ISSE II

Skylla Engineering Ltd.

ISSE II

Livonia, MI
Full Time
Paid
  • Responsibilities

    Skylla Engineering is an agile and adaptive technology company that expeditiously delivers innovative solutions and knowledge-based services in support of the critical missions of our customers involved with the Nation’s Defense. Skylla offers a highly competitive total compensation package including a comprehensive benefits package, 401K matching, and Paid Time Off. We have an immediate opening for an energetic self-starter.

    Skylla Engineering is seeking a highly motivated, self driven, team player for an Information Systems Security Engineer (ISSE) II position for the Fly Away Broadcasting System (FABS) project under the Electromagnetic Warfare Systems (EWS) IPT. The duties include but are not limited to:

    -Identify information protection needs and define System Security Requirements.

    -Apply security risk assessment methodology to system development. Design System Security Architecture and assist in the creation of a System Security Plan.

    • Oversee the development and maintenance of a system’s cybersecurity solutions.

    -Identify AO and SCA cognizance of the system as well as any specific authorization requirements such as reciprocity, cross domain, and applicable overlays to support System Categorization.

    -Identify and tailor the security control baseline with applicable overlays.

    -Directly support the ISSO/ISSM and assist with development, maintenance, and tracking of the system’s security package.

    • Lead the security control implementation and testing efforts. Perform vulnerability-level risk assessments. Assist with any security testing required as part of A&A or annual reviews. Assist in the mitigation and closure of open vulnerabilities under the system’s change control process.

    -Work closely with the Integration team during baseline release cycle. Oversee cybersecurity testing to assess security controls and recording security control compliance status during the continuous monitoring phase of the lifecycle. Make data entries into authorization management records and provide security input for POA&M development consistent with implementation results.

    -Interact with vendors to inquire about new commercial software releases, updates, and/or technical issues.

    -Gather and analyze security requirements from identified stakeholders.

    -Document and map security interfaces, security interconnections, and operational trust relationships.

    -Ensure the system is in compliance with applicable directives, policies, and guidelines.

    -Provide Research and Development (R&D) support by providing input for development of products and design.

    -Develop and maintain documentation and procedures related to all aspects of job requirements.

    Required Skills

    · A thorough understanding of the Risk Management Framework and ability to demonstrate proper implementation.

    · Understand policy/directives, and ability to assess vulnerabilities of multiple commercial components and software to determine risk.

    · A basic understanding of system lifecycle development.

    · Ability to interface and communicate effectively with technical and non-technical audiences.

    · Ability to be proactive and work independently within a small, cohesive group.

    · Experience with MCCAS.

    Required Experience

    • You must be a US Citizen.

    • Must have a current Secret security clearance.

    • Hold a bachelor’s degree in Systems Security Engineering, Software Engineering, or Computer Science.

    • Required - DoD 8140 IASAE level 2 compliance or higher certification required: ( CISSP, CISSP-ISSAP or CISSP-ISSEP)

    • Preferred: Certified Authorization Professional (CAP)

    • Skylla Engineering is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

    VEVRAA Federal Contractor

  • Qualifications

    · A thorough understanding of the Risk Management Framework and ability to demonstrate proper implementation.

    · Understand policy/directives, and ability to assess vulnerabilities of multiple commercial components and software to determine risk.

    · A basic understanding of system lifecycle development.

    · Ability to interface and communicate effectively with technical and non-technical audiences.

    · Ability to be proactive and work independently within a small, cohesive group.

    · Experience with MCCAS.