Security Engineer Lead
Who Are We?
TSTC is an award-winning, Woman Owned, HUBZone certified Small Business providing services to federal intelligence, law enforcement, civilian and defense agencies. Built upon our Total Service - Total Commitment® cornerstone, TSTC takes pride in our commitment to delivering excellence. Total Service - Total Commitment® is our commitment to our employees, to our teams, and to our clients.
What We're Looking For:
TSTC is looking for a security engineer lead with depth of knowledge in the nuances of government security engineering requirements and policies. We need someone who is self-motivated, able to work in a geographically dispersed team of highly technical security personnel, and who loves problem solving. The ideal candidate combines hand’s on security engineering with the ability to translate that and help manage tasks for more junior level staff and is discussing complex topics with senior leadership.
TSTC is looking for candidates for this Key Personnel position that meet or exceed the stated requirements; are excited to join our team and willing to sign a binding letter of commitment; and can start 2 to 3 weeks after notification of contract award.
Basic Qualifications/Preferred Qualifications:
- Bachelor’s Degree and 15 years of related security engineering experience
- Must have a CISSP or a CISM
- Provide subject matter expertise to the security requirements allocation and security architecture processes
- Provide expert technical guidance in translating National Institute for Standards and Technology (NIST), and government agency cybersecurity standards, policies, and procedures into actionable tasks including:
- Reviewing and analyzing all evidence used to verify security vulnerabilities have been sufficiently addressed and/or system artifacts such as those used in the Assessment & Authorization (A&A) process, i.e. Security Plan (SP), Contingency Plan (CP), Contingency Plan Test (CPT), Incident Response Plan, and Configuration Management Plan (CMP), as some, but not all examples
- Reviewing draft documents and providing feedback on allocation of security and privacy requirements (e.g. technical review board (TRB), review of security policies, risk assessments, contingency plans, Plan of Action & Milestone (POA&M) reports)
- Determining the security impact of new technologies or policies (e.g., Continuous Diagnostics & Mitigation (CDM) technologies, anomaly-based tools, virtual environments, etc.) on the TSA information security program for TSA review and approval. The review of security impact should be documented through the completion of the Security Impact Analysis (SIA) process as documented by TSA’s Information Assurance and Cybersecurity Division (IAD)
- Ensuring security requirements are identified, appropriately allocated, and addressed throughout the TSD/SFD mission systems’ architectures
- Experience with Security scan tools and techniques. Examples include:
- Tenable Security Center
- Invicti 360
- Trustwave DbProtect
- CyberArk Certificate Manager (formerly known as Venafi)
- Portswigger Burp Suite Pro
- Lead the preparation of responses to federal ad hoc reporting requirements
- Lead written reviews or assessments in the form of short briefings, written documents, or presentations (expected average of 5-8 per month) as accomplishment reports of Ad hoc Security Engineering services provided (Deliverable #4)
- Help develop alternatives of IT system designs and/or architectures which consider trade-offs between security requirements, functional/operational requirements and cost for TSA review and final approval
- Help determine the impact of new or changing applicable NIST, DHS, and TSA cybersecurity standards and policy changes
- Lead the impact assessments of new or revised legislation and regulations (examples are OMB Memos and Federal Information Security Modernization Act (FISMA)) for review. Lead and support standard operating procedure documentation and updates
- Support weekly security team staff meetings
- Review and ensure security compliance deliverables are accurate and correct
- Skilled in MS office Suite
- Works independently, proactively identifies, and completes task
- Excellent verbal and written skills
Security Clearance and Where You’ll Work
- Candidate must be able to pass a comprehensive background investigation required to obtain a Government suitability determination
- Work will be performed in Annapolis Junction, Maryland or Colorado Springs, Colorado
- This is a hybrid role with 4 days of work on site each week
- Travel 4-5 times per year for weeklong assignments
Benefits at TSTC
Competitive Salary & Bonuses – Includes personal and team merit bonuses, with salary matching for 401(k) up to 3%.
Comprehensive Health Coverage – Multiple medical, dental, and vision plans, plus HSA and FSA options. 100% TSTC-paid life and disability insurance, including short- and long-term plans.
Flexible Work Options – Remote work allowed, flexible schedules, and telework opportunities. (varies per position)
Paid Time Off & Holidays – Generous PTO and paid holidays.
Professional Development – Continuous performance evaluation process… Dedicated annual budget for educational opportunities.
Comprehensive Wellness Programs - confidential employee assistance program (EAP). Wellness Resource Group and wellness programs throughout the year.
All TSTC employees operate according to the terms of the specific contract under which they work. They are responsible for fulfilling the duties of the specific job and are accountable for complying with the terms and conditions of their employment, the TSTC Code of Conduct, and with applicable federal, state and local laws.
As TSTC is an Equal Opportunity Employer, we follow current Federal Discrimination Laws and we do not discriminate against any employee or applicant for employment. TSTC does not discriminate against any employee or applicant for employment due to race, color, national origin, citizenship, religion, creed, age, sex, disability, veteran status and liability for service in the U.S. Armed Forces or any other characteristic protected by applicable law.
If you need assistance or an accommodation due to a disability, please email us at [email protected] or call us at (276) 496-4458.
Job Details
Salary
$155,000 – $170,000/yr
Experience
Management