Cybersecurity Engineer

Lumbee Tribe Holdings, Inc.
Camp Pendleton North, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Junior
Compensation
$ 120K

Job location

Camp Pendleton North, United States of America

Tech stack

JavaScript
Microsoft Windows
C++
Cloud Computing
Static Program Analysis
Code Review
Computer Security
Computer Networks
Computer Literacy
Linux
Information Security Management
Python
Network Configuration and Change Management
Powershell
Ruby
Wireshark
Software Vulnerability Management
Forensic Toolkit
Data Logging
Software Security
Information Technology
Nessus

Job description

The Cybersecurity Engineer delivers software assurance testing expertise and cybersecurity engineering support across both offensive assessment findings and independent engineering analysis. This position directly supports static and dynamic code analysis, Code Review Reporting, Security Posture Assessments, vulnerability mitigation engineering, system hardening guidance, DCO detectability engineering, and DCO integration support.

The incumbent serves as the team's primary link between offensive findings and the implementable engineering changes that make Marine Corps systems more survivable and more defensible for DCO operators.

Essential Position Functions

  • Develop detailed, technically grounded mitigation recommendations for vulnerabilities identified during Cyber Assessment events, software assurance reviews, and vulnerability scans; tailor recommendations to the operational and programmatic constraints of each program of record.
  • Provide system and network configuration hardening guidance based on assessment findings, applicable STIGs, and industry best practices, including specific implementation steps for program engineers and administrators.
  • Analyze assessed systems and provide engineering recommendations for system or network changes that improve the ability of DCO Marines to monitor, detect, and respond to adversarial activity, including sensor placement, logging configuration, alerting thresholds, and data logging standards.
  • Assist in integrating program systems with the tools, processes, and personnel of designated DCO providers; produce DCO System Playbooks outlining incident response procedures tailored to each assessed system.
  • Implement STIG checklists across a wide range of technologies; review Windows, Linux, Cloud, network/application STIGs, DoD Security Requirement Guides (SRGs), and vendor hardening guides.
  • Conduct administration, configuration, and support of IT infrastructure including operating systems, network components, and application security.
  • Run ACAS vulnerability scans; generate reports and propose remediations for open findings.
  • Continuously monitor, report, and respond to changes in application security posture; create and track audit reports and metrics; report issues to the Information System Security Manager (ISSM).
  • Support investigation of cyber breaches; conduct analysis of multiple data sources to identify indicators of compromise.
  • Draft client reports explaining findings, recommendations, and engineering rationale for non-technical Program Office stakeholders.
  • Utilize PowerShell, JavaScript, or Python to automate repetitive cybersecurity engineering and reporting tasks.
  • Collaborate with other cybersecurity engineers and penetration testers to review security tool issues, develop integrated solutions, and ensure recommendations are implementable within each program's operational constraints.
  • Perform additional duties as assigned by the Program Manager.

Requirements

Five (5) or more years of demonstrated experience in cybersecurity.

Two (2) or more years of demonstrated experience with tools such as FTK, Wireshark, Autopsy, or similar technologies.

One (1) or more years of demonstrated experience with development of code in languages such as Python, C/C++, Ruby, or similar.

Desired: Information Assurance Technical (IAT) Level I or Level II certification.

Desired: Bachelor's Degree in Cybersecurity, Computer Science, or equivalent.

Desired: Certified Secure Software Lifecycle Professional (CSSLP), Offensive Security Exploit Developer (OSED), or equivalent software assurance certification.

Desired: experience with DoD and Marine Corps Risk Management Framework (RMF), STIG implementation, and ACAS/Nessus vulnerability management.

Physical Requirements for the role

This position is primarily sedentary and performed in an office setting, requiring extended periods of computer use and close visual attention to technical detail. Occasional lifting of IT equipment up to 25 lbs. may be required.

Benefits & conditions

Commensurate with experience and qualifications.

Apply for this position