<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Great Knowledge Consulting Group Jobs!</title>
<link>http://www.cytiva.com/kcg/openings.asp?act=list</link>
<description>RSS Web Feed for Knowledge Consulting Group Careers</description>
<pubDate>11/20/2009 8:47:57 PM</pubDate>
<lastBuildDate>11/20/2009 8:47:57 PM</lastBuildDate>
<item>
<title><![CDATA[FISMA Compliance Analyst]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg578]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





IT Security's FISMA Compliance team is responsible for monitoring TSA Information Systems during the 4 phases of Certification and Accreditation (C&A) in order to assess their compliance with the FISMA metrics set forth by DHS. These ever-evolving metrics currently include Annual Testing, POA&M Management, C&A, and Program Management.  FISMA Compliance is also frequently tasked with short term, tight-deadline, ad hoc projects spanning all aspects of IT Security. Project deliverables include presentations, manuals, reports, mass information dispersion, spontaneous training, research projects, etc.  The content of this work includes the analysis of  privacy information, C&A artifacts, various security statistics, financial/budgetary statistics, and more. 





- Assist in ongoing training efforts for TAFT, RMS, FISMA and other DHS/TSA related IT Security mandates which may include developing and presenting briefings given to an audience of other IT professionals. 


- Participate in the development and maintenance of reports (mostly MS Excel) which serve to monitor and track multiple FISMA related metrics. 


- Analyze DHS-issued fiscal year policy documentation to determine the upcoming annual metrics TSA must follow and enforce.


- Use and maintain expertise in Trusted Agent FISMA Tool (TAFT) and the Risk Management System (RMS). Tasks include data research, report creation, account maintenance, data entry, file upload/downloading, etc. 


- Some review of security documentation may be required, to include SSPs, RAs, CPs, CPTRs, ST&E Plans, ST&E Results, weakness matrices, PTAs, and others.





Requirements: 


- 5 years FISMA experience with no degree, 2 years with bachelors degree in a related field.     


- Ability to and interest in providing support and guidance to ISSO/SO's through the four phases of C&A, including monitoring C&A artifact compliance, annual self-assessment (NIST 800-53A) completion, vulnerability scans, annual contingency plan testing, and POA&M management. Must possess experience with FISMA.


- Able to assist with other ISSO responsibilities including documentation, policy compliance, and CM review, as well as user training.


- Working knowledge of Microsoft Office Suite (to include Excel, Word, and Powerpoint).  


- Ability to work effectively in a team management environment and participate in collaborative initiatives which foster the mutual exchange of knowledge and expertise. 


- Must be able to multi-task, work independently and as part of a team, share workloads, and deal with sudden shifts in project priorities.


- Ability to communicate effectively orally and in writing to build and maintain customer satisfaction and express conclusions in a clear, technically sound manner on matters associated with IT security.


- Ability and interest in obtaining a security/C&A certification (e.g., CAP).]]></description>
<pubDate>11/20/2009</pubDate>
</item><item>
<title><![CDATA[Jr. Vulnerability Management Engineer]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg597]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret clearance is required with the ability to get SCI.





Any candidate accepted for this position will be responsible for administering the Miscrosoft SCCM, Microsoft WSUS, and Red Hat Enterprise 5, and QMX for the purpose of the patch management process.  This is a great opportunity for a Linux Administrator to transition into the IT Security field.





Highlights:


Exposure to latest tools and techniques in the field of information security.


Exposure to the majority of computing technologies in use today.


Team members consistently recognized as leaders in the field of information security.


Professional development/certifications are paid for.


Easily accessible location.]]></description>
<pubDate>11/20/2009</pubDate>
</item><item>
<title><![CDATA[SOC Consultant]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg603]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





This position is being opened in the Computer Network Defense team (CND) of the Information Assurance Division (IAD), Office of Information Technology (OIT), Transportation Security Administration (TSA), within the Department of Homeland Security (DHS). 





This position will serve as the liaison between the CND and the Security Operations Center (SOC) provided by a managed services provider under contract to the TSA. 





This position will also serve as an advisor to the Branch Chief of the CND, and to senior management officials, on matters pertaining to the operation of the SOC. This position will manage various projects for the CND and, skill set permitting, may be called upon to provide assistance in the collection of security related intelligence or the remediation of security incidents. 





The position's primary duties include, but are not limited to:


- Serve as liaison between the TSA CND and the managed services provider's SOC.


- Identify operational issues within the SOC, the CND, or the interoperation of the two, and make recommendations for the resolution.


- Organize and run regular meetings between the two teams to resolve issues and facilitate interoperation.


- Manage long-term projects which involve one or both organizations.


- Serve as a senior expert and consultant to the TSA CND and to senior management officials regarding the operation of the SOC and the integration of the SOC into other IT programs. 


- Advise other IT experts on issues pertaining to SOC operations and the technologies used by the SOC which include, but are not limited to, Intrusion Detection Sensors, Security Event Management systems, Anti-Virus systems, Content Filtering solutions, Firewalls, and Access Control Lists.


- Track the resolution of requests for service made of the SOC by external organizations, or by the SOC of external organizations. This includes following up on these tasks to ensure completion and reporting on their status to the CND.


- Write drafts of memos and other official communications pertaining to the operation of the SOC for the Branch Chief of the CND to review and submit to senior management officials.





**Primary location of this job is in Ashburn, VA and 30% will be in Arlington, VA.





Requirements:


- 7+ years experience in IT Security (may overlap the other experience qualifications)


- 5+ years of management experience (may overlap the other experience qualifications)


- 5+ years of experience working in or with a Security Operations Center (may overlap the other experience qualifications).





Specifically, candidates must have experience with the following:





IDS - 


Differences between signature based and behavioral or anomaly based NIDS


Underlying technology behind HIDS and the benefit in a "defense in depth" strategy


IDS tuning principles and concepts


 


Firewalls - 


ACL/Ruleset auditing


Trust zone configurations/examples


Difference between packet filter, stateful, and application layer firewalls


 


Routing/Switching - 


General conceptual knowledge of current technologies/hardware


SPAN concepts as they relate to IDS monitoring


Conceptual knowledge of LAN/WAN technologies (MPLS, Ethernet/Fiber speeds, VLAN, Subnets, etc.)]]></description>
<pubDate>11/20/2009</pubDate>
</item><item>
<title><![CDATA[Sr. Policy Analyst]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg607]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





1. Develop, implement and communicate IT security policy, standards, guidance and procedures;


2. Assist with conversion of a variety of government directives into useful component-level policy and procedural documentation; 


3. Assist with the development of policy awareness efforts and materials for distribution to the user community;


4. Develop and implement processes and procedures required to respond to evolving NIST and departmental directives and guidance;


5. Participate in working groups in the development of DHS IT Security policy and procedures;


6. Provide support in the development and enhancement of a comprehensive IT Security Policy Program; 


7. Assist the ITSD with the development of policy letters, memoranda, briefings, and associated documentation for distribution to Federal community;


8. Provide support working with members of intelligence community, coordinating system security policy, as necessary; and


9. Develop policy letters, memoranda, briefings, presentations and associated documentation for distribution to the Federal community.]]></description>
<pubDate>11/20/2009</pubDate>
</item><item>
<title><![CDATA[COMSEC Engineer]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg606]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret clearance is required with the ability to get SCI.





- Ensure compliance with federal directives and executive orders.


- Understand and comply with  the Federal COMSEC Custodian governance.


- Provide technical guidance and assistance to the customer's administration on an as needed basis.


- Technology used includes:  TACLANE, KIV 7's, STE's, Secure Cell phones, and DIAS.


- Ensure DHS encryption policy is implemented and enforced.


- Provide possible 7X24 hour support for upload of key material at multiple TSA and DHS locations - maybe on an on call schedule.


- Be able to provide emergency support in elevated threat levels for COMSEC services.


- Assist in the development, implementation and communication of the COMSEC program.


- Provide Guidance on controlling, maintaining and securing COMSEC equipment.


- Solve customer problems/concerns for IT physical, systems and personnel security issues as they relate to COMSEC.


- Perform security reviews.]]></description>
<pubDate>11/19/2009</pubDate>
</item><item>
<title><![CDATA[ISSO]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg601]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret clearance is required and must be clearable to SCI.





- Reviewing System Security configurations and maintaining a system security plan and associated documentation.


- Ensuring the Information System (IS) is operated, used, maintained and disposed of in accordance with security policies and practices.


- Ensuring the IS is certified and accredited.


- Ensuring users and system support personnel have the required security clearances, authorization and need-to-know.


- That users are indoctrinated and familiar with internal security practices before access to the IS is granted.   


- Ensuring compliance of system users with security policies and safeguards applicable to the IS.


- Ensuring audit trails are reviewed periodically (e.g. weekly, daily), and audit records are archived for future reference.  


- Initiating and/or implementing risk mitigation activities. 


- Reporting security incidents in accordance with FBI and division-specific policy to the Designated Accrediting Authority (DAA) when an IS is, or is suspected to be, compromised.


- Reporting the security status of an IS as required by the designated accrediting authority and evaluating known vulnerabilities to ascertain if additional safeguards are needed.]]></description>
<pubDate>11/19/2009</pubDate>
</item><item>
<title><![CDATA[Information Security Engineer]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg605]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





This candidate will join a team of information security professionals in providing comprehensive support to the customer's certification and accreditation process. This individual will be exposed to emerging technology, enterprise-level vulnerability assessment approaches and information security policy development/implementation on an agency-wide scale.





Requirements:


The successful candidate will have at least one year in the information security field, and will be knowledgeable on the general concepts of information security practices and government regulations applicable to FISMA. Must possess experience with NIST.





This candidate should possess a B.A. or B.S. in related field and 1 year of IA experience. B.A. or B.S. may be substituted with 4 additional years of professional Information Assurance services experience.]]></description>
<pubDate>11/18/2009</pubDate>
</item><item>
<title><![CDATA[Information Assurance Analyst]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg595]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. TS/SCI clearance is required.





Support the Regional IAM with the DCHC Information Assurance program. Assist PMs with IA Self-Assessment Security Review to ensure compliance. Develop/maintain disaster recovery plan. Ensure adequate IT Security Program is in place (SOPs, User Guides, Training, STIG compliance etc.) Manage/maintain DCHC network users credentials and provide user training. Review and approve all user access requests (verify DD2875, need-to-know, etc). Assist RIAM to support the system certification and accreditation team. Assist Incident Response/System Administrators with assessing system damage/vulnerabilities and management of audit logs. Ensure systems are registered in the Vulnerability Management System and IAVM compliant. Review, approve and document requirements for shared/service accounts. Responsible for the Safeguarding of Sensitive and/or Classified Data to include maintaining classification guidance for systems, providing classified handling, processing and discussion guidance.]]></description>
<pubDate>11/17/2009</pubDate>
</item><item>
<title><![CDATA[Information Assurance Analyst]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg544]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret with SCI clearance is required.





Support the Regional IAM with the DCHC Information Assurance program. Assist PMs with IA Self-Assessment Security Review to ensure compliance. Develop/maintain disaster recovery plan. Ensure adequate IT Security Program is in place (SOPs, User Guides, Training, STIG compliance etc.) Manage/maintain DCHC network users credentials and provide user training. Review and approve all user access requests (verify DD2875, need-to-know, etc). Assist RIAM to support the system certification and accreditation team. Assist Incident Response/System Administrators with assessing system damage/vulnerabilities and management of audit logs. Ensure systems are registered in the Vulnerability Management System and IAVM compliant. Review, approve and document requirements for shared/service accounts. Responsible for the Safeguarding of Sensitive and/or Classified Data to include maintaining classification guidance for systems, providing classified handling, processing and discussion guidance.]]></description>
<pubDate>11/17/2009</pubDate>
</item><item>
<title><![CDATA[ISSO]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg546]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





1. Must develop and implement documentation outlining system operating environment, to include the overall mission, floor layout, hardware configuration, software, type of information processed, user organizations and security clearances, operating mode, interconnections to other systems/networks of users, their security personnel, and associated responsibilities; 


2. Assist in the development and maintenance of the overall system security document, the Information System Security Plan, which contains all necessary security procedures, instructions, operating plans, and guidance;


3. Participate in the development or revision of System-specific security safeguards and local operating procedures that are based on the above regulations;  


4. Provide IT security consulting to system owners as to the other security documents, for example, security incident reports, equipment/software inventories, operating instructions, technical vulnerability reports, and contingency plans; and


5. Provide expertise in classified and unclassified ratings to customers.


6. Work closely with Certifiers to navigate the TSA Certification & Accreditation process and produce all appropriate accreditation documentation.


7. Attend monthly ISSO training course at TSA Headquarters.


8. Perform monthly vulnerability assessment scans of assigned systems using Tenable Nessus.





Requirements:


The ISSO is the principal point of contact for information assurance activities at the IT system level. The ISSO is responsible for ensuring that management; operational and technical controls for securing either National Security Systems or SBU level IT Systems are in place and are followed. This includes ensuring that appropriate steps are taken to implement information security requirements for IT systems throughout their life cycle, from the requirements definition phase through disposal.]]></description>
<pubDate>11/17/2009</pubDate>
</item><item>
<title><![CDATA[Primary Certifier]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg599]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





- Develop, update, and maintain appropriate Certification & Accreditation packages based on NIST standards for general support systems and major applications.


- Recommend appropriate FIPS 199 impact level designations and identify appropriate security controls based on characterization of the general support system or major application.


- Develop and maintain POA&M for all accepted risks upon completion of system C&A.


- Assist the government with developing a network of public and private sector organizations capable of providing cost effective, quality, system and network security assessment and certification based on unified federal guidelines and procedures.


- Integrate with a team of skilled information technology security professionals demonstrating competence in the application of the system certification guidelines and procedures.]]></description>
<pubDate>11/17/2009</pubDate>
</item><item>
<title><![CDATA[Sr. IT Security Architect]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg604]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





- Develop and Maintain a TSA Specific IT Security Architecture.


- Develop Federal Enterprise Architecture Framework based Present Architecture, and Future Architectures.


- Develop Federal Enterprise Architecture Framework based Transition Plan.


- Develop individual detailed IT Security technical reference models.


- Perform product evaluations against IT Security policy and business requirements.


- Interface with DHS and Components on all phases of Architecture.


- Extract and maintain Security Requirements from Policy, Standards and Best Practices as required.


- Develop a method of integrating Security Requirements throughout the TSA based System Development Life Cycle.


- Update and maintain risk management framework documentation


- Coordinate with engineering and the Enterprise Architect to review proposed new products for enterprise implementation.]]></description>
<pubDate>11/17/2009</pubDate>
</item><item>
<title><![CDATA[Vulnerability Assessment Tester]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg580]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret clearance is required with the ability to get SCI.





Any candidate accepted for this position will be responsible for carrying out vulnerability assessments and penetration tests on a wide range of information technology in support of the FBI certification and accreditation process.





Requirements:


Successful candidates must possess a thorough working knowledge of common commercial and/or open source vulnerability assessment tools and techniques used for evaluating operating systems, networking devices, databases and web applications. Applicants will be asked to demonstrate their knowledge in a computer laboratory environment.  





Successful candidates should be familiar with certification and accreditation processes in general; experience with the NIST 800 series of documents would be advantageous.





Successful candidates must be able to quickly master new technology/software for the purposes of evaluating the security functionality of the technology/software.]]></description>
<pubDate>11/17/2009</pubDate>
</item><item>
<title><![CDATA[C&A Subject Matter Expert]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg570]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





This candidate will provide leadership to a team of information security and C&A professionals.  Vulnerability assessment, security guidance and documentation review will be conducted by this individual on a regular basis. Additionally, this person will have a direct impact on current and future information security processes and policy across the enterprise.





Requirements:


The successful candidate will have at least seven years in the information security field, with a concentration on Certification and Accreditation (C&A) as it applies to FISMA. Four of these years must be in a lead security design or technical task/program leadership position. Must possess a strong background with NIST.





This candidate should possess a B.A. or B.S. in related field and 7 years of experience. B.A. or B.S. may be substituted with 4 additional years of professional Information Assurance services experience.]]></description>
<pubDate>11/16/2009</pubDate>
</item><item>
<title><![CDATA[Primary Certifier/IT Security Specialist]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg574]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





- Develop, update, and maintain appropriate C&A packages based on NIST standards for general support systems and major applications.


- Recommend appropriate FIPS 199 impact level designations and identify appropriate security controls based on characterization of the general support system or major application.


- Develop and maintain POA&M for all accepted risks upon completion of system C&A.


- Assist the government with developing a network of public and private sector organizations capable of providing cost effective, quality, system and network security assessment and certification based on unified federal guidelines and procedures.


- Integrate with a team of skilled information technology security professionals demonstrating competence in the application of the system certification guidelines and procedures.


- Work with RMS and Trusted Agent FISMA to develop C&A related documentation and track POA&M and vulnerability status.





Requirements:


- Must possess 2 years dedicated information assurance/cyber security experience. B.S. Degree in a related field required but may be substituted with 4 additional years of security related experience.


- Ability to and interest in providing support and guidance to System Owner's through the four phases of C&A, including monitoring C&A artifact compliance, annual self-assessment (NIST 800-53A) completion, vulnerability scans, annual contingency plan testing, and POA&M management. Must possess experience with FISMA.


- Ability to work effectively in a team management environment and participate in collaborative initiatives which foster the mutual exchange of knowledge and expertise. 


- Must be able to multi-task, work independently and as part of a team, share workloads, and deal with sudden shifts in project priorities.


- Ability to communicate effectively orally and in writing to build and maintain customer satisfaction and express conclusions in a clear, technically sound manner on matters associated with IT security.


- Experience with developing Security Test and Evaluation Plans and analyzing the results of security test activities to evaluate the existence and effectiveness of 800-53 security controls.]]></description>
<pubDate>11/16/2009</pubDate>
</item><item>
<title><![CDATA[Sr. IT Security Engineer/C&A]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg598]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





This candidate will be a leading member of the Information Assurance Governance team at the customer location. This team is responsible for evaluating, improving and developing all information security related processes for the customer. Additionally, this team plays a key role in evaluating new technology for potential security vulnerabilities and ensuring secure communication paths between the customer and other agencies and organizations. The successful candidate will be in a position of leadership on a number of high-visibility projects and responsible for deliverables impacting the agency as a whole.]]></description>
<pubDate>11/16/2009</pubDate>
</item><item>
<title><![CDATA[Security System Analyst]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg596]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Secret clearance is required and must be clearable to the TS/SCI level.





Candidate will be doing the job of a Real Time analyst. 24/7 real time monitoring of AF network, doing initial identification of potential intrusions to pass to incident response for further development.  Additional responsibilities may include: 


- Perform log analysis.


- Perform packet analysis and be able to identify malformed packets.


- Be able to analyze the payload of the packet.


- Define the relationship between seemingly unrelated events.


- Use search engines and ArcSight knowledge base and reference pages.


- Perform advanced queries of NSD historical and reference databases.


- Make recommendations for rule and filter modifications and creation in IDS and ArcSight.


- Be able to take required elements of a report and create a properly formatted report.


- Understand differences between various operating systems - which OS an event came from and which OS is vulnerable to a certain attack.





Requirements:


- Ideally, candidates should possess a Masters degree and 5 years of experience; or a Bachelors degree and 8 years of work experience; or 15 years total working experience.  At least 2 years for their working experience must be in a technical field. NOTE THAT THIS IS NOT A FIXED REQUIREMENT - ONLY A TARGET.


- Ideally, should have minimum of 5 years of IDS/IPS experience. Must have minimum of 2 years experience - preferably with computer and network security, intrusion detection and network monitoring, or combined training within the last 3 years of intrusion detection, intrusion prevention and network monitoring and Internet, and Domain name addressing; fundamental components of networks; and TCP/IP, FTP, and HTTP protocols.]]></description>
<pubDate>11/5/2009</pubDate>
</item><item>
<title><![CDATA[IDS Analyst]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg593]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret clearance is required with the ability to get SCI.





Candidates will provide intrusion/incident monitoring and detection utilizing customer provided data sources, audit and monitoring tools at the Unclass, Secret and Top Secret levels. Staff will provide security situational awareness through analysis and correlation of multiple customer provided data sources. Staff will aid with the determination and escalation of critical security events in accordance with customer direction. Must be able to provide clear and concise verbal and written communication to include compiling, writing and providing input to reports and presentations. Analysts will augment existing incident response capability when required.]]></description>
<pubDate>10/28/2009</pubDate>
</item><item>
<title><![CDATA[Primary Certifier]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg587]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Secret clearance is required. Candidate will need to get through DHS EOD approval.





- Provide Certification review of completed C&A packages based on NIST and DHS standards for general support systems and major applications.


- Review appropriateness of FIPS 199 impact level designations and 800-60 security categorizations.  Review appropriate security controls based on characterization of the general support system or major application.


- Provide comprehensive review of C&A package for completeness, accuracy, and compliance with defined DHS standards.   


- Integrate with a team of skilled information technology security professionals demonstrating competence in the application of the system certification guidelines and procedures.


- Develop comprehensive checklists for reviewing C&A packages and develop processes and procedures to promote consistent completion and review of packages.]]></description>
<pubDate>10/28/2009</pubDate>
</item><item>
<title><![CDATA[Outreach & Training Specialist]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg592]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





This candidate will be a spokesperson for information security topics at this government agency. This individual will work with senior leadership to address all aspects of information security awareness at each level of user experience and responsibility to prevent inadvertent compromise or disclosure of sensitive information.  





Personal knowledge, professional presence and the ability to quickly grasp and explain technical concepts will be distinguishing characteristics that will allow the successful candidate to establish a well-known professional standing within both this agency and the government information security community as a whole. The candidate will be responsible for developing courses and training seminars including, but not limited to the following:


- Security Awareness training


- Role Based Security training


- Addressing IT security in Capital Planning and Investment Control


- Security costing methodology for Plans of Actions & Milestones (POA&Ms)


- Linking funding identified for corrective actions in POA&Ms to the sources of those funds


- IT security for Project Managers


- Tracking security funding and specialized IT system courses on the C&A process


- Self Assessment process


- Contingency Planning


- Risk Assessment


- Preparation of System Security Plans  





Requirements:


The successful candidate will possess a minimum of 5 years experience in developing, executing, and/or managing outreach or education and awareness training programs. A B.A. or B.S. degree is preferred. The candidate should have some experience with information security concepts, best practices, and policies. Information Security experience is not required but would be a significant plus. The candidate should have experience with relating training material in presentations to groups, via the intra/internet, group workshops, CBT or other technology. Additionally, the candidate should have experience with Federal outreach or PR campaigns. Experience with NIST 800-16 and 800-50 regarding training for IT security and knowledge requirements for specific functions is preferred.]]></description>
<pubDate>10/20/2009</pubDate>
</item><item>
<title><![CDATA[McAfee Security Engineer]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg591]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Secret clearance is required. Top Secret is preferred.





Looking for security engineers who are interested in being part of an emerging McAfee consulting practice. The opportunity will expose you to a variety of McAfee security tools in multiple client settings, allowing you to quickly build your technical expertise. Training will be provided as required and you will have access to the McAfee support infrastructure.





Candidates will be working as an extension of the McAfee Worldwide Professional Services team to deploy, configure, tune, and maintain the HBSS deployment to various government customers. Additional assignments will vary in length and will include anything from installation and deployment support, to security network engineering/architecture support. Products supported will include: ePO, HIPS, Virus-Scan, Anti-Spyware, Rogue Systems Detection.





This position would involve up to 100% travel but candidates can reside anywhere within the U.S.]]></description>
<pubDate>10/19/2009</pubDate>
</item><item>
<title><![CDATA[Sr. IT Security Architect]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg586]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





- Develop and Maintain a TSA specific IT Security Architecture.


- Familiarity with existing risk management frameworks, such as COBIT, ITIL, and ISO 27001. 


- Develop business process mapping for implementation of security policies and standards throughout enterprise.


- Develop individual detailed IT Security technical reference models. 


- Develop process flows and mapping of security architecture components as part of an enterprise architecture. 


- Interface with DHS and Components on all phases of Architecture. 


- Develop and Maintain TSA Specific IT Security Policies 


- Review and update existing policies. 


- Research and develop new policies. 


- Maintain DHS to TSA policy matrix. 


- Maintain policy outreach, i.e. Intranet and Newsletter. 


- Create and update a TSA Requirements Traceability Matrix.


- Support the ST&E efforts by reviewing the architecture design.


- Support vulnerability assessments on various types of networks and topologies. 


- Analyze output from network vulnerability assessments and recommend mitigation strategies.


- Review and provide feedback on security plans and procedures regarding all aspects of LAN, WAN or MANs, as applicable.


- Assist in designing security products to include firewalls, intrusion detection systems, antivirus, patch management, etc.; 


-  Review and provide input into network designs to ensure compliance with security and enterprise architecture.


- Provide input and visibility into emerging security technologies, deployment strategies and other security protocols to ensure awareness within the IT Security Branch. 


- Build/enhance security architecture and configure network to enhance the security posture of the enterprise.





Requirements:


- B.A. or B.S. degree is preferred. 


- Must possess 7 or more years of experience with federal IT security. 


- CISSP, CISM, or similar information security professional certification is preferred.


- Must possess relevant security experience with security policy development, security architecture models, and information security regulatory compliance.


- Experience in the life-cycle of cyber security and computer network security technical and programmatic operations. This includes experience in:





- Penetration testing and other cyber security automated testing and monitoring tools (Not vulnerability scanning)


- Virus/malicious software identification and management 


- Computer network monitoring


- Security tool development 


- Development of strategies for managing a cyber/computer security event


- Threat Modeling


- Developing Policy, Procedure and Standards


- Cyber security best practices


- Knowledge of Comprehensive National Cyber security Initiative (CNCI), Consensus Audit Guidelines (CAG), and NIST 800-53/800-53-A]]></description>
<pubDate>10/6/2009</pubDate>
</item><item>
<title><![CDATA[Program Manager/Security Technical Lead]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg559]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





- Oversight of daily program activities. Performs cost, schedule, performance, risk, quality, security, and administrative duties relative to contract to include support to the addition of new contract tasking.  


- Provides senior level consulting to the Information Assurance Division on subjects including program development, best industry practices, and enhancement of existing program areas.


- Acts as primary customer contact for program activities, leading program review sessions with customers to discuss cost, schedule, and technical performance.  


- Provides the Customer with appropriate metrics (results, cost, and schedule) to track performance to successfully meet missions and objectives.  


- Provides reports and meets with the client, Contracting Officer, and Contracting Officer's Technical Representative as required.


- Participates in the negotiation of contract changes. 


- Coordinates the preparation of proposals, business plans, proposal work statements and specifications, operating budgets and financial terms/conditions of contract.


- Proactively implement and manage and integrated contractor IT Security Program.  


- Ensure appropriate resource and staffing needs are addressed.


- Define appropriate processes for managing deliverables and work products of personnel supporting multiple teams.


- Task management - assigning duties to team members (not otherwise assigned by Government program leads) ensuring adequate priorities of the tasks are appropriately staffed for coverage. Provide task priority de-confliction or arbitration when operational priorities conflict across teams.


- Report all pertinent matters involving the security of programs, mission support systems, and applications to the Government leads for action.


- Attend all required meetings such as senior staff meetings, working meetings, review boards and other applicable and assigned meetings.


- Ensure staff members receive annual IT Security Awareness Training and Significant Security Responsibility Training.


- Ensure team performs in a professional manner at all times. Responsible for taking appropriate administrative and disciplinary actions in a timely fashion in support of the contractor and subcontractor staff;.


- Ensure compliance of all staff members to all federally mandated laws such as security clearance requirements, building access rules, etc.  


- Provide senior level consulting as appropriate to the Information Assurance Division of ICE, such as program development, best industry practices, enhancement of existing program areas, etc.]]></description>
<pubDate>9/24/2009</pubDate>
</item><item>
<title><![CDATA[Critical Infrastructure Protection Specialist]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg560]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





Candidate will support client by providing strategic planning, technical and subject matter expertise in cyber security, malicious software, viruses and other forms of attacks against the nation's cyber infrastructure. Under the technical direction of the client lead, will support the identification of various threats, provide leadership in identification of the nature and impact of these threats and lead the development of mitigation and protection strategies to minimize the impact and risk to these threats. The candidate will also support the client by developing written presentations and communications of these threats of various government and industry partners.





The selected candidate must be able to:


- Understand policy and procedure, and analyze their applicability to the TSA/DHS programs and staff.


- Analyze security related issues and provide recommended resolution of major/critical problems.


- Leverage a strong IT security background in the identification and assessment of cyber security mechanisms of both applications and general support systems.


- Provide general and technical advice and assistance on the interpretations of cyber security requirements, developing and presenting briefings and incident information, analyzing regulatory/legislative requirements for cyber security.





Requirements:


- BA or BS degree is preferred. 


- Must possess 7 or more years of experience with federal IT security. 


- CISSP, CISM, or similar information security professional certification is preferred.


- Must possess relevant security experience with SABSA, Operational Risk Management, Enterprise Security Architecture. 





- Experience in the life-cycle of cyber security and computer network security technical and programmatic operations. This includes experience in:


- Penetration testing and other cyber security automated testing and monitoring tools (Not vulnerability scanning).


- Virus/malicious software identification and management.


- Computer network monitoring.


- Security tool development.


- Development of strategies for managing a cyber/computer security event.


- Threat Modeling.


- Developing Policy, Procedure and Standards.


- Cyber security best practices.





- Should be familiar with DHS and NIST security policy and be able to review against Security Architecture technical requirements .


- Must have knowledge of enterprise security architecture, SABSA, network design, and operational risk management.


- Familiarity with existing risk management frameworks, such as COBIT, ITIL, and ISO 27001. 


- Must possess strong written and verbal communications skills, including technical writing and presentation (Skilled in PowerPoint, Word, Excel, Visio, Project. With the ability to create simple graphics/flowcharts and format documents).


- Ability to lead working sessions and stakeholder meetings.


- Knowledge of Comprehensive National Cyber security Initiative (CNCI), Consensus Audit Guidelines (CAG), and NIST 800-53/800-53-A.


- Commercial or Government Security or Risk Compliance/Certification experience (PCI, FISMA, additional Risk Management compliance).


- Commercial business experience.]]></description>
<pubDate>9/16/2009</pubDate>
</item><item>
<title><![CDATA[Lead Primary Certifier]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg513]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Must be clearable to the Top Secret level.





- Successful candidate will function as co-team lead for a team of Certification specialists.


- Will be responsible for maintaining accreditation status for all major applications and general support systems within FISMA inventory. 


- Will interact with primary certifiers, ISSO's, System Owners, and Security Test Engineers to ensure certification packages are complete and approved in accordance with component and departmental level standards.


- Develop, update, and maintain appropriate Certification & Accreditation packages based on NIST standards for general support systems and major applications.


- Recommend appropriate FIPS 199 impact level designations and identify appropriate security controls based on characterization of the general support system or major application.


- Develop and maintain POA&M for all accepted risks upon completion of system C&A.


- Assist the government with developing a network of public and private sector organizations capable of providing cost effective, quality, system and network security assessment and certification based on unified federal guidelines and procedures.


- Integrate with a team of skilled information technology security professionals demonstrating competence in the application of the system certification guidelines and procedures.]]></description>
<pubDate>9/10/2009</pubDate>
</item><item>
<title><![CDATA[Software Engineer]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg416]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret clearance is required.





The Software Engineer will be an Enterprise Portal developer as part of the User Interface software development team. The program is developing a Services Oriented Enterprise system that has many different user facing components that are presented via a Web Application, Web Portal, and various COTS products.





The Software Engineer will be expected to apply creative problem solving to leverage the tools and environment to design and build components for the Enterprise Portal.





Requirements:


- Bachelors degree from an accredited college in a related discipline, or equivalent experience/combined education, with 5 years of professional experience; or 3 years of professional experience with a related Masters degree.


- 2 years of J2EE Portal development


- Familiarity and understanding of the JSR-168 spec.


- 1 year of experience with the Spring Framework.


- 1 year of experience using MVC design pattern.


- Project experience with Hibernate.


- Project experience with AJAX.


- 2 years of experience with JUnit.


- 2 years of experience with Ant.


- 4 years of experience with Java web based development.


- Experience with Eclipse IDE.]]></description>
<pubDate>7/24/2009</pubDate>
</item><item>
<title><![CDATA[Sr. Software Engineer]]></title>
<link><![CDATA[http://www.cytiva.com/kcg/detail.asp?jobid=kcg415]]></link>
<description><![CDATA[Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Top Secret clearance is required.





- The FBI SENTINEL program is looking for a senior Java developer to join the Work Item Authoring (WIA) Integrated Product Team (IPT). 


- Responsible for the detailed design and implementation of forms, entity extraction, reporting, and related Java objects for the SENTINEL Case Management application. 


- This position requires substantial Customer interaction during design and development.


- Responsible for supporting integration activities with the SENTINEL Case Management application.


- Participate in full lifecycle software development, including design documentation, code reviews, unit testing.


- Assist in the analysis of system level requirements and the derivation of implementation requirements for the WFL product team.


- Coordinate all product testing activities with the Test team, and assist in the development of Test Procedures.


- Potential candidate should be highly motivated and willing to take ownership of assigned area.





Requirements:


- Bachelors degree from an accredited college in a related discipline, or equivalent experience/combined education, with 9 years of professional experience; or 7 years of professional experience with a related Masters degree. 


- 9 years experience in full lifecycle software development with at least five of those years working on Object-Oriented development using Java/J2EE. Prior experience with Automated Test Tools (such as JUnit, Cruise Control) and technical software documentation and modeling using UML are required.]]></description>
<pubDate>7/24/2009</pubDate>
</item></channel>
</rss>
