Cyber Engineer Principal

  • SAIC, Inc
  • Chantilly, VA, USA
  • Sep 08, 2021

Job Description

Description

JOB DESCRIPTION:

SAIC is seeking a Senior Cyber Security Analyst, to serve as a Blue Team Vulnerability Assessment subject matter expert. Conducts Blue Team risk and vulnerability assessment at the network, system and application levels. Conducts cyber threat modeling exercises with commercial tools such as Red Seal, Sky Box or like tools. Ensure applicable Blue Team Vulnerability Assessment discipline is applied. Leverage customer/contractual Vulnerability Assessment Process Framework to include documentation creation and review as it relates the assessment, document risk/issues. Designs, tests, and implements secure operating systems, networks, security monitoring, tuning and management of IT security systems and applications, incident response, digital forensics, loss prevention. 
Possess a thorough understanding in a wide range of security issues including vulnerability assessment architectures, firewalls, electronic data traffic, and network access. Experience with utilizing commercial tools such as NESSUS, KIBANA, RedSeal, Lancope, WireShark, etc.  Researches, evaluates and recommends new security tools, techniques, and technologies and introduces them to the enterprise in alignment with IT security strategy. Utilizes COTS/GOTS and custom tools and processes/procedures in order to scan, identify, contain, mitigate and mitigate vulnerabilities, and intrusions. Assists in the implementation of the required government security policy ICD/503 in support of Cyber lab environment. 
Performs analyses to validate established security requirements and to recommend additional security requirements and safeguards. Support cyber metrics development, maintenance and reporting. Supports the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations participation in the tests, analysis of the results, and preparation of required reports. Periodically conducts review of each system's audits and monitors corrective actions until all actions are closed. Experience with providing briefings to senior staff. Applies advanced technical principles, theories, and concepts. Contributes to development of new principles and concepts. Participates with senior managers to establish strategic plans and objectives: Serves as organization spokesperson on advanced projects and/or programs. Acts as advisor to management and customers on advanced technical research studies and applications.

FREEDOM TO ACT: Work is performed without appreciable direction. Exercises considerable latitude in determining technical objectives of assignment. Completed work is reviewed from a relatively long-term perspective for desired results. Exercises judgment in selecting methods, techniques and evaluation criteria for obtaining results. IMPACT: Guides the successful completion of major programs. Erroneous decisions or recommendations would typically result in failure to achieve major organizational objectives. LIASON: Represents organization as prime technical contact on contracts and projects. Interacts with senior external personnel on significant technical matters often requiring coordination between organizations.

Qualifications

TYPICAL EDUCATION AND EXPERIENCE: Bachelors and nine (9) years or more experience; Masters and seven (7) years or more experience ; PhD or JD and four (4) years or more experience.

Clearance required to start: Top Secret with Polygraph

Required certification compliance: DoD Directive 8570 / 8140 IAT/IAM III certification

Desired Qualifications:
Certified Information Systems Security Professional (CISSP)
ISACA Certified Information Systems Auditor (CISA) 
EC-Council Certified Ethical Hacker (CEH)
SANs GIAC certification (e.g., GPEN or GW APT)
Offensive-Security Certified Professional (OSCP)
Experience with Cyber threat methodologies

Desired Specific Blue Team Skills:
Identification and Validation of Security Flaws
Network Mapping / Network Analysis
Vulnerability Analysis
Pen-testing network filters and security countermeasures
Threat Hunting
Incident Response
Forensic Analysis
 


COVID Policy: Prospective and/or new employees will be required to adhere with SAIC's vaccination policy. Full vaccination will be required before the start of employment in order to work onsite at an SAIC location. If applicable, prospective or new employees may seek an exemption to the vaccination requirement at Contact Us and must have an approved exemption prior to the start of their employment. Employees working onsite at a customer location must comply with customer requirements which may include mandatory vaccination, mandatory attestation regarding one's vaccination status and mandatory weekly or bi-weekly testing.