Senior Principal Consultant - Security A&A Engineer (Clearance Required)
Reston, VA, United States
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Full Time Senior-level / Expert Clearance required USD 87K - 178K
Oracle
Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.Must current hold and have the ability to maintain a TS/SCI with Poly.
We are seeking a highly experienced and motivated Information Systems Security Analyst to join a new and exciting task order. The ideal candidate will play a critical role in assisting with driving all assessment & authorization (A&A) efforts for a new data platform. Working along side a team of technical engineers, this role requires both cybersecurity experience and technical saavy. In this role, you will use NIST 800-53 RMF framework, prepare all A&A documentation, managing milestones and work with the project team to gain an Approval to Operate a new system. This includes creating documents such as SSPs, Contingency Plans, Access Control Plans and more.
Responsibilities:
- Serve as a security advisor for project teams on all initiatives that may have an impact on security. As part this, the ideal candidate will be able to act as liaison between the project teams and key members of cybersecurity leadership.
- Initiate and drive the A&A process for all new project systems.
- As part of A&A preparation efforts, proactively identify potential risks associated with systems and advise on mitigation strategies.
- Drive efforts to produce appropriate artifacts to support A&A control responses.
- Identify and work with key A&A stakeholders to ensure all system documentation is kept up to date and reflects current security configurations, architecture, and data flow.
- Participate in all A&A status and technical exchange meetings (TEM) and facilitate discussions around control responses. You will be working with non-security minded team members; you must be able to explain/breakdown controls and security concepts to help the team provide you with responses. If a protective measure is not in place, you must be able to think in terms of compensating measures and processes.
- Be able to analyze, interpret, and apply changes to A&A control requirements and Federal cybersecurity guidance with respect to customer systems.
- Be able to communicate the current state, and discuss future state, security posture of customer systems to Oracle and Customer leadership and/or via designated reporting mechanisms.
- Conduct thorough reviews all vulnerabilities from malware scans, as well as architecture, and defense-in-depth strategies and report findings in POA&Ms document.
Required Skills and Qualifications:
- Experience with NIST 800-53 and Implementing Risk Management Framework (RMF)
- Experience with creating security and managing security documentation, both creating from scratch and updating in include mitigation of risks
- Knowledge of cybersecurity procedures, processes, and plans in accordance with customer needs and changes in cybersecurity federal regulations and/or accreditation requirements
- Understanding of vulnerability assessment tools like Rapid7 or Nessus
- Knowledge of User Access Monitoring, Identity Access Management and controls
- Experience in creating and reviewing system design documents and workflows
- Ability to work with technical team members and translate to non technical staff and customer leadership
- Must demonstrate proficiency in the following areas: multi-tasking, critical thinking; and the ability to work quickly, efficiently, and accurately in a dynamic and fluid environment
- Ability to work independently and as part of a team
Desired Skills and Qualifications:
- Certifications: Security+, CISSP, Network+, GSEC
- Experience with analyzing and advising on securing IT infrastructures on-premise and in the Cloud
- Understanding of Cloud principals and engineering
- Understanding of software development lifecycle and application security
- Experience with Terraform, SIEM and ML/AI governance a plus
Required Credentials and Experience:
- 6+ years of experience relevant to this position
- Bachelor’s Degree in engineering, computer science, business, or related discipline. Master’s degree preferred.
- Must possess a TS/SCI security clearance with Polygraph
Join us to be part of a forward-thinking team that’s pushing the boundaries of what’s possible in enterprise data engineering. Your expertise will help shape a scalable, reliable, and efficient data platform supporting mission-critical business decisions.
Disclaimer:Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.
Range and benefit information provided in this posting are specific to the stated locations only
US: Hiring Range in USD from: $87,000 to $178,100 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
Career Level - IC3
As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s challenges. We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.
We know that true innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing an inclusive workforce that promotes opportunities for all.
Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.
We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_mb@oracle.com or by calling +1 888 404 2494 in the United States.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Tags: Application security CISSP Clearance Clearance Required Cloud Computer Science Governance GSEC Malware Monitoring Nessus NIST NIST 800-53 Oracle Polygraph Risk management RMF SDLC Security Clearance SIEM System Security Plan Terraform TS/SCI Vulnerabilities
Perks/benefits: 401(k) matching Career development Competitive pay Equity / stock options Flex hours Flexible spending account Flex vacation Health care Insurance Medical leave Parental leave Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.