Cyber Security Engineer
Job Description
Lawrence Livermore National Laboratory is hiring a Cyber Security Engineer to support the Cyber Security Operations Center (CSOC) Incident Response team. This hybrid role in Livermore, CA plays a direct part in protecting enterprise systems and information through incident response, threat hunting, security monitoring, and technical assessments. The position also includes flexible schedules (depending on project needs) and may involve intermittent on-call and off-hours work.
The role offers a flexible benefits package along with a comprehensive support system for long-term planning and growth, including 401(k), relocation assistance, and an education reimbursement program. Salary range is USD 146,340 - 222,564 per year, with level-based ranges provided below.
Responsibilities
- Respond promptly to security threats and incidents to help protect enterprise systems and information, working independently and as part of a team.
- Conduct proactive threat hunting and execute identification, containment, eradication, and support for recovery efforts.
- Analyze LLNL intrusion detection systems.
- Provide security monitoring and incident response support, including troubleshooting and resolution of issues.
- Create and manage processes, systems, and tools with a high degree of responsibility.
- Serve as an incident response technical point of contact and interact with internal and external personnel.
- Perform technical assessments, document actions and findings, and provide remediation recommendations.
- Support plans that promote diversity, equity, and inclusion within the program.
- Manage multiple complex parallel tasks and priorities while meeting deadlines and leveraging team skills.
- Develop advanced methods, tools, and procedures to improve incident response capabilities and automate complex tasks.
- Mentor and provide technical guidance to team members on incident response best practices and procedures.
- Perform other duties as assigned.
Requirements
- Ability to obtain and maintain a US DOE Q-level security clearance, which requires U.S. Citizenship.
- Bachelor’s degree in Computer Science, Computer Engineering, or a related field (or an equivalent combination of education and related experience).
- Broad experience with SIEM, log aggregation, packet analysis, or other cybersecurity tools.
- Experience conducting host forensics, network forensics, log analysis, or malware analysis supporting incident response investigations.
- Proficient written and verbal communication and strong interpersonal skills to collaborate in a multi-disciplinary environment.
- Ability to manage concurrent technical tasks with conflicting priorities, approach difficult problems with creativity, and adjust focus as needed, including independent work experience.
- Ability to work off-hours and on-call to respond to incidents (intermittently, as-needed or as part of a rotation).
- Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management.
- Significant experience with log analysis, event correlation, or incident management procedures.
- Advanced ability to provide innovative approaches and apply new technologies to tasks and projects that may not be well defined.
Technologies
- SIEM, log aggregation, packet analysis
- Host forensics, network forensics, log analysis, malware analysis
- AWS, Azure
- C, C#, Python, Java, PowerShell, PHP
- CISSP, CISM, GIAC
Benefits
- Flexible benefits package
- 401(k)
- Relocation Assistance
- Education Reimbursement Program
- Flexible schedules (depending on project needs)
Additional Qualifications (SES.3 level)
- Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management.
- Significant experience with log analysis, event correlation, or incident management procedures.
- Advanced ability to provide innovative approaches and apply new technologies to tasks and projects that may not be well defined.
Qualifications We Desire
- Master’s degree in Computer Science, Computer Engineering, or related field (or equivalent level of knowledge).
- Significant incident response experience, including experience with cloud services such as AWS/Azure, and experience leading teams.
- Experience with programming or scripting languages including C, C#, Python, Java, PowerShell, and PHP.
- Current industry specific certifications, including but not limited to CISSP, CISM, or GIAC.
Pay Range
- $146,340 - $222,564 Annually
- $146,340 - $185,544 at the SES.2 level
- $175,530 - $222,564 at the SES.3 level
An employee’s position within the salary range will be based on several factors including specific competencies, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs.
Position Details
- Flexible Term appointment for a definite period not to exceed six years.
- If the final candidate is a Career Indefinite employee, Career Indefinite status may be maintained (should funding allow).
- #LI-Hybrid
Security Clearance and Testing
- This position requires a Department of Energy (DOE) Q-level clearance.
- If selected, a Federal background investigation will be initiated to determine eligibility for access to classified information or matter.
- All L or Q cleared employees are subject to random drug testing.
- External applicants selected must pass a post-offer, pre-employment drug test, including testing for marijuana as Federal law applies to Federal Contractors.
Wireless and Medical Devices
Depending on job duties, you may be required to work in a Limited Area where personal and/or laboratory mobile devices are not permitted (examples include cell phones, tablets, fitness devices, wireless headphones, and other Bluetooth or wireless enabled devices). Sensitive Compartmented Information Facilities require separate approval. Hearing aids without wireless capabilities or wireless that has been disabled are allowed in Limited Areas, Secure Space, and Transit/Buffer Space within buildings.