Accenture Federal Services logo
Accenture Federal Services
Posted 25 days agoVerified live 2d ago

Information Security Systems Engineer (ISSE)

Brief overview

Remote
UndergradOr in progress
$106k–$221k/yrStated range
2+ yrsMinimum
Clearance requiredU.S. government
NIST Risk Management Framework (RMF)NIST SP 800-171Information Systems Security EngineeringVulnerability AssessmentSecurity Controls and STIGsAssessment and Authorization (A&A)Risk ManagementMicrosoft Office SuiteSoftware Development Life Cycle (SDLC)FedRAMPCISSP

Job description

Summary

Accenture Federal Services is seeking a mid-level Information Security Systems Engineer to support its internal CISO organization and portfolio teams. The role integrates cybersecurity practices into business operations, manages security compliance and risk activities, and develops authorization, assessment, and security documentation.

Responsibilities

  • Work with project teams to develop and maintain bodies of evidence (BOE) for information systems, custom application, services, and networks
  • Must be able to understand and implement Client Data Program (CDP) program with project teams
  • Develop and disseminate system security policies, processes, and likewise governing products in service of maintaining a low operational risk posture
  • Work with project teams to conduct internal vulnerability assessments and facilitate external audits of security controls
  • Coordinate security-related tasks and activities across other functional areas E.g., Program Management, Engineering, Software Development, supply chain risk etc
  • Produce documentation in response to, and satisfaction of information security requirements
  • Work with project teams to develop Authorization to Operate (ATO) Packages and ATO supporting documentation. Examples are: SSPs, POA&Ms, SCTMs, Certification Test Reports, Briefings, Continuous Monitoring Plan and Training products
  • Conduct Security Impact Analyses (SIA) on System Change Requests for systems that have been authorized by CISO
  • Must be able to manage multiple priorities and complex tasks in a dynamic work environment
  • Must have the ability to translate technical concepts to semi-technical clients

Skills

  • To excel in this role, you will need a strong foundation in risk management and problem-solving, as these skills will be critical in identifying vulnerabilities and implementing effective countermeasures that project teams can use to supplement their security knowledge
  • Familiarity with tools and processes related to threat detection, vulnerability assessments, and supply chain risk management will be highly advantageous
  • Additionally, experience working in cross-functional teams and collaborating with technical experts in security engineering and architecture will help you navigate the complexities of this role
  • Your ability to communicate effectively with both technical and non-technical stakeholders will be essential in driving security initiatives forward and fostering a culture of cybersecurity awareness across the organization
  • Must be able to manage multiple priorities and complex tasks in a dynamic work environment
  • Must have the ability to translate technical concepts to semi-technical clients
  • Bachelor's degree in a related area or equivalent experience (4 years)
  • 2-5 years of experience configuring and securing systems to achieve compliance with Security requirements (Controls, STIGS)
  • 3+ years of experience conducting Assessment and Authorization (A&A) using Risk Management Framework (RMF) activities; across all 6 steps
  • 2-5 years expertise administering risk management in an enterprise or tactical environment
  • 5+ year's experience and competency with the Microsoft Office Suite. E.g., Word, Excel, PowerPoint etc
  • 2+ years working with and understanding systems, and the Software Development Life Cycle (SDLC)
  • Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States
  • The ideal candidate will have working knowledge of various NIST guidance and frameworks such as NIST's Risk Management Framework (RMF), and NIST SP 800-171
  • Experience working with non-traditional IT (Example - Small, purpose-built computers and/or networked sensor equipment is a Plus)
  • Cloud experience (vendor agnostic), FedRAMP knowledge
  • CISSP or equivalent certification
  • Security Clearance: Active Secret

Qualifications

Must Haves

  • To excel in this role, you will need a strong foundation in risk management and problem-solving, as these skills will be critical in identifying vulnerabilities and implementing effective countermeasures that project teams can use to supplement their security knowledge
  • Familiarity with tools and processes related to threat detection, vulnerability assessments, and supply chain risk management will be highly advantageous
  • Additionally, experience working in cross-functional teams and collaborating with technical experts in security engineering and architecture will help you navigate the complexities of this role
  • Your ability to communicate effectively with both technical and non-technical stakeholders will be essential in driving security initiatives forward and fostering a culture of cybersecurity awareness across the organization
  • Must be able to manage multiple priorities and complex tasks in a dynamic work environment
  • Must have the ability to translate technical concepts to semi-technical clients
  • Bachelor's degree in a related area or equivalent experience (4 years)
  • 2-5 years of experience configuring and securing systems to achieve compliance with Security requirements (Controls, STIGS)
  • 3+ years of experience conducting Assessment and Authorization (A&A) using Risk Management Framework (RMF) activities; across all 6 steps
  • 2-5 years expertise administering risk management in an enterprise or tactical environment
  • 5+ year's experience and competency with the Microsoft Office Suite. E.g., Word, Excel, PowerPoint etc
  • 2+ years working with and understanding systems, and the Software Development Life Cycle (SDLC)
  • Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States

Nice to Haves

  • The ideal candidate will have working knowledge of various NIST guidance and frameworks such as NIST's Risk Management Framework (RMF), and NIST SP 800-171
  • Experience working with non-traditional IT (Example - Small, purpose-built computers and/or networked sensor equipment is a Plus)
  • Cloud experience (vendor agnostic), FedRAMP knowledge
  • CISSP or equivalent certification
  • Security Clearance: Active Secret

More jobs like this