ASRC Federal Holding Company logo

Senior Cyber Security Engineer

ASRC Federal Holding Company
  • Beltsville, MD
    3 days ago

    Job Description

    ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work

    ASRC Federal is seeking a Senior Cyber Security Engineer to be a member of our Shared Services team located in Beltsville, MD.

    Work location: Hybrid/Primarily Remote (at least 2 days onsite)

    Summary: The ideal candidate will be responsible for enterprise security engineering, vulnerability and compliance management, security tool administration, incident response, and Tier II Security Operations Center (SOC) support within an enterprise environment. This role focuses on implementing and maintaining security technologies, performing vulnerability and configuration assessments, identifying and remediating security weaknesses, responding to cyber incidents, and improving enterprise security capabilities.

    The Senior Cyber Security Engineer will have strong hands-on experience with vulnerability management, security configuration assessments, STIG benchmarking and adjudication, Windows and Active Directory environments, endpoint security technologies, network architecture, and enterprise security operations. Experience with Tenable architecture, cloud security, and Microsoft GCC/GCC High environments is highly desirable.

    Key Responsibilities

    • Operate and maintain enterprise vulnerability and compliance scanning platforms, including scan policies, repositories, asset groups, credentials, schedules, and reporting.
    • Perform vulnerability assessments, security configuration assessments, and compliance scans to identify, prioritize, and track remediation of security weaknesses.
    • Conduct STIG benchmarking, analyze findings, perform technical adjudications, and document remediation or applicable exceptions.
    • Manage and optimize enterprise security technologies such as EDR/EPP/XDR, and SIEM, and identify and remediate gaps in security coverage, configuration, logging, and telemetry.
    • Investigate and respond to security alerts involving phishing, malicious URLs, malware, credential compromise, suspicious authentication activity, and endpoint threats.
    • Serve as a Tier II/Tier III escalation point for complex security investigations, engineering issues, and cybersecurity incidents.
    • Perform incident response activities including triage, containment, eradication, recovery, and root cause analysis.
    • Maintain strong understanding of Windows and enterprise infrastructure, including Active Directory, Group Policy Objects (GPOs), permissions, authentication, authorization, and access controls.
    • Support security engineering and assessment activities across Microsoft Azure and Microsoft 365 environments, including GCC and GCC High where applicable.
    • Develop scripts and automation using PowerShell, Python, or similar technologies to support security operations, vulnerability management, assessment, and response activities.
    • Collaborate with infrastructure, networking, endpoint, identity, cloud, and application teams during security investigations, assessments, and remediation efforts.
    • Document technical findings, security assessments, incident timelines, remediation recommendations, and risk-based adjudications.
    • Develop and maintain security metrics, KPIs, dashboards, and on-demand reports to communicate security posture, trends, risks, and operational performance to technical and business stakeholders.

    Required Qualifications

    • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent professional experience.
    • 9+ years of hands-on experience in vulnerability scanning, compliance assessments, STIG benchmarking, security configuration assessments, and technical adjudication.
    • Must be a U.S. Citizen or Permanent Resident (Green Card Holder).
    • Experience with cybersecurity engineering, vulnerability management, security operations, incident response, or related fields.
    • Strong understanding of Windows operating systems and enterprise Windows architecture, e.g., Active Directory, Group Policy Objects (GPOs), permissions, authentication, authorization, and access control.
    • Strong understanding of TCP/IP, DNS, HTTP/S, VPNs, firewalls, and enterprise network architecture.
    • Experience with endpoint security technologies such as EDR, EPP, or XDR.
    • Proficiency in PowerShell; experience with Python or similar scripting languages preferred.
    • Strong analytical, troubleshooting, documentation, and communication skills.
    • Ability to work independently and collaboratively in a fast-paced enterprise environment.

    Preferred Qualifications

    • Certifications such as CISSP, GCIH, GCIA, Security+, CEH, or equivalent (at least one is required).
    • Experience with Tenable Security Center/Tenable Vulnerability Management, including enterprise architecture, repositories, asset tagging, scan configuration, credentialed scanning, and compliance scanning.
    • Experience with DISA STIGs, SCAP, security benchmarks, and STIG adjudication.
    • Experience with Microsoft security technologies such as Defender for Endpoint, Defender for Identity, Defender for Office 365, and Microsoft Sentinel.
    • Experience with Microsoft Azure, Microsoft 365, GCC, and GCC High security configurations.
    • Experience with MITRE ATT&CK, threat intelligence platforms, SOAR, or security automation.
    • Experience supporting cybersecurity frameworks such as CMMC, NIST 800-53, NIST 800-171, FedRAMP, or DISA security requirements.

    We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

    EEO Statement

    ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

    Numbers & Facts

    LocationBeltsville, MD
    IndustryAerospace and Defense
    Company Size5,000 to 9,999 employees
    Year Founded2003
    Websitehttp://www.asrcfederal.com

    Benefits

    Military Leave, On Site Cafeteria, Parking, Prescription Drug Coverage, Professional Development, 401K, Employee Referral Program, Flexible Spending Accounts, Employee Events, Tuition Reimbursement, Work From Home, Life Insurance, Merchandise Discounts

    About Company

    ASRC Federal comprises a family of companies that provide mission-critical services to federal government agencies dedicated to defense, civil and intelligence support. Our customer-focused service delivery model and emphasis on operational excellence are foundational elements infused in all our companies. The reliability and quality of day-in, day-out service delivery from our family of companies ensure our customers that we keep our sights on their mission-critical priorities.

    Skills

    • Access Authorizationunmatched
    • Access Controlunmatched
    • Adjudicationunmatched
    • Analysis Skillsunmatched
    • Applications Securityunmatched
    • Authenticationunmatched
    • Automationunmatched
    • Benchmarkingunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Applicationsunmatched
    • Cloud Architectureunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Hackingunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • DNS (Domain Name System)unmatched
    • Defense Information Systems Agency (DISA)unmatched
    • Documentationunmatched
    • Endpoint Securityunmatched
    • Enterprise Architectureunmatched
    • Enterprise Protectionunmatched
    • Establish Prioritiesunmatched
    • Federal Governmentunmatched
    • Firewallsunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GNU C Compilerunmatched
    • Government Contractsunmatched
    • HTTP (HyperText Transport Protocol)unmatched
    • Identify Issuesunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Legalunmatched
    • Maintain Complianceunmatched
    • Malwareunmatched
    • Metricsunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Officeunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows NT Group Policyunmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Architecture/Engineeringunmatched
    • Operations Managementunmatched
    • Performance Metricsunmatched
    • Phishingunmatched
    • Public Healthunmatched
    • Python Programming/Scripting Languageunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Root Cause Analysisunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
    • Technical Supportunmatched
    • Technical Writingunmatched
    • Telemetryunmatched
    • Trend Analysisunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Citizenunmatched
    • VPN (Virtual Private Network)unmatched
    • Vulnerability Scannersunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder