Senior IT Security Engineer-NIGC

CTI, Inc.
Falls Church, VA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Systems Engineering Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Systems Local Area Networks Network Security Security Information and Event Management Syslog EndPointSecurity Computer Network Technologies
+3 more
Firewalls (Computer Science) Information Technology Security Orchestration, Automation & Response

Job description

  • Apply knowledge and skills of information systems security principles, NIST guidelines, FISMA, CISA, and federal directives, to conduct ongoing security assessments of installed systems and networks with a view to recommend corrective actions.
  • Perform systems engineering and maintenance activities according to established standards.
  • Apply knowledge of Networking Technologies including LAN, MS Azure, and Wireless management in security solutions implementation and troubleshooting. d. Develop agency’s security operations capabilities by evaluating current strategies and pursuing alignment with best practices.
  • Ensure the effective configuration and daily operations of tools that support the agency’s cybersecurity strategy. Such tools include SEIM integration, Syslog, Network Detection and Response (NDR), Endpoint Detection and Response (EDR), Firewalls, M365 Cloud security, Defender for Cloud, and Continuous Diagnostics & Mitigation (CDM) capabilities.
  • In collaboration with CISO and Privacy Officer develop plans, techniques, and measurable objectives to improve the development of cybersecurity and privacy measures that meet agency’s goals for protecting sensitive information.
  • Collaborate with other teams on the integration of agency Applications and IT services to consider security implications and ensure that AGENCY security requirements are met.
  • Maintain threat awareness and monitor agency information systems for exploits and any suspicious activities. Analyze aggregated logs from security tools and perform regular threat hunting activities.
  • Develop Security Orchestration and Automation capabilities.
  • Adhere to Continuous Monitoring practices to evaluate the effectiveness of implemented security controls and execute proactive threat hunting activities to ensure confidentiality, integrity, and availability of agency information systems.
  • Develop detection and response configuration policies to increase automation. l. Execute Incident Response activities to include all associated actions according to the agency incident response plan.
  • Develop Incident handling procedures.
  • Validate that sufficient and relevant information is captured and retained from security tools to support actionable security awareness and incident investigations.
  • Collect security operations performance and agency security posture management metrics and prepare agency threat reports to inform risk management decisions.
  • Develop and maintain accurate security operations documentation including the preparation of standard operating procedures for recurring tasks.

Requirements

  • SIEM Tool : 5 years (Required)
  • Syslog and Log Collection tools: 5 years (Required)
  • Network Detection & Response (NDR) tools: 5 years (Required)
  • Endpoint Detection & Response (EDR) tools: 5 years (Required)
  • Firewalls / Network Security Gateways tools: 5 years (Required)
  • M365 Cloud Security tools: 3 years (Required)
  • Continuous Diagnostics & Mitigation (CDM): 5 years (Required)
  • IT Security: 9 years (Required)

License/Certification:

  • CISSP (Required)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all