IT Security Engineer
Job Description
Senior IT Security Engineer accountable for directing security operations, threat monitoring, and incident response to safeguard agency information systems.
Responsibilities
- Leverage information security principles, NIST guidelines, FISMA, CISA, and federal directives to continually assess installed systems and networks, and propose corrective actions.
- Perform systems engineering and maintenance work in line with established standards.
- Apply networking expertise, including LAN, MS Azure, and wireless management, to deploy and troubleshoot security solutions.
- Enhance the agency's security operations by evaluating current strategies and aligning with industry best practices.
- Configure and operate tools that support the cybersecurity strategy, including SEIM integration, Syslog, Network Detection and Response (NDR), Endpoint Detection and Response (EDR), firewalls, M365 Cloud security, Defender for Cloud, and CDM capabilities.
- Collaborate with the CISO and Privacy Officer to develop plans, techniques, and measurable objectives that advance cybersecurity and privacy measures aligned with protecting sensitive information.
- Partner with other teams to integrate applications and IT services with security requirements in mind, ensuring agency security standards are met.
- Maintain threat awareness, monitor systems for exploits and suspicious activity, analyze aggregated security logs, and conduct regular threat hunting.
- Develop Security Orchestration and Automation capabilities.
- Adhere to Continuous Monitoring practices to evaluate control effectiveness and proactively hunt threats to safeguard confidentiality, integrity, and availability.
- Develop detection and response configuration policies to increase automation.
- Lead incident response activities in accordance with the agency incident response plan.
- Develop incident handling procedures.
- Validate that security tools capture and retain relevant information to support actionable security awareness and investigations.
- Collect security operations performance metrics and posture data, and prepare threat reports to inform risk management decisions.
- Develop and maintain accurate security operations documentation, including standard operating procedures for recurring tasks.
Requirements
- CISSP certification required.
- SIEM Tool: 5 years required.
- Syslog and Log Collection tools: 5 years required.
- Network Detection & Response (NDR) tools: 5 years required.
- Endpoint Detection and Response (EDR) tools: 5 years required.
- Firewalls / Network Security Gateways tools: 5 years required.
- M365 Cloud Security tools: 3 years required.
- Continuous Diagnostics & Mitigation (CDM): 5 years required.
- IT Security: 9 years required.
- SIEM Tools: 5 years required.
- Log Collection Tools: 5 years required.
- M365 Cloud Security tools: 5 years required.
- IT Security: 10 years required.
Technologies
- SEIM integration
- Syslog
- Network Detection and Response (NDR)
- Endpoint Detection and Response (EDR)
- Firewalls / Network Security Gateways
- M365 Cloud security
- Defender for Cloud
- Continuous Diagnostics & Mitigation (CDM)
- MS Azure
- LAN
- Wireless management
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Professional development assistance
- Tuition reimbursement
- Vision insurance
Work Location
- Washington, DC (onsite)
- In person
Salary
- Salary: USD 109,376 - 160,000 per year