Cyber Security Engineer II
cFocus Software Incorporated
United States
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Amazon Web Services
Application Firewall
User Authentication
Microsoft Azure
Cloud Computing
Cloud Computing Security
CompTIA Security+
Cyber Security
Information Systems
Databases
Linux
+18 more
Identity and Access Management
Networking Hardware
Intrusion Detection Systems
Network Security
Network Segmentation
Systems Development Life Cycle
Cloud Services
Zero Trust Network Access
Software Vulnerability Management
SSL Certificate Management
Cloud Platform System
Firewalls (Computer Science)
Information Technology
Malware Detection
CIS Benchmarks
ArcSight Event Correlation
Cyber Warfare
Vulnerability Analysis
Job description
cFocus Software seeks a Cyber Security Engineer II to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Engineer, deploy, configure, and maintain enterprise cybersecurity technologies supporting NIH information systems.
- Support security monitoring and operational cyber defense activities across on-premises, hybrid, and cloud environments.
- Administer endpoint security, endpoint detection and response (EDR), anti-malware, and host-based security solutions.
- Implement secure configurations and system hardening in accordance with NIST, HHS, and NIH security standards.
- Configure and maintain enterprise identity and access management (IAM) security technologies.
- Support implementation and enforcement of Zero Trust Architecture (ZTA) principles.
- Assist with enterprise log management, security monitoring, and event correlation capabilities.
- Perform technical security assessments of servers, workstations, cloud resources, databases, and applications.
- Coordinate with system administrators and application owners to implement security controls and corrective actions.
- Support enterprise cybersecurity modernization initiatives.
- Perform enterprise vulnerability assessments using approved vulnerability scanning platforms.
- Analyze vulnerability scan results and prioritize remediation activities based on risk.
- Coordinate vulnerability remediation with system administrators, application teams, and infrastructure personnel.
- Verify remediation activities through follow-up validation testing.
- Perform security configuration reviews against DISA STIGs, CIS Benchmarks, and NIH security baselines.
- Monitor compliance with organizational vulnerability remediation timelines.
- Develop remediation recommendations for operating systems, applications, databases, network devices, and cloud services.
- Support development of Plans of Action & Milestones (POA&Ms) related to identified vulnerabilities.
- Conduct risk analysis associated with newly discovered vulnerabilities and emerging threats.
- Develop vulnerability metrics and executive reporting supporting enterprise cybersecurity risk management.
- Design, engineer, implement, and maintain enterprise security architectures supporting NIH mission systems.
- Engineer secure cloud environments within Microsoft Azure, Microsoft 365, AWS, and hybrid infrastructures.
- Support implementation of network security technologies including firewalls, IDS/IPS, web application firewalls, secure gateways, and network segmentation.
- Implement secure authentication, encryption, privileged access management, and certificate management solutions.
- Engineer secure infrastructure supporting NIST Risk Management Framework (RMF) security controls.
- Evaluate emerging cybersecurity technologies and recommend improvements to enterprise security architecture.
- Support secure system lifecycle engineering activities throughout system development and modernization efforts.
- Participate in technical architecture reviews and security design assessments.
- Develop engineering documentation, implementation guides, standard operating procedures, and technical diagrams.
- Support implementation of Cybersecurity Supply Chain Risk Management (C-SCRM) controls where applicable.
Requirements
- Public Trust Clearance
- B.S. Computer Science, Information Technology, or a related field
- 3+ years of experience implementing enterprise cybersecurity technologies.
- Experience supporting Federal cybersecurity programs.
- Experience engineering enterprise security solutions across Windows, Linux, cloud, and hybrid environments.
- Experience implementing NIST cybersecurity controls and Federal security requirements.
- Active CISSP, CCSP, Security+, CEH, GSEC, GCIH, or AWS Certified Security - Specialty
Benefits & conditions
Invitation for Job Applicants to Self-Identify as a U.S. Veteran
- A ādisabled veteranā is one of the following:
- a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
- a person who was discharged or released from active duty because of a service-connected disability.
- A ārecently separated veteranā means any veteran during the three-year period beginning on the date of such veteranās discharge or release from active duty in the U.S. military, ground, naval, or air service.
- An āactive duty wartime or campaign badge veteranā means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
- An āArmed forces service medal veteranā means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on cfocussoftware.applytojob.comGood distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago