Your working location will be a hybrid of on-site/work from home, on-site location is Warminster, PA. Questions related to flexible work should be directed to the hiring manager during the interview process.
We are searching for a Cyber Security Engineer to join the Cybersecurity Division at the Applied Research Laboratory (ARL) at Penn State. Our mission is to support and secure the data and systems relevant to the challenging scientific, engineering, and technology problems conducted by our research teams in support of the Navy, the Department of Defense (DoD), and the Intel Community (IC). This role helps to protect ARL’s network and systems by providing proactive security measures, assessing and acting on risks, and ensuring compliance.
ARL is an authorized DoD SkillBridge partner and welcomes all transitioning military members to apply.
You will:
- Aid in the, development, validation, and submission of information system security plans, security test and evaluation plans, certification and accreditation or authorization packages, and plans of action and milestones in support of compliance requirements
- Take part in conducting, developing, planning, and coordinating risk assessments of information systems in development, test, production and research environments as required by established or newly determined compliance/audit requirements
- Complete technical requirements for networks and systems such as; vulnerability scanning, review of security/event logs, network analysis, security configuration review, and incident response on an as‑needed basis
- Administer and harden against DISA STIG Windows/Linux systems across physical and virtual environments; provision, patch, baseline, and manage AD accounts/groups
- Operate and maintain virtualization platforms (e.g., VMware/Hyper‑V): create VMs/templates/snapshots, monitor resources, and optimize performance
- Basic network administration (ports/VLANs/port security); monitor system/network health, respond to alerts, perform root‑cause analysis, and remediate
- Continuous Monitoring; deploy Splunk universal forwarders, ensure log ingestion health and develop searches, alerts, and dashboards for ops/cyber use
Required Skills/Experience areas include:
- Strong practical technical experience with multiple operating systems and types of technologies and the ability to audit them against compliance requirements
- Knowledge and application of NIST 800-171, NIST 800-53, NISPOM, DAAG, and other regulatory requirements
- Security plan development and/or continuous monitoring for compliance with security plans
- Strong system and network administration skills
- Active security clearance, at the Top Secret level or higher
- Effective analytical, problem solving, and communication skills
- Efficient organizational, multitasking, and time management abilities with the aptitude to work independently, as part of a team, and across multiple teams in various disciplines
Preferred Skills/Experience areas include:
- Experience certifying and accrediting systems and networks
- TCP/IP network analysis and network/packet level examination tools
- Experience with vulnerability management tools and best practice
- SEIM management or use for analysis, such as Splunk or ELK
- VMWare and management of Virtual Machines