About this role
- Researches, organizes, writes, edits, trains, and produces technical data, guidelines, templates, and policy to support Security Engineering.
- Perform information security risk assessments across a variety of platforms and applications submitted through the Change Management process.
- Guide users in determining and integrating baseline security requirements, advise on viability of alternative approaches and conduct and evaluate feasibility studies.
- Propose remediation/mitigating controls and recommendations to stakeholders and management to minimize risk.
- Address security concerns or issues with proposed software and hardware projects to ensure “baked-in” security considerations in project proposals.
- Lead security team engagements to build and mature processes to produce written Standard Operating Procedures with a focus on improvement to Information Assurance processes, methodologies, and communication methods.
- Support iterative review of security assessment results and work with stakeholders across organizations to provide structure around risk management and internal controls.
- Experience with CIS Benchmarks and DISA STIGs to provide system hardening guidance.
- Maintain a Master Library of Security Benchmarks for relevant systems as a reference for essential baseline security requirements, compliance and continuous monitoring capabilities.
- Provide status updates and follow-up on active open Security Engineering tickets.
- Align with and support the execution of the Cybersecurity Information Assurance organization vision and strategy.
- Development of security guidance, policies, and procedures.
- Bachelor’s degree or equivalent work experience in related field and 3-5 years of relevant work experience with network engineering and/or system administration background (Unix/Linux/Windows)
- Previous experience with cloud providers like Azure and using Agile tools for day-to-day tasking preferably Azure Dev Ops.
- Experience with leading daily scrums, sprint planning and facilitating the scrum process (Scrum Certification preferred)
- Sound cyber security knowledge foundation, to include understanding of Computer and network technology fundamentals.
- Strong familiarity with NIST Security Controls (NIST 800-53) and ITIL Certification
- Experience with ServiceNow
- Experience with security tools in an enterprise environment to include installation, configuration, usage, and troubleshooting.
- Demonstrate security expertise with multiple Windows, and Unix-based operating systems.
- Excellent verbal and written communication skills and ability to build strong relationships with stakeholders at all levels.
- Strong problem-solving capabilities and the ability to effectively communicate solutions.
- Strong analytical capabilities.
- Strong understanding of how computer systems and networks are secured and in compliance with government and industry regulations.
- Ability to independently collect, review, and evaluate IT product data to identify and characterize security threat sources of concern and provide recommendations to Government leadership.
- Ability to articulate ideas to both technical and non-technical audiences through excellent written and oral communication skills.
- The ability to establish effective relationships with internal partners and teams.
- Must possess a valid baseline security certification (e.g., CompTIA Security+, CISSP, CEH, or DoD equivalent)
- Ability to obtain Public Trust Clearance
Tech stack
Azure