Cybersecurity III

Full Time
Montgomery, AL 36109
Posted
Job description
Overview:

Oasis Systems is looking for a Cybersecurity III -ISSM to support the Business Enterprise Systems Programming Innovation (BESPIN) at Maxwell-Gunter Air Force Base in Montgomery, AL. BESPIN is responsible for providing comprehensive IT solutions to the over 750,000 military, civilian, and contractor personnel working in the USAF and managing a portfolio consisting of over 140 applications that must be actively maintained and modernized. As well as developing the AF automated mobile pipeline and Kubernetes platform to enable scalable production environments under a Continuous Authority To Operate supporting continuous integration and continuous deployment for customers DoD wide.


LOCATION:
Maxwell AFB-Gunter Annex, Montgomery, Al
JOB STATUS: Full-time

TRAVEL: Less than 5%


REQUIRED QUALIFICATIONS

SECURITY CLEARANCE: Secret (Required) and U.S. Citizenship is required for all applicants


EDUCATION:

BS in Computer Science, Engineering, Information Systems, or other related technical discipline 8 years of directly related experience, 5 of which must be in the DoD; or 15 years of directly related experience, 8 of which must be in the DoD


CERTIFICATIONS:

At a minimum, the successful candidate will meet the requirements for and maintain an IAT or IAM Level III Cybersecurity certification by possessing at least one of the following certifications as directed by DoD 8140 and outlined in DoD 8570.01 -M, Appendix3, Table 2,2 AFMAN 17-1303:

CASP+ CE
CCNP Security
CISA
CISSP (or Associate)
GCED
GCIH
CCSP
CISM
GSLC
CCISO

EXPERIENCE LEVEL:
Level III

OTHER QUALIFICATIONS/SKILLS:

Has the knowledge, experience and demonstrated ability to perform tasks related to the technical/professional discipline they are performing

Has the ability to work independently and apply the proper procedures and processes related to their area of expertise.

Has experience with penetration testing. (Highly Desired).

Will also have the ability to problem-solve and troubleshoot various situations to develop successful outcomes with established program/project guidelines

The following skills are highly desirable but not required for this position:
  • Working knowledge of the Agile Development methodologies; Scrum, Kanban, etc.
  • Experience using any, or all, of the following tools (Desired):
  • o CheckMarx
  • o SonarQube
  • o Jira
  • o Confluence


RESPONSIBILITIES:

The ISSM will be responsible for ensuring that Information Systems are secure, and that the data maintained in these systems is protected from unauthorized access. Develop and implement advances cyber-defense solutions and changes for organizations; safeguard the corporate infrastructure from infiltrations; and assure that the systems are built to specifications and deployed successfully. Design, maintain and operated highly complex ad highly secure communications network environments. Perform in-depth network security analysis and conduct preliminary incident response, event analysis and threat intelligence. Review security events that could be a detriment to the organization's overall security stance. Develop and coordinate Authority to Connect/Authority to Operate approval packages. Provide technical input for the implementation of NSA, DoD, and Air Force security instructions, manuals, and policies. Provide security assistance and information to the capability development team throughout the software development lifecycle. Understand the Certification & Accreditation (C&A) and Risk Management Framework (RMF) processes. DISA Security Technical Implementation Guidelines (STIGs) implementation. eMass input, updates, and reviews. Ensure all milestones are prepared, accurate and delivered. Perform the Information Systems Security Manager (ISSM) duties as outlined in DoDI 8510.01
The contractor shall support technical assessments of IT systems to include web applications, application servers, web servers, access control, and databases and perform the following:
  • Conduct automated penetrations testing of web applications and APIs for susceptibility to SQL injections, command injections, Cross-Site Scripting, and Cross Site Request Forgery vulnerabilities using commercial and open source tools such as OWASP ZAP, Burp, and HCL AppScan;
  • Conduct automated vulnerability scanning against supporting infrastructure components using commercial and open source scanning tools such as nikto, nessus, nmap, and metasploit;
  • Conduct automated credentialed vulnerability scanning against databases using commercial and open source scanning tools;
  • Conduct manual testing of infrastructure and web applications to identify, test and validate security vulnerabilities;
  • Conduct code review and analysis to assess the security posture using static code analysis tools such as Fortify, Checkmarx, and Coverity;
  • Pre-assessment research and preparation including reconnaissance, documentation and configuration review, and customer interviews;
  • Conduct reviews of system configurations for identification of security weaknesses or misconfigurations;
  • Assess compliance posture against regulatory requirements such as NIST SP 800-53;
  • Analyze security findings, including risk analysis and root cause analysis;
  • Develop Security Test Report to document security testing, validated security vulnerabilities, mitigations, remediations, and course of actions;
  • Brief pen test results with appropriate management; and,
  • Coordinate with CDMs, ISSMs, ISSOs, and developers to remediate and correct security vulnerabilities.


Penetration Testers are required to hold and maintain an IAT level III certification.
Penetration Testers are authorized long-term telecommuting/telework requests


Benefits
Full time (30-40 hours): This role is eligible for comprehensive benefits including Medical, Dental, Vision, Life, Disability, 401(k), Paid Time Off (PTO), Supplemental and Voluntary Benefits and More!
Part-time (20- 29 hours): This part-time role is eligible for 401(k), Paid Time Off (PTO), and Commuter Benefits.
Part time (less than 20 hours): This part-time role is eligible for 401(k), Commuter Benefits and Sick leave as required by State law.


Who We Are

Oasis Systems is a premier provider of customer-driven, cost-effective, and quality Engineering Services; Enterprise Systems and Applications; Human Factors Engineering; Information Technology and Cyber Security; Professional Services; and Specialized Engineering Solutions to the Department of Defense, Federal Aviation Administration, Nuclear Regulatory Commission, and other Federal Agencies.


We strive to be an exciting and welcoming company that attracts, develops, motivates and retains the most talented, skilled and dedicated people in the industry; where they are encouraged to achieve personal excellence, purpose, and their full potential and career aspirations, while supporting mission-critical national security technologies and programs.


Oasis Systems is an equal opportunity employer and does not discriminate in hiring or employment on the basis of any legally protected characteristic including, but not limited to, race, color, religion, national origin, marital status, gender, sexual orientation, ancestry, age, medical condition, military veteran status or on the basis of physical handicap which, with reasonable accommodation, render the application to satisfactorily perform the job available


"Oasis Systems EPASS GB Division"

www.colinoncars.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, www.colinoncars.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, www.colinoncars.com is the ideal place to find your next job.

Intrested in this job?

Related Jobs

All Related Listed jobs