- Providing expert oversight to maintain continuous compliance through monitoring, validating, and enforcing operational security to ensure EDSO's confidentiality, integrity, and availability
- Modifying and implementing secure network connectivity between Amazon Web Services and the USMC
- Evaluating and remediating potential security risks, where identified
- Evaluating and remediating potential cloud, network, host, application, identity, firewall, load-balancing, WAF, and CI/CD pipeline security risk
- Supporting DevSecOps pipeline administration, including secure code integration, configuration management, software deployment, vulnerability scanning, dependency scanning, secrets management, and CI/CD security controls
- Supporting Cloud and network logging, alerting, monitoring, incident response, vulnerability remediation, and continuous compliance activities
- Coordinating with platform engineers, network engineers, system administrators, developers, mission owners, and customer-support personnel to validate cyber security controls; maintain operational security; resolve cyber security incidents; support system changes; and sustain secure, reliable, and available IL6 cloud services
- Provides operations and customer support for all services, to include, but not limited to:
- Operating System Maintenance
- VPC Configuration
- Infrastructure as Code Tools
- Amazon Web Services (AWS)
- SCCA Network Components (Cisco Routers and F5 devices)
- SCCA firewall (Palo Alto)
- Identity and Access Management - Active Directory (AD)
- Multi-Factor Authentication
- Intrusion Detection and Intrusion Prevention System (IDS/IPS)
- Assured Compliance Assessment Solution (ACAS)
- Microsoft Defender
- Windows Server Update Services (WSUS)
- Online Certificate Status Protocol (OCSP)
#LI-LL1
FILLING THIS POSITION IS CONTINGENT UPON FUNDING
Requirements- BS degree in engineering, physical science, physics, network security, computer science
- 10 years of experience in relevant technical field, to include: technology analysis and assessment, design definition, development of systems specification, systems analysis, systems architecture, systems/equipment integration, test & evaluation criteria
- Experience with DevSecOps practices, secure CI/CD pipelines, configuration management, infrastructure as code, and secure software-delivery processes
- Experience with cloud automation, and infrastructure-as-code tools (Ansible, Terraform, CloudFormation, Lambda)
- Experience with Python, JSON
- Experience supporting secure cloud networking, network segmentation, routing, firewall policies, and cloud connectivity
- Experience with Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs), continuous monitoring, vulnerability management, and cyber security compliance
- Experience developing cyber security documentation, operational procedures, security-control evidence, remediation plans, risk registers, and technical reports
- Ability to identify operational cyber security risks, assess potential mission impact, recommend mitigation measures, and track remediation through closure
- Amazon Web Services (AWS) experience
- Five years of technical experience in cyber engineering, network infrastructure, networking, server virtualization, object-oriented programming, software development, software configuration, software installation, or cloud transition, and cyber security
- Desire to work in a secure lab environment
- Holds an CompTIA Security+ or higher certification
- Experience with container security
- Experience supporting GitLab security capabilities, including code scanning, dependency scanning, secrets management, runner security, auditing, and CI/CD pipeline controls
- Experience with cloud security logging, monitoring, alerting, incident response, threat detection, and security-event analysis
- Experience reviewing and validating cloud, network, firewall, WAF, load-balancing, and identity-and-access-management configurations
- Network experience
- SAFe (Scaled Agile Framework) Experience
- Recognized expert who has demonstrated industry and/or public service (e.g., federal, state, or local)
- leadership in Information Technology services
- Experience may be concurrent
SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE SECRET LEVEL WITH TOP SECRET ELIGIBILITY
Travel Requirements- Travel one week per quarter to Charleston, SC or Stafford, VA
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
EEOScientific Research Corporation is an equal opportunity employer that does not discriminate in employment.
All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.
Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact [email protected] for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
Skills Required
- Bachelor’s degree in engineering, physical science, physics, network security, or computer science
- 10 years of experience in a relevant technical field involving technology analysis, systems architecture, integration, testing, or related work
- Experience with DevSecOps practices, secure CI/CD pipelines, configuration management, infrastructure as code, and secure software delivery
- Experience with cloud automation and infrastructure-as-code tools including Ansible, Terraform, CloudFormation, and Lambda
- Experience with Python and JSON
- Experience supporting secure cloud networking, segmentation, routing, firewall policies, and cloud connectivity
- Experience with RMF, STIGs, continuous monitoring, vulnerability management, and cybersecurity compliance
- Experience developing cybersecurity documentation, procedures, control evidence, remediation plans, risk registers, and technical reports
- Ability to identify cybersecurity risks, assess mission impact, recommend mitigations, and track remediation to closure
- AWS experience
- Five years of technical experience in cyber engineering, networking, infrastructure, programming, software configuration, cloud transition, or cybersecurity
- Willingness to work in a secure lab environment
- CompTIA Security+ or higher certification
- U.S. citizenship
- U.S. government Secret security clearance with Top Secret eligibility
- Container security experience
- Experience with GitLab security capabilities, including code scanning, dependency scanning, secrets management, runner security, auditing, and CI/CD controls
- Experience with cloud security logging, monitoring, alerting, incident response, threat detection, and security-event analysis
- Experience reviewing cloud, network, firewall, WAF, load-balancing, and identity-access-management configurations
- Network experience
- SAFe experience
- Recognized industry or public-service leadership in information technology services
What We Do
Sciolex Corporation is a CVE-certified Service-Disabled Veteran-Owned Small Business that provides systems and mission engineering, technical assistance, operations advisory, cloud computing, acquisition support, and executive and administrative services. The company supports federal civil, defense, and Intelligence Community agencies, helping them plan, integrate, test, deploy, and manage information, technology, and mission capabilities while improving information operations through research and innovative processes.








