What are the responsibilities and job description for the Information System Security Engineer 3 position at First Tek, Inc.?
Title: Information System Security Engineer 3
12 months contract
Vancouver, WA
Onsite role- 5 days per week (only local candidates of Oregon or Washington)
REQUIREMENTS
Education & Corresponding Experience (required on matrix)
• Bachelor of science in computer science, information technology or a directly related technical discipline is highly preferred.
o 10 years of experience is required with an applicable bachelor’s degree.
o 12 years of experience is required with an applicable associate’s degree.
o 14 years of experience is required without a degree or an applicable.
• Experience must include the following:
o Hands-on technical implementation of networks and systems.
o Experience evaluating various technical, operational, and management solutions to security problems, using written language and various media to present alternatives and recommendations.
o Proven ability to develop documentation sufficient to arrive at logical and comprehensive conclusions and recommendations. The documentation must be of a sufficient professional level to stand as an artifact for reuse as part of the security architecture.
o Experience evaluating the adequacy and existence of OT security controls as it conforms to security architectures.
o Experience having properly documented evidence of security architecting, design, and cyber-security activities sufficient for a third-party reviewer to arrive at the conclusion the Security control Assessor has reached in the work.
• 3 years previous experience effectively performing security control implementation on networks, servers and systems and/or vulnerability assessments.
Required Technical Skills & Experience (required on matrix)
• One or more of the following networking or security certifications:
o Certified Information Systems Security Professional (CISSP)
o Certified Information Systems Auditor (CISA)
o Certified Information Security Manager (CISM)
• 5 years of experience performing security control evaluation and testing.
• 8 years of experience with North American Electric Reliability Corporation, Critical Infrastructure Protection (NERC CIP) regulatory standards and requirements.
• 10 years of experience with the Risk Management Framework and the 800 series of National Institute of Standards & Technology (NIST) Special Publications (in particular 800-37, 800-39, 800-53, 800-53A, 800-82 and 800-115).