Company Overview
Spry brings a unique blend of proven service delivery, scalable and agile corporate infrastructure, and the ability to recruit and retain the best and brightest in the industry to support our customers. The Spry team engages in exciting and rewarding opportunities that challenge their abilities, in an atmosphere that encourages both personal and professional growth, fostering a positive and energetic work environment.
Position Overview
Spry Methods is searching for a strong Cybersecurity Subject Matter Expert to provide expertise in the secure development, engineering, and migration of critical systems and applications to the cloud.
Job Responsibilities and/or Success Factors
- Performs or leads security requirements analysis, security requirements definition, system security design, security architecture generation, security trade studies, and security verification and validation with little or no supervision.
- Executes the security testing and evaluation to ensure the correct implementation of security requirements.
- Supports system development by adding security rigor to the design, assessing the security posture, and hardening dynamic operating environments.
- Act as the main security interface with integration and/or development team to solve complex security problems while adhering to prescribed NIST 800 Special Publication series.
- Collaborates with teams to perform security control assessment activities.
- Conducts research and performs security analysis on the impacts of system designs, modifications, and technological initiatives.
- Reviews security architecture design to determine level of security compliance.
- Performs automated verification of DISA STIGs and other security benchmarks against web and appliance configurations.
- Synthesizes security solutions within the context of the system to meet customer expectations while staying within schedule and cost constraints.
- Researches and analyzes data, such as vendor products, COTS components, GFE/CFE, specifications, and manuals to determine security of design.
- Effectively chooses the appropriate standards, processes, procedures, and tools throughout the system development life cycle to support the generation of the security engineering products.
- Assists in drafting program required security documentation, including items such as security plans, technical configurations, concepts of operations, certification and accreditation documents, and procedures in compliance with the IA policy.
- Performs vulnerability scans and analysis of the scan results.
- Periodically conducts code reviews to ensure compliance with organizational policies and guidelines and best practices.
Required skills and experience include
- CISSP or equivalent certification
- Must have an active Top Secret security clearance and candidates must be willing to take a CI Poly
- Bachelor of Science degree in Engineering, a related specialized area or field is required (or equivalent experience) plus a minimum of 6 years of relevant experience; or Master's degree plus a minimum of 4 years of relevant experience
- Experience/Familiarity with Linux, Windows Server, JBoss, SQL Server, Marklogic, and Oracle
- Experience with agile project management tools
- Proficient with Microsoft Office suite of products
- Strong use and understanding of systems engineering concepts, principles, and theories
- Strong understanding of cyber security specifications such as Risk Management Framework (RMF), STIGs and other government security specifications and guidelines
- Strong knowledge of cyber security technology and trends
- Highly responsible, team-oriented individual with a very strong work ethic and a self-starter
- Effective organizational skills with strong attention to detail
- Ability to work in a fast paced, constantly changing environment
- Must be a team player and work in a collaborative team environment
- Strong written and verbal communications skills
- Effective in communicating issues, impacts, and corrective actions as they affect the cyber design and implementation
- Strong ability in reporting relevant cyber systems engineering design
Preferred Skills
- Creative thinker, good multi-tasker
- Knowledge and/or experience with secure cloud solutions (i.e., Amazon Web Services, Azure) and tools
- Contact with project leaders and other professionals within the Engineering and Development departments and with project teams
- Has received training and/or certifications in one or more of the following:
- Cloud Certified Security Professional or Cloud Security Solutions
- IT Infrastructure Language
- Web Application and Database Security
Perks of Working for Us (Benefits):
Medical Coverage – United Healthcare - 3 Options
- Traditional - POS Choice Plus Network
- HDHP - POS Choice Plus Network
- HDHP - EPO Choice Network
Vision Coverage – VSP - Vision Service Plan
Dental Coverage – Guardian Dental - PPO Premier Plan or Value Plan
Paid Holidays: Full-time employees receive 11 paid federal holidays
Paid Time Off (PTO) – PTO accrual starts at 15 days per year
Training Benefit – Annual training allowance available toward any job-related training or education
401 (k) – Multiple Fund Choices through Fidelity with a company match
For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/
EEO Statement
At Spry, we believe talented and dedicated employees are our most valued assets and the foundation of our success. We are committed to crafting a diverse and inclusive workplace that endorses engagement, creativity, quality and innovation.
We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.