Security Engineer

Zermount Inc.
Washington, DC, United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Active Directory Application Programming Interfaces (APIs) Agile Methodology Artificial Intelligence Amazon Web Services Amazon S3 Systems Engineering Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security
+36 more
Cloud Engineering Cyber Security Information Systems Computer Networks Databases Computer Engineering Continuous Integration Digital Assets Infrastructure as a Service (IaaS) Identity and Access Management Intrusion Detection Systems Information Systems Security Architecture Professional Network Security Log Analysis Platform as a Service (PAAS) Scrum Methodology Zero Trust Network Access Security Information and Event Management Software Engineering Virtualization Technology Wide Area Networks Google Cloud Okta Multi-Cloud HybridCloud Firewalls (Computer Science) Azure Security Center Information Technology Cloudwatch Amazon Simple Queue Service (SQS) Ddos Devsecops Serverless Computing Key Vault Vulnerability Analysis Microservices

Job description

We are looking for a highly talented, technical hands-on Senior Security Engineer to develop and implement strategies to protect computer systems, networks, and other digital assets from malicious attacks. To work with a team of IT professionals to design and implement new security measures or update existing ones. To leads the development of new security measures designed to patch holes and keep sensitive data safe., * Develop, and integrate with other Cybersecurity workflow to include: ATO Intake, assessment, and Vulnerability Scanning process.

  • Perform security reviews based on RMF controls compliance, clients, and security best practices.
  • Provide security input on Cloud Center of Excellence (CCOE) and Cloud Advisory Council (CAC) agenda items by participating in technical working groups, providing security analysis, and providing recommendations.
  • Performs architecture design reviews including configuration and log reviews, and perform network traffic analyses.
  • Produces a SAR Report to include HVA’s architecture strengths and findings.
  • Design and deploy native Cloud security services in AWS, Microsoft Azure, and Google Cloud.
  • Perform proof of value of Cloud-native, COTS, 3rd party, or opensource security capabilities by hands-on deploying and evaluating against security requirements.
  • Develop scripts or code to perform Cloud Security assessments through Cloud native API or SDK.
  • Develop enterprise cloud security blueprints to include security in Infrastructure as Code (IaC templates).
  • Analyzing the impact of emerging technologies on existing security systems and identifying potential risks
  • Research new and emerging security practices and capabilities such as AI/ML to address compliance and mitigate security risk.
  • Improve Cloud Security monitoring to include ingestion of logs such as: API, application/database, and flow logs into SIEM.
  • Increasing Cloud vulnerability coverage in the areas of Operating System (OS), application code, and Infrastructure level.
  • Develop architecture for integrating findings into a centralized dashboard that allows product owners direct access to team’s specific systems or cloud account findings.

Work with Cybersecurity Authorizations and Compliance Branch (CACB) to:

  • Conduct studies and analysis of proposed operations modifications.
  • Provide end-to-end architecture tradeoff assessments.
  • Develop strategic and tactical plans.
  • Conduct evaluation of new program requirements.
  • Investigate and develop new technologies for possible operations modifications.
  • Develop standards and solutions to meet the client’s requirements., Certified Information Systems Security Professional (CISSP) is required. Certifications to include one or more of the following: Certified Cloud Security Professional, AWS Certified Solutions Architect Associate, AWS Certified Security Specialist, Microsoft Azure Solutions Architect, Google Professional Cloud Architect.

Requirements

  • High level of attention to detail, needs minimal guidance, effective verbal, and written communications.
  • Equally adept at strategic planning and operational/technical level.
  • Able to adapt to new and changing requirements or priorities and manage work and resources accordingly.
  • At least 5 years (preferred 10 years) of network, systems, applications:
  • LAN/WAN, WAF/CDN/DDOS, Network Firewalls, IDS/IPS.
  • Virtualization, hypervisor security, container security.
  • Application development, serverless security, microservices, CICD.
  • At least 5 years of designing and/or implementing security in Cloud (AWS required, Azure or Google Cloud Platform optional):
  • Multi-Cloud, Hybrid Cloud, IaaS, PaaS, SaaS, shared responsibility model.
  • AWS IAM, KMS, S3, RDS, SNS/SQS, Organization, Guard Duty, Security Hub, Detective, Config, CloudTrail, CloudWatch, Lambda.
  • Azure E3/E5, Active Directory, Blob, Azure Security Center, Key Vault, SSE, Monitor, Log Analytics, Policy.
  • Experience with DevSecOps strategy and implementation and designing architecture in accordance to RMF, CSF, FISMA, and Fedramp.
  • Familiarity with: ZTNA and SASE Framework, ICAM (OKTA), CWPP, SOC Operations, Vulnerability Threat Management, and Compliance.
  • At least 2 years working in or managing Agile Devops, Scrum, Kanban.
  • Cloud architecture
  • Architecture experience
  • Networking experience
  • Network Security / Cyber Security experience, Candidate must have a Bachelor of Science (or higher) in one of the following: computer engineering, computer science, information technology, or cyber security. The resume may reference another major, so long as the resume is clear that the degree addressed at a minimum one of the following: cyber security engineering, systems administration, information systems security, software development security, systems engineering, information systems or information technology.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

Videos

See all

Related articles

See all