|
Cybersecurity Specialist Location: Offutt AFB, NE Minimum Clearance Required: Top Secret/SCI eligibility This position is contingent upon contract award. This position requires the ability to obtain and maintain a Top Secret U.S. Government Security Clearance with SCI eligibility. U.S. Citizenship status is required, as this position necessitates an active U.S. Government Security Clearance for employment. Non-U.S. citizens are not eligible to obtain a U.S. security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence, foreign preference, criminal conduct, security violations, and illegal drug use. As a Cybersecurity Specialist, you will be responsible for assessing the security of systems, applications, and networks using established cybersecurity tools, frameworks, and testing methodologies. You will identify vulnerabilities, evaluate cybersecurity controls, and support the development of documentation, reports, and recommendations that ensure compliance with required security standards. This role also involves conducting a variety of security tests and audits, analyzing findings, and helping strengthen overall cybersecurity posture across supported environments. Who You Are and What You Need:
- Bachelor's degree in Computer Science or other related field.
- Minimum of 3 years of experience conducting penetration testing or Blue team testing required
- Possession of one of the following certifications: GPEN, GWAPT, GSE, OSEE, OSCE, OSCP, or GXPN.
- Knowledge of application security principles and safe coding techniques.
- Experience with programming languages such as SQL, C#, JavaScript, Ruby, PowerShell, and Python.
- Proficiency with security assessment tools including Tenable NESSUS, WebInspect, OWASP ZAP, Burp Suite, Metasploit, and Kali Linux.
- Familiarity with security frameworks such as NIST, MITRE ATT&CK, OWASP, and APT TTPs.
- Experience using operating systems such as Linux, UNIX, and Windows.
- Possession of DoD Directive (DoDD) 8570 Information Assurance Management (IAM) Level II certification or DoDD 8140 Information Assurance Security Engineer Level II certification.
- Knowledge and experience with NIST 80053 and DoD Risk Management Framework tools, including eMASS and Xacta.
What You Will Do:
- Understand and develop Plan of Action and Milestones (POA&M) required in support of information assurance or security necessities.
- Evaluate new applications software technologies; and/or ensuring the rigorous application of information security/ cybersecurity policies, principles, and practices to the delivery of application software services.
- Manage the fact finding, analysis, and development of hypothesis, conclusions, production of final reports and presentations, which requires expert knowledge of database practices, and USSTRATCOM database organization, operations and objectives, and requires training in application security and software analytical tools used by the IPT.
- These tools include: Application Security AppDetective Pro, Application Security DBProtect, Fortify Source Code Analyzer, Fortify 360 Server, Fortify Real-Time Analyzer, IBM/Rational AppScan.
- Support Cybersecurity and Cybersecurity Testing.
- Conduct tests of cybersecurity safeguards and integration of systems IAW established test plans, STIGs and Cybersecurity Controls. Cybersecurity support must be able to identify areas of cyber weakness within the programs and assist in providing solutions and document results with POA&Ms. Cybersecurity staff must ensure the design of hardware, operating systems, and software applications adequately address security requirements for the Computing Environment (CE) to include testing cybersecurity mitigations.
- This work requires the establishment and sustainment of information security assurance processes that satisfy complex system-wide requirements based upon DoDD 8500.1 Information Assurance, DoDI 8500.2 Information Assurance Implementation, DoDD 8520.1 Protection of SCI, DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology, DoD 8570.01M Information Assurance Workforce Improvement Program, and DoDI 8580.1 Information Assurance in the Defense Acquisition Process used for the analysis of user, policy, regulatory, and resource demands. These tasks require the development and production of RMF documentation for Secret, Top Secret and JWICS networks. Cybersecurity recommendations shall be provided based on evaluation and review of engineering proposals to ensure compliance with mandated cybersecurity requirements.
- Provide support in the development and implementation of doctrine and policies including CJCSI 6510.01E IA and Computer Network Defense (CND); CNSSP-22 Information Assurance Risk Management Policy for National Security Systems, and CNSSP-6 National Policy on Certification and Accreditation of National Security Systems.
- Perform vulnerability assessments and security tests on networks, web-based applications, and computer systems.
- Use testing methods to pinpoint ways that attackers could exploit weaknesses in security systems.
- Conduct network and system security audits, evaluate how well system conforms to a set of established criteria.
- Analyze policies for effectiveness, make suggestions on security policy improvements, and work to enhance methodology material.
- Document findings, write security reports, and discuss solutions with IT teams and management.
- Provide feedback and verification after security fixes are issued.
- Perform "black box" and "white box" testing.
- Perform Blue and Red team war gaming exercises.
- Perform security and technical assessments on new technologies.
- Generate "Best Practices" for implementations of new technologies.
- Perform reviews of application designs and source code (mainly Java, JavaScript, and C).
- Automate security testing through scripts and macros
What We Offer:
- Comprehensive benefits including health, dental and vision for the employee and family
- 401k Plan with a company contribution; fully vested immediately
- Company paid Life and AD&D insurance
- Company paid Short-Term and Long-Term Disability insurance
- Flexible Spending Accounts
- Paid Time Off (PTO)
- 10 paid holidays
- Employee Assistance Program
- Tuition Reimbursement
Who We Are: Calvert Systems is a Service-Disabled Veteran-Owned Small Business headquartered in Bellevue, Nebraska, with operations in twelve states including the District of Columbia. With over 20 years of trusted support to the Department of Defense, Calvert combines the strength of deep mission expertise, a workforce composed largely of veterans with the values of a family business culture. Our team is committed to exceeding customer expectations by leveraging a rich blend of operational experience, technical excellence, and a strong commitment to service. Calvert Systems Engineering provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
|