge of IA policy, procedures, and workforce structure to design, develop, and implement secure networking, computing, and enclave environments
Interact with the customer and other project team members
Participate as the primary security engineering representative on engineering teams for the design, development, implementation, evaluation, and/or integration of IA architectures, systems, or system components
Support the Government in the enforcement of the design and implementation of trusted relationships among external systems and architectures
Support security planning, assessment, risk analysis, and risk management
Identify overall security requirements for the proper handling of Government data
Provide security planning, assessment, risk analysis, and risk management
Perform system or network designs that encompass multiple enclaves, to include those with differing data protection/classification requirements
Recommend system-level solutions to resolve security requirements
Support the Government in the enforcement of the design and implementation of trusted relationships among external systems and architectures
Individual Capabilities/Experience Required:
Fourteen (14) years experience as an ISSE on programs and contracts of similar scope, type, and complexity is required. Bachelor's degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or university is required. DoD 8570.01-M compliance with IASAE Level 2 is required CISSP Certification is required. Four (4) years of ISSE experience may be substituted for a bachelor's degree.
Customer facing skills to drive discussions with senior personnel regarding trade-offs, best practices, project management and risk mitigation.
Experience with cloud computing and virtualization platforms. Specifically, AWS experience is strongly preferred.
Ability to quickly learn and shift in step with the latest cloud-computing, networking, and infrastructure management technologies.
Excellent communication, problem solving, and troubleshooting skills.
Strong knowledge of network architecture and security principles.
Knowledge of security and compliance requirements for cloud-based solutions.
DoD 8570.01-M compliance with IASAE Level 2 is required.
CISSP Certification is required
Themis Insight has all the PERKS!
You are our most valuable resource — your ambition, your knowledge, your creativity. We offer an industry-leading set of benefits to supplement your normal salary compensation. Themis Insight has you covered with flexible ways to balance work and home life, full health benefit premium coverage, and generous contributions toward your retirement.
Competitive health, dental, and vision plans with 100% paid premiums.
401k: We contribute 6% even if you don't!
Time Off: 11 standard holidays, and 25 days of PTO
Career Development: Get career counseling and individualized career development plans, including education and training.
Employee referral bonuses for successful hires
Themis Insight is an Equal Opportunity/Affirmative Action employer.
Themis Insight provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.