Cybersecurity Engineer 3 (Senior)

Compu-Vision Consulting Inc.

Washington, DC

JOB DETAILS
SKILLS
Analysis Skills, Application Integration, Authentication, Automation, Best Practices, CISA - Certified Information Systems Auditor, Cisco Network Systems, Cloud Computing, Computer Security, Corrective Action, Data Quality, Develop Methodologies, Documentation, FISMA - Federal Information Security Management Act, Firewalls, Hunting, Identify Issues, Identity Data Management, Incident Response, Information Technology & Information Systems, Information/Data Security (InfoSec), Infrastructure as a Service (IaaS), Internet Security, Linux Administration, Linux Operating System, Local Area Network (LAN), Metrics, Microsoft Product Family, Microsoft Windows Azure, Mobile Devices, Network Configuration Management, Operational Audit, Operations, Platform as a Service (PaaS), Procedure Development, Risk Management, Security Information and Event Management (SIEM), Software Patches, Software as a Service (SaaS), Standard Operating Procedures (SOP), Systems Administration/Management, Systems Analysis, Systems Engineering, Systems Maintenance, Technical Support, U.S. National Institute of Standards and Technology (NIST), Windows PowerShell, Wireless Security
LOCATION
Washington, DC
POSTED
30+ days ago
Job Title: Cybersecurity Engineer 3 (Senior)
Location: Washington, DC 20024.
Duration: 1 Years
Job Description:
  1. The contractor must provide a senior level cybersecurity operations engineer who will perform activities as follows with minimal supervision and guidance:
  2. Apply knowledge and skills of information systems security principles, NIST guidelines, FISMA, CISA, and federal directives, to conduct ongoing security
  3. assessments of installed systems and networks with a view to recommend corrective actions.
  4. Perform systems engineering and maintenance activities according to established standards.
  5. Apply knowledge of Networking Technologies including LAN, MS Azure, and
  6. Wireless management in security solutions implementation and troubleshooting.
  7. Develop NIGC security operations capabilities by evaluating current strategies and pursuing alignment with best practices.
  8. Ensure the effective configuration and daily operations of tools that support the
  9. NIGC cybersecurity strategy. Such tools include SEIM integration, Syslog, Network
  10. Detection and Response (NDR), Endpoint Detection and Response (EDR),
  11. Firewalls, M365 Cloud security, Defender for Cloud, and Continuous Diagnostics &
  12. Mitigation (CDM) capabilities.
  13. In collaboration with CISO and Privacy Officer develop plans, techniques, and measurable objectives to improve the development of cybersecurity and privacy measures that meet NIGC goals for protecting sensitive information.
  14. Collaborate with other teams on the integration of NIGC Applications and IT services to consider security implications and ensure that NIGC security requirements are met.
  15. Maintain threat awareness and monitor NIGC information systems for exploits and any suspicious activities. Analyze aggregated logs from security tools and perform regular threat hunting activities.
  16. Develop Security Orchestration and Automation capabilities.
  17. Adhere to Continuous Monitoring practices to evaluate the effectiveness of implemented security controls and execute proactive threat hunting activities to ensure confidentiality, integrity, and availability of information systems.
  18. Develop detection and response configuration policies to increase automation.
  19. Execute Incident Response activities to include all associated actions according to the NIGC incident response plan.
  20. Develop Incident handling procedures.
  21. Validate that sufficient and relevant information is captured and retained from security tools to support actionable security awareness and incident investigations.
  22. Collect security operations performance and NIGC security posture management metrics and prepare NIGC threat reports to inform risk management decisions.
  23. Develop and maintain accurate security operations documentation including the preparation of standard operating procedures for recurring tasks.


Mandatory Tasks
The Client requires contractor resources with the required skillsets to adequately perform the identified tasks with limited supervision from NIGC federal staff. Mandatory tasks revolve around the following technologies and standard practices:

  1. Cisco Networking
  2. Cisco Firewall
  3. Microsoft Cloud Technologies (IaaS, PaaS, SaaS
  4. Identity Management Microsoft Entra ID
  5. CUI
  6. Multifactor Authentication
  7. Mobile IOS Devices Management the
  8. Linux Operating System Administration
  9. Endpoint Detection and Response
  10. Network Detection and Response
  11. Patch Management
  12. PowerShell
  13. Log Management Syslog
  14. Security Information and Event Management
  15. Security Orchestration, Automation, and Response




About the Company

C

Compu-Vision Consulting Inc.