Security Engineer Mid positions focus on delivering results in their domain. This page aggregates open Security Engineer Mid roles and what employers typically expect.
Everforth ECS is seeking a **Security Engineer Mid** to work in our ***Suitland, MD*** office. Everforth ECS is a leading information security and information technology company in Suitland, MD. We are looking to hire a Mid Security Engineer to support a full range of cyber security services on a long-term contract. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background clearance. - Design and develop cybersecurity or cybersecurity-enabled products. - Design hardware, operating systems, and software applications to adequately address cybersecurity requirements. - Design or integrate appropriate data backup capabilities into overall system designs, and ensure that appropriate technical and procedural processes exist for secure system backups and protected storage of backup data. - Develop and direct system testing and validation procedures and documentation. - Develop detailed security design documentation for component and interface specifications to support system design and development. - Develop Disaster Recovery and Continuity of Operations plans for systems under development and ensure testing prior to systems entering a production environment. - Develop specific cybersecurity countermeasures and risk mitigation strategies for systems and/or applications. - Identify and direct the remediation of technical problems encountered during testing and implementation of new systems (e.g., identify and find work-arounds for communication protocols that are not interoperable). - Identify and prioritize essential system functions or sub-systems required to support essential capabilities or business functions for restoration or recovery after a system failure or during a system recovery event based on overall system requirements for continuity and availability. - Identify, assess, and recommend cybersecurity or cybersecurity-enabled products for use within a system and ensure that recommended products are in compliance with organization's evaluation and validation requirements. - Implement security designs for new or existing system(s). - Incorporate cybersecurity vulnerability solutions into system designs (e.g., Cybersecurity Vulnerability Alerts). - Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. - Design, implement, test, and evaluate secure interfaces between information systems, physical systems, and/or embedded technologies. - Design, develop, integrate, and update system security measures that provide confidentiality, integrity, availability, authentication, and non-repudiation. - Design to security requirements to ensure requirements are met for all systems and/or applications. - Develop mitigation strategies to address cost, schedule, performance, and security risks. - Perform security reviews and identify security gaps in architecture. - Trace system requirements to design components and perform gap analysis. - Verify stability, interoperability, portability, and/or scalability of system architecture. ***Salary Range:** $102,000- $112,000[General Description of Benefits](https://ecstech.com/careers/benefits)* - Strong written and verbal communication skills. - Knowledge of secure configuration management techniques. (e.g., Security Technical Implementation Guides (STIGs), cybersecurity best practices on cisecurity.org). - Working knowledge of CRIBL. - Knowledge of software development models (e.g., Waterfall Model, Spiral Model). - Knowledge of software engineering. - Knowledge of structured analysis principles and methods. - Experience designing architectures and frameworks. - Knowledge of system design tools, methods, and techniques, including automated systems analysis and design tools. - Knowledge of the systems engineering process. - Knowledge of Supply Chain Risk Management Practices (NIST…