Responsibilities:
- Participate in high-quality interaction with customers, team members, contractors, and ultimately the government authorization official to achieve the directed Information Systems Security objectives.
- Serve as a subject matter expert in the field of Information Systems Security and provide guidance during the design, integration, or upgrade of software applications and information systems.
- Combined knowledge of Information Systems Security policies and operational understanding to develop or review Assessment & Authorization documentation based upon the NIST Risk Management Framework and other U.S. Department of Defense regulations.
- Perform random and scheduled security control assessments of software applications and information systems to ensure compliance with requirements based upon NIST Risk Management Framework and other U.S. military regulations.
- Participate in continuous monitoring activities such as vulnerability management, incident response, and accreditation record maintenance in systems such as eMASS or XACTA.
- Perform work product evaluation of other Information Systems Security team members during the design, integration, or upgrade of new or existing information systems.
Qualifications You Must Have:
- Bachelor's degree in Systems Security, Network Engineering, Information Technology, or related Engineering discipline
- 5+ years of experience in IT security or a related field.
- Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 9 years of related experience is required.
- Higher level relevant degree may substitute for experience.
- Must have IAT Level III certification (CISSP, CASP, GCIH, etc.) or ability to attain within 6 months of hire.
- Demonstrated experience working in an application security environment and performing application security related tasks such as SAST/DAST/SCA testing.
- Demonstrated experience with security control assessment tools such as ACAS / Tenable Nessus, SCAP Compliance Checker, Static Application Security Testing tools and Dynamic Application Security Testing tools.
- Strong understanding of DoD applicable Security Technical Implementation Guides (STIGs), NIST special publications, and NSA Guides.
- Working knowledge of operating systems and networking concepts.
- Demonstrated ability to effectively communicate, complete tasks and assignments on time, problem solve, work in a team environment, and work independently when necessary.
Qualifications We Prefer:
- Experience implementing DevSecOps processes within existing DevOps pipelines.
- Experience configuring, deploying, and securing applications within the modern Kubernetes / CNCF landscape.
- Experience working with the RMF accreditation process for a Department of Defense customer.
- Experience working with deployed tactical information systems.
- Additional information security industry certifications such as the CISSP-ISSEP, CISM, or C|EH Certification
Essential Functions:
- Ability to work primarily at a computer for extended periods.
- Capability to participate in on-call rotation for incident response.
- Must be able to lift up to 25 lbs occasionally.
- Ability to work in an office or hybrid environment.
- Occasional travel may be required.
This posting will be open for application for a minimum of 5 days and may be extended based on business needs.
SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more.
IMPORTANT NOTICE:
This position requires current/active Top Secret U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. Citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence, foreign preference, criminal conduct, security violations, and illegal drug use.Learn more about the background check process for Security Clearances.
SNC is a global leader in aerospace and national security committed to moving the American Dream forward. We’re known and respected for our mission and execution focus, agility, and disruptive and rapid innovation. We provide leading edge technologies and transformative solutions that support our nation’s most critical security needs. If you are mission-focused, thrive in collaborative environments, and want to make our country stronger with state-of-the-art technologies that safeguard freedom, join our team!
SNC is an Equal Opportunity Employer committed to an environment free of discrimination. Employment decisions are made based on merit without regard to race, color, age, religion, sex, national origin, disability, status as a protected veteran or other characteristics protected by law.
Skills Required
- Bachelor's degree in Systems Security, Network Engineering, Information Technology, or a related engineering discipline
- 5+ years of experience in IT security or a related field
- If substituting experience for a degree, at least 9 years of related experience
- IAT Level III certification, such as CISSP, CASP, or GCIH, or ability to attain it within six months of hire
- Experience working in an application security environment, including SAST, DAST, and SCA testing
- Experience with security control assessment tools, including ACAS, Tenable Nessus, SCAP Compliance Checker, SAST tools, and DAST tools
- Strong understanding of DoD STIGs, NIST special publications, and NSA Guides
- Working knowledge of operating systems and networking concepts
- Ability to communicate effectively, complete assignments on time, solve problems, and work independently and collaboratively
- Ability to work primarily at a computer for extended periods
- Ability to participate in an on-call incident response rotation
- Ability to lift up to 25 pounds occasionally
- Ability to work in an office or hybrid environment
- Experience implementing DevSecOps processes within DevOps pipelines
- Experience configuring, deploying, and securing applications in Kubernetes or the CNCF landscape
- Experience with the RMF accreditation process for a Department of Defense customer
- Experience with deployed tactical information systems
- Additional certifications such as CISSP-ISSEP, CISM, or C|EH
What We Do
SNC is an innovative and agile aerospace and defense contractor. We design, manufacture, and enhance spacecraft, aircraft, ground vehicles, electronics, hardware and software, and provide services that serve and empower our astronauts, war fighters, and first responders. Honored as a Tier I Superior Supplier for the U.S. Air Force, we consistently rank among America’s fastest growing businesses. We were also selected to represent the commercial space industry by the newly formed National Space Council as one of the most innovative U.S. companies in space. Founded in 1963 and headquartered in Reno/Sparks, Nevada (America's #1 Best Small City), SNC is privately owned and operates under the leadership of owners, CEO Fatih Ozmen, and Chairwoman & President Eren Ozmen. Today we have nearly 4,000 employees in 32 locations in 19 U.S. states, England, Germany and Turkey. SNC has also been recognized by its employees as: Reno-Tahoe's Best Places to Work, Denver's Best Places to Work, and Florida's Best Companies to Work


.png)




