Information Assurance & Cybersecurity Engineer (Network Hardening & STIGs)
Description
• Clearance: Active DoD Top Secret
We are seeking an Information Assurance & Cybersecurity Engineer specializing in network infrastructure hardening to support the security, compliance, and risk management of critical network and telecommunications systems. The engineer will be responsible for applying Security Technical Implementation Guides (STIGs), implementing baseline security configurations, conducting vulnerability assessments, and maintaining compliance across enterprise and service-provider network equipment. The ideal candidate has hands-on experience configuring and securing network devices, a deep understanding of DoD cybersecurity requirements, and expertise in translating security guidelines into practical, operational network configurations.
Key Responsibilities
• Apply, validate, and document DISA STIGs and Security Requirements Guides (SRGs) across routers, switches, firewalls, optical transport, and telecommunications equipment.
• Establish, maintain, and audit secure baseline configurations for multi-vendor network devices.
• Perform automated and manual vulnerability scans using tools like ACAS (Nessus) and SCAP Compliance Checker (SCC).
• Identify, analyze, and remediate cybersecurity vulnerabilities and configuration drift across network hardware and firmware.
• Develop Plan of Action and Milestones (POA&Ms) for non-compliant controls and track vulnerability remediation through completion.
• Support Risk Management Framework (RMF) Authorization and Assessment (A&A) processes, compiling body of evidence (BoE) artifacts for network controls.
• Configure secure administrative protocols and access controls, including TACACS+, RADIUS, SSHv2, SNMPv3, 802.1X, and Role-Based Access Control (RBAC).
• Implement network-level security controls, including control plane policing, banner settings, logging (Syslog/SIEM integration), disabling unnecessary services, and port security.
• Collaborate with network operations and engineering teams to ensure security controls do not disrupt network availability or performance.
• Develop automated scripts (e.g., Python, Ansible) to streamline configuration auditing, STIG compliance checks, and bulk remediation.
• Deliver STIG Compliance Checklists and Assessment Reports, Hardened Configuration Templates for Network Equipment, Network Security Architecture Diagrams & SOPs.
Desired Qualifications
• DoD 8570/8140 Advanced Certification: IAT Level III or IAM Level II/III (e.g., CISSP, CASP+/SecurityX, CISM).
• Experience with Type 1, HAIPE and MACSEC encryptors.
• Experience with script-based automation (Python, Ansible, PowerShell) for STIG auditing and configuration enforcement.
• Familiarity with the RMF process, eMASS, and NIST SP 800-53 security controls.
• Experience with network virtualization, firewalls, and boundary defense architecture.
Requirements
- Bachelor's degree in Cybersecurity, Information Technology, Computer Engineering, or a related field (equivalent experience considered)
- 3–6 years of experience in Information Assurance, Cybersecurity, or Systems/Network Security Engineering
- DoD 8570/8140 Baseline Certification: Active IAT Level II certification (e.g., CompTIA Security+ CE, CySA+, SSCP) or higher
- Strong hands-on experience applying DISA STIGs to network hardware
- Solid understanding of core networking protocols (TCP/IP, BGP, OSPF, VLANs, VRFs, IPsec, GRE)
- Experience hardening multi-vendor network equipment (Cisco, Juniper, Palo Alto, Ciena, or Nokia)
- Experience with vulnerability management and compliance tools (ACAS/Nessus, SCAP, STIG Viewer)
- Experience with secure network administration and hardening techniques (AAA, PKI, port security, control plane defense)
- Strong technical writing skills to produce POA&Ms, compliance reports, and standard operating procedures (SOPs)
- Active DoD Top Secret clearance