Cyber Security Engineer
hace 2 días
Kings Point
Cyber Security Engineer Location: Kings Point, NY (Hybrid – some days onsite, some remote) Contingent Position | IT – Information Security Role Summary The Cyber Security Engineer Lead will design, implement, and maintain the United States Merchant Marine Academy’s cybersecurity governance, compliance programs, and overall security posture. This role leads technical and administrative security efforts, including ATO lifecycle management, RMF documentation, SSP/POA&M development, vulnerability management, incident response, Zero Trust initiatives, and enterprise security monitoring. The position serves as the primary liaison to DOT, MARAD, auditors, and federal oversight bodies while ensuring continuous alignment with NIST CSF, NIST 800-53, FISMA, DOT, and MARAD cybersecurity requirements. Key Responsibilities • Ensure compliance with NIST CSF and RMF frameworks to maintain accreditation and protect system confidentiality, integrity, and availability., • Lead the development, update, and management of ATO packages, RMF documentation, SSPs, POA&Ms, and risk management artifacts., • Provide strategic and tactical security guidance, advising on both technical and administrative controls., • Direct and mature the Incident Response Program, including triage, escalation, documentation, after-action reviews, and program improvements., • Administer enterprise security policies, maintain SOPs/checklists, and drive continuous monitoring processes., • Lead threat and vulnerability management, including scanning, penetration test coordination, risk scoring, and remediation tracking., • Conduct threat landscape assessments, business impact analyses, and provide risk treatment recommendations., • Oversee creation and updates of cybersecurity procedures, including International Travel, BYOD, and secure communications., • Manage recurring reviews of SSPs, POA&Ms, annual security plans, account audits, and risk acceptance packages., • Serve as primary cybersecurity liaison to DOT, MARAD, auditors, and federal oversight entities., • Support Zero Trust Architecture initiatives and broader enterprise security modernization., • Lead quarterly and biannual Incident Response tabletop exercises and incorporate lessons learned into program updates., • Coordinate ITSEC team training and cross-functional security knowledge-sharing., • Maintain security documentation, templates, policies, and recurring reports (Awareness Bulletins, POA&M dashboards, CSAM reporting)., • Review DOT/MARAD alerts, coordinate patching, evaluate software requests, and maintain secure system configurations., • Deliver cybersecurity briefings, Awareness Bulletins, Sea Year presentations, and Indoc training; participate in cyber governance meetings such as DOT Cyber Ops, CAM, vulnerability reviews, and Change Control Board meetings. Required Technical Skills • Minimum 12 years of progressive cybersecurity experience., • Expertise with NIST RMF, ATO, C&A processes, POA&M development, and preparation for federal audits., • Experience conducting Security Testing & Evaluation, risk assessments, and developing security policies and procedures., • Experience within U.S. Government contracting or federal cybersecurity environments., • Strong leadership capabilities to guide Infrastructure, Applications, and Cyber teams toward a unified security posture., • Demonstrated ability to communicate security requirements to technical and non-technical stakeholders and lead governance meetings with senior federal leadership., • Proficiency with incident response, vulnerability management tools, security event analysis, and risk treatment methodologies. Preferred / Nice-to-Have Skills • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field., • ITIL v3 Foundation certification., • CISM, CISSP, or other advanced security management certifications., • Azure Security certifications., • Experience with Zero Trust Architecture, cloud security standards, and federal enclave cybersecurity operations., • Experience leading cybersecurity training, cyber awareness initiatives, and developing security programs., • Experience working within a college or university environment. Benefits (employee contribution): Health insurance Health savings account Dental insurance Vision insurance Flexible spending accounts Life insurance Retirement plan All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.