Plan and execute authorized penetration tests across diverse infrastructure environments while coordinating with system owners and SOC personnel. Develop decision-ready reporting and validate vulnerabilities including CISA WAS, FAST, and KEV findings.
The Junior Security Engineer will help ensure appropriate security controls are in place to safeguard digital files and electronic infrastructure. They will also support the integration and development of automated and AI-based security solutions within complex cloud environments.
The analyst will evaluate information systems to ensure they operate at an acceptable level of risk by performing technical assessments and developing mitigation strategies. They will also support authorization decisions, manage POA&Ms, and maintain cybersecurity dashboards to track compliance and risk posture.
The analyst will provide hands-on support for penetration testing activities, including reconnaissance, evidence collection, and documentation of findings. They will also assist with the triage of vulnerability disclosures and use automation tools to improve reporting workflows.
Plan and execute authorized penetration tests across diverse IT environments while coordinating with system owners and SOC personnel. Validate vulnerabilities, support CISA compliance findings, and utilize AI-enabled tools to improve reconnaissance and reporting efficiency.
The ISSO will own the security posture for assigned systems, advising on architecture, risk decisions, and authorization boundaries. They will lead control compliance, manage vulnerability remediation, and coordinate audits while maintaining key security artifacts.
The ISSO will develop and maintain System Security Plans and security documentation to support the Authorization to Operate process for federal systems. They will provide daily security guidance to project teams and ensure compliance with NIST standards and continuous monitoring requirements.
You will plan, implement, and monitor security measures to protect agency networks and information within cloud environments. Additionally, you will design security solutions for complex engineering problems and support the integration of automated and AI-based security capabilities.
The analyst will support the execution of the Risk Management Framework to authorize IT systems and contribute to risk mitigation strategies. They will also perform technical analysis, track POA&Ms, and present risk posture assessments to clients and decision-makers.
The engineer will configure, support, and troubleshoot SailPoint IdentityIQ modules, including reporting, JML processes, and access reviews. Additionally, they will develop and extend the SailPoint ServiceNow connector while partnering with stakeholders to deliver ongoing support initiatives.