Cyber Security Continuous Monitoring Team Supervisor

Relocation
Apply
AI Summary

Lead the continuous monitoring program across IT and operational technology environments. Develop and execute the program, and collaborate with cross-functional teams for vulnerability assessment and remediation. Possess advanced cyber security principles and experience with MITRE ATT&CK framework.

Key Highlights
Lead the continuous monitoring program.
Develop a strategy for risk mitigation and prioritization.
Collaborate with cross-functional teams for vulnerability assessment and remediation.
Key Responsibilities
Spearhead the continuous monitoring program across IT and Operational Technology environments.
Build and execute the roadmap for the program.
Develop a strategy to mitigate risks and improve visibility across IT and OT environments.
Enforce continuous discovery, assessment, and remediation status of enterprise-wide assets.
Technical Skills Required
GIAC Enterprise Vulnerability Assessor (GEVA) GIAC Security Essentials (GSEC) Certified Information Systems Security Professional (CISSP) MITRE ATT&CK framework CVE database CVSS System OWASP Testing Guidelines OWASP Application Security knowledge framework DHS Continuous Diagnostic and Mitigations (CDM) tools Scanning best practices for hardware and software asset management
Benefits & Perks
Comprehensive salary package
Medical, dental, and vision
Pension and 401k
Paid time off and 96 hours of paid holidays
Relocation package
Tuition assistance and reimbursement
Nice to Have
GIAC Enterprise Vulnerability Assessor (GEVA)
GIAC Security Essentials (GSEC)
Certified Information Systems Security Professional (CISSP)

Job Description


Job Description

Mission Support and Test Services, LLC (MSTS) manages and operates the Nevada National Security Site (NNSS) for the U.S. National Nuclear Security Administration (NNSA). Our MISSION is to help ensure the security of the United States and its allies by providing high-hazard experimentation and incident response capabilities through operations, engineering, education, field, and integration services and by acting as environmental stewards to the Site’s Cold War legacy. Our VISION is to be the user site of choice for large-scale, high-hazard, national security experimentation, with premier facilities and capabilities below ground, on the ground, and in the air. (See NNSS.gov for our unique capabilities.) Our 2,750+ professional, craft, and support employees are called upon to innovate, collaborate, and deliver on some of the more difficult nuclear security challenges facing the world today.

  • MSTS offers our full-time employees highly competitive salaries and benefits packages including medical, dental, and vision; both a pension and a 401k; paid time off and 96 hours of paid holidays; relocation (if located more than 75 miles from work location); tuition assistance and reimbursement; and more.
  • MSTS is a limited liability company consisting of Honeywell International Inc. (Honeywell), Jacobs Engineering Group Inc. (Jacobs), and HII Nuclear Inc.

Responsibilities

NNSS is seeking a Continuous Monitoring Team Supervisor (Supervisor II) to lead our Cyber Security Continuous Monitoring program. The candidate must possess the knowledge, skills, and abilities required to lead the continuous monitoring team in conducting continuous monitoring, vulnerability scanning, and remediation operations within an enterprise environment. An ideal candidate will possess professional certifications such as GIAC Enterprise Vulnerability Assessor (GEVA), GIAC Security Essentials (GSEC) and/or Certified Information Systems Security Professional (CISSP) .

Key Responsibilities

  • Spearhead the continuous monitoring program across the organization's Information Technology and Operational Technology environments.
  • Build and execute the roadmap for the program, develop metrics to measure the program, and aggressively drive the reduction of risks and vulnerabilities.
  • Enforce continuous discovery, assessment, and remediation status of enterprise-wide assets.
  • Oversee deployment of the monitoring infrastructure and improve visibility across on-premises and cloud infrastructure and endpoints.
  • Develop a strategy to identify and prioritize a repeatable process to mitigate risks in the enterprise.
  • Collaborate with system owners, ISSO's and other teams within the organization's IT division to identify, track, and remediate risks.
  • Assess emergency threats for applicability and work with cross-functional teams to implement countermeasures and reduce the attack surface.
  • Communicate the state of vulnerability management to stakeholders, developers, IT, and business leaders.
  • Build and maintain dashboards that present actionable data to IT teams and IT leadership in an intuitive manner.
  • Oversee the validation and testing of complex compliance audits and vulnerability plugins to ensure accuracy of the scan results.
  • Communicate with the third-party vendors regarding issues with the scanning tools to ensure issues identified during the scanning process are troubleshooted and resolved.
  • Assists with data calls, FISMA reporting, compliance scanning and reporting, continuous monitoring, and compiling reports for auditors.
  • Contribute to an overall productive and respectful work environment by providing excellent customer service and working in a positive, collegial manner. Maintain cooperative and respectful working relationships with Cyber Security staff, other divisions, and other customers.

Qualifications

  • Bachelors' degree or equivalent training and experience in a computer-related field and at least 8 years of related experience.
  • Experience using MITRE ATT&CK framework.
  • Knowledge of vulnerability management and scanning best practices such as CVE database and the CVSS System used for scoring vulnerabilities.
  • Knowledge of network and application security principles such as OWASP Testing Guidelines, OWASP Application Security knowledge framework and ATT&CK framework.
  • Knowledge of DHS Continuous Diagnostic and Mitigations (CDM) tools and reporting structures.
  • Knowledge of scanning best practices for hardware and software asset management.
  • Preferred Additional Qualifications (please upload certificate(s) when applying):
    • GIAC Enterprise Vulnerability Assessor (GEVA)
    • GIAC Security Essentials (GSEC)
    • Certified Information Systems Security Professional (CISSP)
  • Has command of a broad range of the most advanced cyber security principles, protocols, concepts, and theories in a broad range of disciplines.
  • Ability to integrate work of specialized personnel to produce the desired results.
  • Knowledge of network-based services and client/server applications, familiarity with intrusion detection systems, familiarity with network architecture and security infrastructure placement.
  • Knowledge of vulnerabilities, mitigation strategies, network architecture, and how to apply security controls.
  • Ability to analyze network traffic, identify misconfigurations of information systems and networks, troubleshoot security appliances, independently identify network and host security vulnerabilities.
  • Understand the Windows operating system and command line tools, network protocols, and TCP/IP fundamentals.
  • Ability to maintain strict confidentiality.
  • Ability to communicate effectively in English, both verbally and in writing, sufficient to communicate with co-workers, customers, testify, write clear and concise reports, and collect information.
  • Ability to use multiple electronic devices including standard office machines, cellular phones, and security appliances.
  • Ability to articulate highly technical processes and information to a non-technical audience.
  • Ability to meet the physical requirements necessary to perform all assigned duties safely and effectively.
  • Ability to pass a federal background and obtain a “Q” clearance.
  • The primary work location will be at the Losee Road facility located in North Las Vegas, Nevada.
  • Work schedule will be 4/10's Monday through Thursday (subject to change).
  • Pre-placement physical examination, which includes a drug screen, is required. MSTS maintains a substance abuse policy that includes random drug testing.
  • Must possess a valid driver's license.
MSTS is required by DOE directive to conduct a pre-employment drug test and background review that includes checks of personal references, credit, law enforcement records, and employment/education verifications. Applicants offered employment with MSTS are also subject to a federal background investigation to meet the requirements for access to classified information or matter if the duties of the position require a DOE security clearance. Substance abuse or illegal drug use, falsification of information, criminal activity, serious misconduct or other indicators of untrustworthiness can cause a clearance to be denied or terminated by DOE, resulting in the inability to perform the duties assigned and subsequent termination of employment. In addition, Applicants for employment must be able to obtain and maintain a DOE Q-level security clearance, which requires U.S. citizenship, at least 18 years of age. Reference DOE Order 472.2 , “Personnel Security”. If you hold more than one citizenship (i.e., of the U.S. and another country), your ability to obtain a security clearance may be impacted.

Department of Energy Q Clearance (position will be cleared to this level). Reviews and tests for the absence of any illegal drug as defined in 10 CFR Part 707.4 , “Workplace Substance Abuse Programs at DOE Sites,” will be conducted. Applicant selected will be subject to a Federal background investigation, required to participate in subsequent reinvestigations, and must meet the eligibility requirements for access to classified matter. Successful completion of a counterintelligence evaluation, which may include a counterintelligence-scope polygraph examination, may also be required. Reference 10 CFR Part 709 , “Counterintelligence Evaluation Program.”

MSTS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability, veteran status or other characteristics protected by law. MSTS is a background screening, drug-free workplace.

Annual salary range for this position is: $103,480.00 - $165,568.00.

Starting salary is determined based on the position market value, the individual candidate education and experience and internal equity.

Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Associate

California ISO

United State

Senior Vice President of Global IT and Cybersecurity

Cyber Security
9h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Lyten

United State

Senior Security Engineer

Cyber Security
9h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Insight Global

United State

Subscribe our newsletter

New Things Will Always Update Regularly