- Company Name
- DataStaff, Inc.
- Job Title
- Cybersecurity Engineer
- Job Description
-
Job title: Cybersecurity Engineer
Role Summary:
Design, implement, and maintain enterprise‑wide information security solutions. Lead risk identification, vulnerability assessment, and incident response activities in a federal or regulated environment, ensuring compliance with security policies and standards.
Expectations:
- Minimum 7 years of hands‑on experience in security operations.
- Proven track record in network, endpoint, and perimeter security technologies.
- Ability to manage and document security controls, policies, and audit findings.
- Strong communication for coordinating with IT, vendors, and governance teams.
Key Responsibilities
- Design, deploy, and support security infrastructure for the organization.
- Conduct network scans, penetration tests, and vulnerability assessments; analyze results and recommend remediation.
- Develop, document, and maintain security policies, procedures, and System Security Plans (SSP).
- Collaborate with the Office of Information Security (OIS), ISO teams, and auditors on audit findings and corrective actions.
- Manage security incidents, including detection, response, and resolution.
- Support Azure cloud security reviews and integration of cloud‑native controls.
- Ensure device configurations adhere to best practices and maintain up‑to‑date documentation.
Required Skills
- Expertise in firewalls, IDS/IPS, web security gateways, NAC, endpoint protection, and perimeter security.
- Proficiency with anti‑virus, anti‑malware, anti‑phishing, authentication, and web content filtering solutions.
- In‑depth knowledge of TCP/IP, OSI layers, and network/security protocols.
- Experience with log management, SIEM, and threat analytics.
- Skilled in vulnerability scanning, threat modeling, and risk assessment.
- Ability to remediate security incidents and perform incident response workflows.
- Strong documentation and communication skills for cross‑functional collaboration.
- Capable of creating and maintaining System Security Plans and Risk Assessments.
- Experience with penetration testing tools and web‑app security practices.
- Comfortable working with technical and non‑technical stakeholders.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Information Security, or related field.
- CISSP (Certified Information Systems Security Professional) preferred.
- Other relevant certifications (CISM, CEH, OSCP, CGEIT) considered a plus.