Job description
• Designs, tests, and implements secure operating systems, networks, security monitoring, tuning and management of I.T. security systems and applications, incident response, digital forensics, loss prevention, and eDiscovery actions.
• Conducts risk and vulnerability assessment at the network, system, and application level.
Conducts threat modeling exercises.
• Develops and implements security controls and formulates operational risk mitigations along with assisting in security awareness programs.
• Involved in a wide range of security issues, including architectures, firewalls, electronic data traffic, and network access.
• Researches, evaluates, and recommends new security tools, techniques, and technologies and introduces them to the enterprise in alignment with the I.T. security strategy.
• Utilizes c and custom tools and processes/procedures to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions.
• Assists in implementing the required government policy (i.e., NISPOM, DCID 6/3) and makes recommendations on process tailoring.
Performs analyses to validate established security requirements and to recommend additional security requirements and safeguards.
• Supports the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
• Periodically conducts a review of each system' s audits
and monitors corrective actions until all actions are closed.• Periodically conducts a review of each system 's audits and monitors corrective actions until all actions are closed.
• May support cyber metrics development, maintenance, and reporting.
May provide briefings to senior staff.
Utilizes COTS/GOTS and custom tools and processes/procedures to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions.
• Assists in implementing the required government policy (i.e., NISPOM, DCID 6/3) and makes recommendations on process tailoring.
Performs analyses to validate established security requirements and to recommend additional security requirements and safeguards.
• Supports the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
• May support cyber metrics development, maintenance, and reporting.
Required Skill Profession
Computer Occupations