Overview
Join us and make a difference in National Security! This role protects customer information systems and networks from cyber-attacks. The Cyber Security Engineer – Technical Lead will be a hands-on, player-coach, dedicating approximately 75% of time to direct engineering, troubleshooting, and implementation, while providing technical leadership and coordination across the security team. The candidate will work with team leads, developers, operations personnel, and other Technical Leads throughout a DevSecOps life cycle. This is not a supervisory management role; success is measured by individual technical contribution and leadership impact.
Primary Responsibilities
- Plan, implement, manage, monitor, and upgrade security controls and tools to protect enterprise systems and networks; identify opportunities to automate repeatable tasks.
- Design, configure, implement, troubleshoot, and maintain security technologies (e.g., firewalls/security groups, endpoint protection tools, SIEM platforms).
- Formulate systems and methodologies; respond to security events and assist in remediation of incidents (system or network breaches, malware).
- Participate in change management to ensure security compliance and avoid introducing vulnerabilities.
- Conduct regular vulnerability scanning and assessment; provide reports and track remediation to closure.
- Provide technical leadership to the security engineering team; coordinate with peer Technical Leads to align architecture and security controls.
- Serve as primary technical escalation point for complex security issues; mentor junior engineers through collaborative troubleshooting.
Basic Qualifications
- Experience implementing and managing Security Information and Event Management (SIEM) tools such as Splunk or similar platforms.
- Experience with endpoint and network security technologies, including IDS/IPS, HBSS/Trellix, and related tools.
- Expert with automation (e.g., Ansible, CloudFormation).
- Proven ability to implement, troubleshoot, and maintain security technologies in production environments.
- Ability to balance technical leadership with hands-on engineering; strong attention to detail and problem-solving skills.
- Monitor security advisories and threat intelligence to stay informed on vulnerabilities and trends.
- Requires Master’s degree and 15+ years of relevant experience; active TS/SCI with polygraph preferred or equivalent experience per policy.
Preferred Qualifications
- Experience with additional security tools and processes such as IDS/IPS, VPN, GitHub, GitLab, SonarQube.
- Experience with network and application firewalls, VPNs, web protocols, incident detection/response, and forensics.
- Experience with Agile software development, scripting/programming (Python, PowerShell), DevSecOps pipelines and tools.
- Familiarity with cloud services (AWS, Oracle, Google).
- Knowledge of attack vectors (XSS, injection, hijacking, social engineering).
- Experience with health monitoring tools (SolarWinds) and STIG compliance assessment.
- Experience with databases, search engines, web applications, Linux (Red Hat), and Windows environments.
EEO notice: All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, disability, or any other status protected by law.