ECS logo
ECS
Posted 61 days agoVerified live 5d ago

IT SOC Engineer I

Brief overview

Remote
$100k–$120k/yrStated range
CybersecurityCompTIA Security+ CENIST SP 800-53Cybersecurity Risk Management FrameworkSTIGSecurity control vulnerability mitigationSystem security measures implementationIncident assessment and responseForensic analysisPenetration testingVulnerability assessmentSOC software tools and technologiesSecurity architectureRisk managementThreat intelligence

Job description

Summary

Everforth ECS is seeking an IT SOC Engineer I to work remotely. This position will provide governance, risk management, compliance support, security architecture, and cybersecurity monitoring in support of the US International Development Finance Corporation's Chief Information Security Officer.

Responsibilities

  • Responsible for performance of forensic analysis on various digital media devices and mediums to identify, reverse engineer, and obfuscate content related to an incident, such as malicious content
  • Consult with security operations regarding cybersecurity communications and deliver or request assistance or assist with investigations
  • Provide technical expertise in cyber adversary capabilities and an assessment of the intentions of these groups to conduct Computer Network Exploitation (CNE) and Computer Network Attack (CNA) against U.S. private sector and Government networks and information systems
  • Consult and provide onsite and remote vulnerability assessment capabilities as a sustained, full-time program independent of incident detection, recovery, or reporting activities
  • Consult both internal and external penetration and security testing which mimics real-world attacks to identify methods for circumventing the security features of an application, system, and network
  • Consult with teams to detect, prevent, and respond to threats posed by malicious, negligent, or compromised insiders by maintaining in-depth visibility into the DFC Enterprise and having a means of filtering and prioritizing threat data into concise, actionable intelligence
  • Provide expert security engineering and subject matter expertise to conduct market research, product evaluation, testing, configuration, deployment, operations, and maintenance support for various SOC software tools and technologies
  • Advise and assist with SOC architecture activities for all DFC SOC information systems initiatives supporting all SOC tools and capabilities
  • Create procedures and documentation for maintaining SOC hardware and software
  • Determine and document the security impact of proposed or actual changes to the information systems and their environment of operation
  • Assess the technical, management, and operational security controls employed within and inherited by the information systems in accordance with the organization defined monitoring strategy
  • Facilitate and perform remediation actions based on the results of ongoing monitoring activities and the outstanding items in the POA&M
  • Update the System Security Plan, SAR, and POA&Ms. Key Deliverables: updated Residual Risk Statement and Risk Acceptance Recommendation Report
  • Report the security status of information systems to appropriate organizational officials on an ongoing basis
  • Review the reported security status of information systems ongoing Risk Determination and Acceptance
  • Incident Assessment and Response Support; work with the DFC CIRT or any other pertinent parties (including external vendors) at any DFC location to recover from any incident

Skills

  • Cybersecurity professional experience
  • Experience with governance, risk management, compliance support, security architecture, standards and design
  • Knowledge of cybersecurity monitoring (Detection, Response, and Prevention)
  • Familiarity with threat intelligence
  • Experience with NIST RMF and NIST Cybersecurity Framework (CSF)
  • Forensic analysis skills on various digital media devices
  • Consultation experience with security operations regarding cybersecurity communications
  • Technical expertise in cyber adversary capabilities
  • Experience in conducting Computer Network Exploitation (CNE) and Computer Network Attack (CNA) assessments
  • Vulnerability assessment capabilities
  • Experience with penetration and security testing
  • Ability to detect, prevent, and respond to threats posed by insiders
  • Expert security engineering and subject matter expertise
  • Market research and product evaluation skills
  • Experience with SOC software tools and technologies
  • SOC architecture activities experience
  • Ability to create procedures and documentation for SOC hardware and software
  • Experience in determining and documenting security impacts of changes to information systems
  • Assessment of technical, management, and operational security controls
  • Facilitation of remediation actions based on monitoring activities
  • Updating System Security Plan, SAR, and POA&Ms
  • Reporting security status of information systems
  • Incident Assessment and Response Support experience

Qualifications

Must Haves

  • Cybersecurity professional experience
  • Experience with governance, risk management, compliance support, security architecture, standards and design
  • Knowledge of cybersecurity monitoring (Detection, Response, and Prevention)
  • Familiarity with threat intelligence
  • Experience with NIST RMF and NIST Cybersecurity Framework (CSF)
  • Forensic analysis skills on various digital media devices
  • Consultation experience with security operations regarding cybersecurity communications
  • Technical expertise in cyber adversary capabilities
  • Experience in conducting Computer Network Exploitation (CNE) and Computer Network Attack (CNA) assessments
  • Vulnerability assessment capabilities
  • Experience with penetration and security testing
  • Ability to detect, prevent, and respond to threats posed by insiders
  • Expert security engineering and subject matter expertise
  • Market research and product evaluation skills
  • Experience with SOC software tools and technologies
  • SOC architecture activities experience
  • Ability to create procedures and documentation for SOC hardware and software
  • Experience in determining and documenting security impacts of changes to information systems
  • Assessment of technical, management, and operational security controls
  • Facilitation of remediation actions based on monitoring activities
  • Updating System Security Plan, SAR, and POA&Ms
  • Reporting security status of information systems
  • Incident Assessment and Response Support experience

More jobs like this