USfalcon - Colorado Springs, CO

posted about 2 months ago

Full-time - Mid Level
Colorado Springs, CO
Professional, Scientific, and Technical Services

About the position

We have an exciting opportunity to join us in supporting one of our valued customers as an Information Security Analyst 3 (DevSecOps) to work out of Colorado Springs, CO. This is a hybrid position with a salary range of $115,000 - $150,000. The Information Security Analyst 3 (DevSecOps) will support the Modeling and Simulation (M&S) software developers in the furtherance of FedRAMP Impact Level packages and ATC/ATO matters. The candidate will design, implement, operate, and monitor SecOps solutions using tools such as AWS GuardDuty, CloudTrail, and CloudWatch; Prometheus; Grafana; Jaeger; Elastic/ELK Stack (kubewatch; fluentd; Static Code Analysis tools; third party dependency vulnerability scanners; authentication proxies; firewalls; TLS encryption; role based access control; vulnerability scanners; and patch and configuration management tools while restricting access to sensitive components such as nodes, etcd, Kubelet, Kubernetes Dashboard, and API servers. Critical to this effort, the candidate should be able to identify possible attack vectors, vulnerabilities, and proper configurations to mitigate risk to an acceptable level. The candidate will support developers in DevSecOps design, implementation, and maintenance operations to include securing Kubernetes hosts, control planes, pods, and workloads. Work with developers to ensure the Continuous Integration/ Continuous Development (CI/CD) pipeline automates security scanning and reporting to ensure secure coding practices are being followed; such as securing container images, passing vulnerability and quality scanners when code is checked into source code repositories, and adhering to role-based access control policies.

Responsibilities

  • Support the Modeling and Simulation (M&S) software developers in FedRAMP Impact Level packages and ATC/ATO matters.
  • Design, implement, operate, and monitor SecOps solutions using various security tools.
  • Identify possible attack vectors, vulnerabilities, and proper configurations to mitigate risk.
  • Integrate security principles into the development and deployment of software/hardware solutions.
  • Ensure continuous monitoring processes are installed and actively controlled.
  • Participate in root cause analysis investigations.
  • Establish DevSecOps processes to ensure permissions and configurations are appropriate.
  • Review and validate newly developed code for security concerns.
  • Facilitate data and cloud migration.
  • Collaborate with team members, management, customers, and external technical teams to identify/capture end-user requirements.
  • Ensure timely, high-quality solutions and assist in code and functionality/usability reviews.
  • Troubleshoot, debug, test, maintain and improve software; assist other team members; design, develop, document, analyze, test, integrate, debug, and analyze software and system requirements.

Requirements

  • Current DoD 8570.01-M IAT Level 2 or 3 certification (e.g., CompTIA Security +, ISC2 CISSP or must obtain within six months of hire).
  • Understanding of cloud service technologies and critical DevSecOps principles.
  • Proficiency in virtual environments.
  • Strong verbal and written communication skills and ability to interact with others in a professional manner.
  • Excellent problem solving and troubleshooting skills.

Nice-to-haves

  • Experience supporting DoD Contracts.
  • Several years' experience with DevSecOps and/or AWS.
  • Experience with FedRAMP Impact Level and/or CMMC.
  • Knowledge of Ansible, Terraform and YAML scripts is strongly desired.
  • Knowledge of common coding languages (C, C++, C#, .NET, XML, PHP, Python, Go (Golang), Groovy, JavaScript, TypeScript, HTML, CSS, WebSockets, jQuery, Junit, VUE, MATLAB, YAML, JSON, REST, and JavaScript Framework (Angular, NodeJS, Express, React, Ember, Knockout, Backbone, and/or Vue)).
  • Experience with cloud monitoring services such as Kubernetes Dashboard, Grafana, Prometheus, Jaeger, Elastic/ELK Stack.

Benefits

  • Paid holidays
  • Disability insurance
  • Health insurance
  • Dental insurance
  • Flexible spending account
  • Paid time off
  • Parental leave
  • Employee assistance program
  • Vision insurance
  • 401(k) matching
  • Life insurance
  • Pet insurance
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service