Security Office L3&L4
Role details
Job location
Tech stack
Job description
We are seeking a highly motivated and detail-oriented Security Officer with a strong background in information security, network security, and cybersecurity frameworks. In this role, you will be responsible for implementing, monitoring, and maintaining security measures across our IT infrastructure to safeguard sensitive data and ensure compliance with industry standards. Your expertise will help us uphold the integrity of our systems, protect against cyber threats, and support the organization's security policies. This paid position offers an exciting opportunity to contribute to a dynamic team dedicated to maintaining robust security operations in a fast-paced environment., * Develop, review, and update system security plans aligned with NIST standards and ISO 27000 series frameworks to establish comprehensive security policies.
- Manage and configure network security devices such as Cisco ASA firewalls, Cisco ISE for identity management, and IDS/IPS systems for threat detection and prevention.
- Conduct vulnerability assessments and risk analysis using SIEM tools like Splunk or SolarWinds to identify potential security gaps.
- Implement and oversee identity and access management (IAM) solutions, including LDAP, RBAC, SSO, and PKI to control user permissions securely.
- Perform incident response activities by investigating security breaches, conducting threat detection & response procedures, and supporting incident recovery efforts.
- Ensure compliance with regulatory frameworks such as FISMA, FedRAMP, HIPAA (if applicable), and government information & network security standards through continuous monitoring and audits.
- Lead security risk assessments investigations using RMF (Risk Management Framework) methodologies to evaluate vulnerabilities within cloud infrastructure (AWS, Azure) and on-premises systems.
Requirements
- Extensive knowledge of system security plans, NIST cybersecurity framework (SP 800-53), ISO 27002/27000 standards, and cybersecurity best practices.
- Proficiency in configuring and managing network protocols including TCP/IP, IPsec VPNs, BGP, OSPF routing protocols, Ethernet switching, LAN/WAN architecture.
- Hands-on experience with firewall management (Cisco ASA), intrusion detection systems (IDS), threat intelligence tools like Splunk or New Relic, and network monitoring software such as SolarWinds or PRTG.
- Strong understanding of computer networking concepts including load balancing, high availability architectures, disaster recovery planning, and system hardening techniques.
- Familiarity with cloud computing platforms (AWS, Google Cloud Platform), virtualization technologies (VMware vSphere), DevOps practices (CI/CD), and infrastructure as code tools like Terraform or Ansible.
- Ability to perform vulnerability assessments using vulnerability research tools; conduct system security audits; implement encryption solutions; manage IT risk management programs; and ensure information security compliance across diverse environments.
- Excellent team leadership skills combined with a deep understanding of governance, risk & compliance (GRC) software; cybersecurity incident management; IT governance frameworks such as COBIT; and project management methodologies like Agile.