XLA is seeing a mid-level Cyber Security Engineer with a broad knowledge of the domain including network security, system security, vulnerability scanning, web-based application scanning, risk assessments, security engineering, etc. This position will be working at National Archives (NARA) in College Park, MD. Experience configuring, managing and running Security Operation Center (SOC) type tools (e.g., Tenable Continuous View, FireEye Threat Management System, Snort, etc.) SME will support a Federal Civilian Agency with vulnerability management and incident response work. The position involves working in a small focused team that follows the Federal Continuous Monitoring strategy for prioritization of resources and providing support that provides the greatest impact with limited resources. Team members have a large set of cross-functional abilities to support all aspects of Cyber Security.
Principle Duties and Responsibilities
- Conduct vulnerability scans and assessments against agency information systems, web applications and web services
- Conduct assigned activities within the security Incident response and handling lifecycle. These activities could include: detection, triage, analysis, containment, recovery and reporting.
- Coordinate response, triage and recovery activities for security events affecting the agency’s information assets
- Assist with expanding and maturing existing vulnerability management and incident response processes and activities.
- Coordinate with system owners and IT operations to remediate and resolve issues discovered during security scans, system assessments, system audits, and cyber security investigations.
- Conduct security assessments and testing for agency’s different cloud platform types (i.e., IaaS, SaaS, PaaS)
- Conduct on-demand scans, assessments, and audits to assess the cyber security posture of the various on-premises and cloud-based NARA information systems.
- Provide security engineering reviews and recommendations to agency System Owners and Information System Security Officers
- Develop and implement technical solutions to help mitigate security vulnerabilities
- Analyze network and host-based security logs to identify potential security threats
- Develop/review documentation for Security Operations procedures