IT & Cyber Security Consultant

ONTRAC, INC.
Washington, DC, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$156,000.0 - $234,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Bash Shell Cloud Computing Security Cyber Security Python (Programming Language) Network Security Windows PowerShell Zero Trust Network Access Security Information and Event Management Systems Integration Information Technology 3-tier Architectures

Job description

Location: Remote - This position may be performed remotely in states where the company is authorized to employ individuals. Washington D.C., Maryland, Virginia (Preferably) Compensation: The expected starting base pay range for this position is $156,000. - $195,000. with full potential base salary range over a successful candidate’s tenure in the position of $156,000. - $234,000. Actual compensation will be determined based on experience, skills, internal equity, and other job-related factors.

Shift: Monday - Friday, 8:00am - 5:00pm (Hours subject to change based on the needs of the business)

Employment Logistics: The IT & Cyber Security Consultant is responsible for designing, building, and maintaining robust security architectures across hybrid environments (on prem + cloud). You will enable the SOC by improving detection and orchestration capabilities and enable GRC by translating regulatory requirements into technical controls and automated evidence collection. This is a ā€œhands-on-keyboardā€ role that requires the ability to pivot between deep technical engineering and assisting in strategic support, A summary of key responsibilities for the role is outlined below. Additional duties may be assigned as needed to support business objectives.

  • SOC + GRC enablement: Design and implement technical solutions that assist the SOC in alert orchestration (SOAR) and provide the GRC team with automated risk monitoring and evidence collection capabilities.
  • Security integration: Lead the integration of security tools (EDR, SIEM, Cloud Security) to ensure a unified and visible security posture.
  • Risk management support: Assist in technical risk assessments by identifying vulnerabilities and recommending/implementing remediation engineering.
  • Architecture & engineering: Develop and maintain security infrastructure across hybrid environments (on prem/cloud), applying security by design to new deployments.
  • Incident response escalation: Serve as a Tier 3 escalation point for complex incidents requiring deep forensic and/or architectural expertise.
  • Mentorship: Guide junior engineers and analysts, fostering technical excellence and proactive security practices.

Paving your way to your success:

  • You bring the ā€œgeneralistā€ mindset, with proficiency across network security (firewalls, Zero Trust), endpoint protection, and cloud security (AWS/GCP).
  • You communicate exceptionally, explaining deep technical vulnerabilities to non-technical risk stakeholders and translating risk/context back into technical action.
  • You analyze complex issues with multiple variables and apply sound judgment in high-impact situations.
  • You define methods and procedures for new assignments, selecting and adapting advanced techniques to achieve results
  • You deliver innovative and effective solutions to challenging issues.

Requirements

Do you have experience in Tooling?, Do you have a Bachelor’s degree?, Are you eager to join a dynamic and expanding company where you can both learn and make a meaningful impact? If you possess a strong sense of empathy, enjoy assisting others, thrive in a fast-paced environment, and excel at problem-solving, we encourage you to apply today to connect with a recruiter!, * Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience)

  • 10+ years of progressive experience in IT and Security
  • At least 3 years in a senior or lead engineering capacity
  • Strong ability to code/script in Python, PowerShell, or Bash to automate repetitive security tasks and integrations
  • Deep understanding of SIEM logic, YARA rules, and EDR configuration to improve detection efficacy
  • Ability to interpret NIST CSF, ISO 27001, or SOC2 and implement the technical controls required to meet them
  • Preferred CISSP, CISM, or hands-on technical certifications like GIAC (GCIA, GCDA) or Offensive Security (OSCP)

Benefits & conditions

2.82.8 out of 5 stars Washington, DC Remote $156,000 - $234,000 a year, Pulled from the full job description

  • Paid parental leave
  • Parental leave
  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance
  • Paid sick time, Employees are eligible for a comprehensive benefits package which may include:

  • Medical, dental, and vision insurance
  • Life and short- and long-term disability coverage
  • 401(k) retirement savings plan with company match
  • Flex vacation in states other than CA, CO, IL, MA, MT, and NE, with accruals up to 96 hours for first year of employment with tenure-based increases up to 160 hours
  • Two (2) floating holidays per year
  • Paid sick leave*
  • Six (6) paid company holidays
  • Two (2) weeks paid pregnancy disability leave, four (4) weeks paid parental bonding leave
  • Additional wellness and employee assistance programs

Benefits eligibility and offerings are subject to the terms and conditions of the applicable plans and company policies., Compensation decisions are made based on the specific circumstances of each hire to ensure fair and competitive pay.

About the company

Founded in 1986, OnTrac has evolved into the leading provider of same-day and next-day delivery services in the U.S. for premier e-commerce and product-supply businesses, including five of the largest retailers in the U.S., Lasership, Inc. dba OnTrac Final Mile with its affiliates, including OnTrac Logistics, Inc. (collectively, ā€œOnTracā€ or the ā€œCompanyā€) is an equal opportunity employer. We value diversity and welcome applications from individuals of all backgrounds, abilities, and experiences. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or age. Join us in our commitment to creating a diverse and inclusive workplace. If you are excited to be part of our team and contribute to our talent acquisition efforts, we invite you to apply.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker Ā· WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· WWC 2022

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter Ā· WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler Ā· LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Ā· LIVE

Videos

See all

Related articles

See all