Job Description |
Performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction.
- Performs Computer Security Incident Response activities for a large organization, coordinates with other government agencies to record and report incidents.
- Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation.
- Recognizes potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information.
- Evaluate firewall change requests and assess organizational risk.
- Communicates alerts to agencies regarding intrusions and compromises to their network infrastructure, applications and operating systems.
- Assists with implementation of counter-measures or mitigating controls.
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
- Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance.
- Prepares incident reports of analysis methodology and results.
- Provides guidance and work leadership to less-experienced technical staff members, and may have supervisory responsibilities.
- May serve as a technical team or task leader.
- Maintains current knowledge of relevant technology as assigned.
- Participates in special projects as required.
Typical duties include:
- Department of Defense Directive (DoDD) 8500.01E Information Assurance (IA)
- Identification and management of network and system vulnerabilities and security events, vulnerability assessments, and red / blue team events.
- Perform global DoD inspections of Special Enclave services to ensure compliance to DoDI 8530 standards.
- Coordinate with functional leads, and provide inspection services across the enterprise.
- Implement and follow NIST RMF / A&A processes and creation of associated project artifacts.
- Perform site assessments to ensure meet guidelines under the following directives:
• ICD 503 intelligence Community Information Technology Systems Security Risk Management, Certification, and Accreditation.
• DoDD 5200.1 DoD Information Security Program and Protection of Sensitive Compartmented Information (SCI)
• NIST Special Publication 800-30, Guide for Conducting Risk Assessments
• NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach
• NIST Special Publication 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations
- Review C&A / A&A documentation.
- Validate IA controls found in DODI 8500.2 and NIST SP 800-53rev3.
- Provide excellent written and verbal communication skills.
- Provide excellent customer service skills.
- Use XACTA worflow and modules to manage assessment work artifacts and progress.
- Follow NIST Risk Management Framework (RMF) and processes.
Bachelors Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training or work experience.
As a trusted systems integrator for more than 50 years, General Dynamics Information Technology provides information technology (IT), systems engineering, professional services and simulation and training to customers in the defense, federal civilian government, health, homeland security, intelligence, state and local government and commercial NA approximately 32,000 professionals worldwide, the company delivers IT enterprise solutions, manages large-scale, mission-critical IT programs and provides mission support NA is an Equal Opportunity/Affirmative Action Employer - Minorities/Females/Protected Veterans/Individuals with Disabilities.
- 8-10 years of related experience in data security administration.
- Requires DOD8570 IAT-III and CND-SP Specialty: CND Analyst.
- Must be willing to obtain and maintain a CI Polygraph.