Mid Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+19 more
Job description
- Design hardware, operating systems, and software applications to adequately address cybersecurity requirements.
- Design and develop cybersecurity or cybersecurity-enabled products.
-
Develop and direct system testing and validation procedures and documentation.
-
Develop dashboarding capabilities, utilizing the enterprise SIEM and Enterprise Governance Risk and Compliance ( eGRC ) solution, for the ISSO’s to perform real time monitoring of Agency information systems
-
Develop detailed security design documentation for component and interface specifications to support system design and development.
-
Implement security designs for new or existing system(s) .
-
Incorporate cybersecurity vulnerability solutions into system designs (e.g., Cybersecurity Vulnerability Alerts).
-
Create and track metrics using the dashboard in the SIEM/ eGRC solution
-
Design, implement, test, and evaluate secure interfaces between information systems, physical systems, and/or embedded technologies.
-
Design, develop, integrate, and update system security measures that provide confidentiality, integrity, availability, authentication, and non-repudiation.
- Perform security reviews and identify security gaps in architecture.
Requirements
- Strong written and verbal communication skills.
- Knowledge of secure configuration management techniques. (e.g., Security Technical Implementation Guides (STIGs), cybersecurity best practices on cisecurity.org).
- Knowledge of CRIBL.
- Knowledge of software development models (e.g., Waterfall Model, Spiral Model).
- Knowledge of software engineering.
- Knowledge of structured analysis principles and methods.
- Experience designing architectures and frameworks.
- Knowledge of system design tools, methods, and techniques, including automated systems analysis and design tools.
- Knowledge of the systems engineering process.
- Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161)
- Knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations.
- Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Knowledge of network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools.
- Experience with Windows, Linux, UNIX, any other major operating systems
- Experience with programming in Python, C, Java, Perl, Shell and/or bash shell scripting.
- Familiarity with REST API best practices and usage
- Familiarity with security technologies (firewalls, IDS/IPS, AV, etc.) and other SIEM products
Certifications/Licenses:
-
Bachelor’s degree or higher
-
5+ years’ experience security engineering experience and SIEM (security incident and event monitoring) administration, deployment, and/or architectural design
-
Certifications addressing security and risk management, asset security, security engineering, communications and network security, identity and access management, security assessment and testing, security operations, software development security, system security, network infrastructure
-
Active Public Trust clearance or eligible to obtain a Public Trust clearance
Desired Skills
-
In-depth knowledge of Information Theory (e.g., source coding, channel coding, algorithm complexity theory, and data compression).
-
Ability to apply system design tools, methods, and techniques, including automated systems analysis and design tools.
- SIEM deployment, administration, and architecture design
- SOAR experience in deployment and architecture design preferred
-
Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
-
Ability to apply network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
-
Experience designing the integration of hardware and software solutions.
-
Skill in discerning the protection needs (i.e., security controls) of information systems and networks.
- Skill in evaluating the adequacy of security designs and conducting reviews of technical systems.
EverforthECS1 (if funded or Indirect)
About the company
ECS Federal is a leading information security and information technology company in Washington DC. We are looking to hire a Mid Security Engineer to support a full range of cyber security services on a long-term contract. The position is full-time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background clearance., Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities