ATI builds and manages collaborations that conducts research and development of new technologies to solve our nation's most pressing challenges. Our collaborations are custom-built teams of organizations from industry and academia that develop novel technologies for the federal government. Traditionally, these processes are complicated and burdensome. That's where ATI comes in. We simplify and streamline processes to make it all work. When you work at ATI, you become a part of something larger than yourself. Our collective work - no matter what department or division you work in - ultimately enables the warfighter, saves lives, and diversifies the industrial base. At our core, ATI is a service organization. We are in service to others; it's what we do, and it's who we are.
Apply at ATI.ORG; we only accept applications submitted through our applicant tracking system.
**This position offers a hybrid schedule (in-office & remote/work from home) or an onsite schedule and flexible hours. Candidates will need to reside near Summerville, SC to ensure work site flexibility.**
Position Description:
The Senior Assurance and Cybersecurity Engineer provides assistance to the Senior Information Security Manager for the overall direction of enterprise-wide security functions associated with Information Technology applications and protect information assets from intentional or inadvertent access, modification, destruction and/or disclosure. Assists with development, implementation and maintenance of security controls; works alongside the ATI Facility Security Officer for the physical security, data protection services and privacy of the corporation and its employees.
Essential Functions:
Serves as a key contact person (365x24x7) for Information Security Issues; may work extended hours to lead and resolve highly complex security problems that impact critical applications and provide required coverage during testing, system and software upgrading, emergency, disaster recovery, and/or remote response situations.
Provides hands-on support and expertise necessary to protect ATI's infrastructure and data assets.
Ensures the security, confidentiality and integrity of ATI's applications, systems and data by creating and maintaining a comprehensive security plan to include protocols, policies, procedures, and performance metrics.
Ensures that governmental regulatory requirements are addressed and followed by all ATI employees and subcontractors. This may include visiting sub-contractor sites to ensure compliance with requirements such as NIST, DFARS, GSA, NOFORN and other regulatory requirements as it pertains to ATI's projects and programs.
Ensures projects are delivered on time and within scope and budget.
Prepare documentation and security artifacts based on industry standard guidelines; defines procedures to confirm/maintain compliance with regard to NIST SP 800-171/NIST SP 800-53 and relevant DFAR clauses such as 252.204-7012 and compliance frameworks such as CMMC (Cybersecurity Maturity Model Certification).
Analyze existing policies and procedures for compliance with Federal laws, regulations, and standards; recommend remediation strategies to close security gaps.
Demonstrated experience performing Information System Security Officer (ISSO) or Information System Security Manager (ISSM) duties in a Federal or regulated environment, including creating and maintaining RMF documentation, SSPs, POA&Ms, security test plans, and continuous monitoring artifacts.
Recommend system enhancements to address identified deficiencies and improve the overall security posture.
Design, test, and integrate computer and network security tools; secure system configurations and ensure compliant deployments.
Perform system scans, interpret results, and support system administrators in resolving findings.
Conduct internal security program audits and develop mitigation strategies to address identified risks.
Documents and develops in-depth know how of company's existing IT architecture/infrastructure and technology portfolios; provides technical assistance to all team members, as needed.
Participates in security assessments and analysis to identify existing and potential areas of vulnerability; analyzes and assesses current and future threat landscapes and reports to senior management with realistic overviews.
Supports the development of strategies to mitigate risks; researches, evaluates, designs, tests, recommends and plans the implementation of new or updated information security hardware and/or software and analyzes the impact to the existing environment.
Support security incident investigations, root-cause analysis, and response.
Helps define and meet key metrics to measure the effectiveness of security controls; develops strategies and implements actions to improve protections.
Ensures that responsibilities, authorities, and accountabilities of all ATI employees with regard to Information Security are defined and understood by regularly communicating to all-associate meetings, regularly generated e-mails, in addition to other mediums of communication.
Supports the establishment of information security operational and capital budgets.
Additional Responsibilities:
Plans and executes cyber exercises to ensure company awareness and readiness in the event of a cyber-incident.
Oversees IT Security project implementations.
Functions as senior subject matter expert related to ATI security technologies.
Other duties as assigned.
Qualifications:
- BS in Computer Science or Information Systems Required, MS preferred.
- Minimum of 5 years of successfully progressive experience in IT security.
- CISSP or equivalent Cyber Security certification.
- Demonstrated experience with Splunk or other SIEM, Splunk Enterprise preferred. Experience with encryption technologies with the ability to utilize tools for network traffic analysis. Experience with Azure security, Azure Firewall preferred. Experience with Next Generation Firewalls (Palo Alto, Cisco Firepower).
- Previous experience in the design and implementation of enterprise information security policies, processes, and procedures. Knowledge of NIST Cyber Security standards to include NIST 800-171, NIST 800-53.
- Experienced in IT control areas including change management and System Development Life Cycle.
- Demonstrated experience functioning in an Incident Response Team during a rapidly evolving security incident.
- Influences decisions at an organizational level on procedures and standards for extremely complex and diverse data processing and communications network; acts with high degree of independence to establish and modify priorities.
- Works in highly sensitive, vulnerable, high risk area. Has access to high impact security interfaces.
- Demonstrated experience in communicating effectively in written and spoken form to broad internal and external entities including non-technical executives, corporate officers, employees, product and service vendors.
- Prior supervisory experience or team lead.
- U.S. Citizenship required, must be able to possess and maintain a DOD security clearance; preferred to already possess a SECRET Clearance
- This position is subject to a background check that includes a review of criminal records. In reviewing an applicant's criminal history, the company will consider prior criminal convictions that have a relationship to the job duties and responsibilities of the position. The company considers the nature of the crime, the time that has elapsed since the crime and the job duties for the position at issue in making an individualized determination. Individuals may be excluded when the company determines, based on the above factors, that hiring, transferring or promoting the applicant would pose an unreasonable risk to the business, its employees or its customers and vendors.
- If you are a qualified candidate, we encourage you to apply even if you have a prior criminal conviction(s). Convictions will not automatically disqualify the candidate, However, conviction(s) will be considered and balanced against the age of the candidate at the time of the offense, time elapsed since the offense, type of offense, potential impacts of such on the work environment, sensitivity of the position(s) available/sought, and similar independent factors relevant to the employment requirements at ATI.
Physical Requirements:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Regular physical activity to include walking, bending, stooping, reaching, standing and prolonged sitting.
Ability to speak, read, hear, and write, with or without reasonable accommodation.
Ability to use phone and computer systems, copier, fax, and other office equipment.
Must be able to occasionally move/lift up to 25 pounds with or without reasonable accommodation.
Work Environment:
This position is located in an air-conditioned, environmentally controlled atmosphere. Noise level in the work environment is usually moderate and the distraction level in the work environment is often heavy.
ATI is an Equal Opportunity Employer of Minorities, Females, Protected Veterans, and Individual with Disabilities.
ATI complies with the Pay Transparency Nondiscrimination provision mandated by Executive Order 13665.
Apply at ATI.ORG; we only accept applications submitted through our applicant tracking system. If you require accommodations to complete this application, please contact Human Resources at (843) 760-4350 or email hr@ati.org.
Anticipated starting salary is in range commensurate with education and experience:
$135,000 - $155,000