Full-Time

Information Security Compliance Engineer

Posted on 9/5/2024

Axle

Axle

201-500 employees

Provides informatics solutions for biomedical research

Compensation Overview

$150k - $160k/yr

Mid, Senior

North Bethesda, MD, USA

Category
Cybersecurity
IT & Security
Required Skills
TCP/IP
Git
Docker
JIRA
Confluence
Development Operations (DevOps)
Splunk
Linux/Unix
Requirements
  • Must Have hands on Linux/Unix experience and know how secure the systems.
  • Understand how to implement security controls based on NIST 800-53.
  • Must have hands on Linux/Unix administration experience and familiarity with Windows environments.
  • Ethical hacking experience and (CEH) familiarity a big plus.
  • Must have experience with Identity and Access Management (IAM) and tools.
  • Must be able to conduct and lead technical reviews and analysis with infrastructure and application teams.
  • Must be able to troubleshoot security incidents and lead the other technical teams to resolve incidents as well as remediate the threats and concerns.
  • Must be able to provide guidance on security control implementation and perform technical tasks when needed for Windows, Linux/Unix environments.
  • Must be familiar with networking and other infrastructure components such as traffic flow, access management and Active Directory etc.
  • Be able to manage cyber risks by providing guidance to secure system designs, baseline configuration assistance and administer ATO preparation activities.
  • Be able to manage and administer the security tools and have hands on working experience with Tenable Nessus, Netsparker, Trellix suite, Palo Alto, BigFix, Splunk, etc. and cloud-based equivalents.
  • Must have experience with DevOps security controls implementation.
  • Must be familiar with GitHub, Docker and in general with the CI/CD pipeline security.
  • Assist in security incident response efforts.
  • Work with other teams to integrate the NCATS Threat and Vulnerability Management processes with the patching cycles, baseline configurations and CIS benchmarks.
  • Must be familiar with database server architecture and be able to provide security support to the database team.
  • Must be familiar with Cloud environments and tools.
  • Must be familiar with Risk Management Framework (RMF) and Government mandates such as continuous diagnostic mitigation (CDM) and Binding operations directives (BODs)
  • Identify, analyze, and develop mitigation or remediation actions for POA&Ms
  • Assist with a reliable patch and compliance management mechanism for all on-premises and cloud systems.
  • Recommend, configure, and install advanced firewalls and centrally manage other security tools in multiple cloud environments.
Responsibilities
  • Manage daily Cybersecurity Operational activities.
  • Proactively Manage Cybersecurity Operations projects and tasks and ensure on time delivery.
  • Take initiatives to identify, analyze and remediate weaknesses and present reports to the management.
  • Lead and mentor the NCATS CSS Cybersecurity Operations team with hands on security tools support.
  • Must be able to represent NCATS CSS team and provide technical security guidance in troubleshooting calls.
  • Must have hands on experience with firewalls, load balancers switches, routers, Windows and Linux/Unix servers.
  • Must have expert understanding of TCP/IP and networking principles.
  • Must be familiar with GitHub and container security techniques.
  • Take the lead on securing NCATS system and applications through system hardening.
  • Must be able to secure DevOps pipelines by providing technical security guidance and support to the application and infrastructure teams.
  • Lead the security operations in proactively managing threats, vulnerabilities and remediation efforts.
  • Must be familiar with Risk Management Framework (RMF), NIST 800-53 and other Government mandates.
  • Provide security controls implementation support for NCATS Cybersecurity ATO preparations efforts following Risk Management Framework (RMF).
  • Have a solid understanding of the ATO preparation and security controls implementation process.
  • Lead ATO technical guidance efforts and help write documents such as System Security Plans (SSPs).
  • Schedule and coordinate operational activities, sessions, and meetings with the stakeholders.
  • Provide effective guidance to the stakeholders on secure baseline configurations.
  • Manage work through tools such as NIH incident response (IRT) portal, Splunk, ServiceNow, Jira, Confluence etc.
  • Establish communications with vendors for the release of newly identified vulnerabilities and to ensure they understand the specialized requirements of the client’s information systems.
  • Develop daily, weekly, and annual NCATS security landscape metrics.
  • Help the Vulnerability Management team to Identify, analyze, and develop mitigation or remediation actions for system and network vulnerabilities.
  • Monitor the progress of internal and external organizations to ensure operational requirements are fulfilled for audits and reviews.

Axle Informatics provides specialized solutions that combine bioscience and information technology, focusing on translational research, health informatics, and data science. Their products help research centers and healthcare organizations turn scientific discoveries into practical applications, such as new treatments and diagnostics. Axle develops research tools that enhance decision-making by utilizing advanced analytical models, algorithms, and visualization tools to manage large volumes of data. This automation allows researchers to efficiently track and analyze data, leading to improved healthcare outcomes. Unlike many competitors, Axle emphasizes customized software and data management platforms that facilitate the transition from laboratory research to clinical application, known as moving from "bench to bedside." The company's goal is to advance public health by providing effective informatics solutions that support biomedical and clinical research.

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

Rockville, Maryland

Founded

2002

Simplify Jobs

Simplify's Take

What believers are saying

  • Rising demand for AI-driven data analytics boosts Axle's healthcare partnerships.
  • Precision medicine's growth aligns with Axle's computational biology expertise.
  • Global health informatics market growth enhances Axle's competitive edge.

What critics are saying

  • Increased competition from companies like Indica Labs may reduce market share.
  • Rapid digital pathology advancements require significant R&D investment to stay competitive.
  • Dependence on partnerships for large contracts poses risks if partnerships dissolve.

What makes Axle unique

  • Axle Informatics specializes in bioscience and IT, focusing on translational research.
  • The company offers advanced solutions in health informatics and data science.
  • Axle leverages expertise in biomedical science and software engineering for research tools.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Paid Vacation

Paid Holidays

401(k) Company Match

Educational Benefits for Career Growth

Employee Referral Bonus

Flexible Spending Accounts

Company News

The GWW
Jul 25th, 2023
“Octo awarded $64.7M IT Infrastructure Call Order to support NCI’s Cancer research”

Octo, in partnership with Unissant, Axle Informatics, and TRex, has been awarded an IT Infrastructure and Operations Call Order to support the NCI’s OCIO.

GlobeNewswire
Jan 12th, 2023
Digital Pathology Market Worth $1.86 Billion by 2030 -

For instance, in May 2020, Indica Labs (U.S.), a provider of digital pathology solutions, collaborated with information technology consulting companies, Octo (U.S.) and Axle Informatics (U.S.) and the National Institutes of Health (NIH) (U.S.), to develop an online collection of high-resolution histopathology images of tissues from COVID-19 patients using Indica’s HALO Link platform.

INACTIVE