Enable job alerts via email!

DHS HSEN – Security Architect (SIEM & SOAR)

Versar

Washington

Remote

USD 90,000 - 150,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as a Security Architect, where you'll play a crucial role in enhancing national security through advanced SIEM and SOAR solutions. In this dynamic position, you'll collaborate with top-tier network and security engineers to design and implement cutting-edge security architectures, ensuring the integrity of vital data within the Homeland Security Enterprise Network. Your expertise will drive improvements in incident response and security automation, making a significant impact on national cybersecurity efforts. If you're passionate about protecting critical infrastructures and thrive in a collaborative environment, this is the perfect opportunity for you.

Qualifications

  • 6+ years of experience in cybersecurity and incident response.
  • Expertise in SIEM and SOAR tools, particularly Swimlane and Splunk.
  • Strong knowledge of cloud platforms and network security.

Responsibilities

  • Design and maintain SIEM and SOAR solutions for improved security.
  • Collaborate with teams to enhance security requirements and tools.
  • Research and present findings on latest security technologies.

Skills

Cybersecurity
SIEM
SOAR
Swimlane
Splunk
Cloud Security
Network Security
Incident Response
Programming/Scripting (Python, PowerShell)

Education

BA or BS in Cyber Security
BA or BS in Computer Science
Relevant experience may substitute for education

Tools

Splunk
Swimlane
AWS
Azure
Windows/Linux

Job description

Position Summary

BayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Security Architect (SIEM & SOAR) to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This resource will be a member of a high functioning team of network and security engineers, data center specialists, and stakeholder groups, such as the DHS Network Operations Security Center – Cyber (NOSC-Cyber), ISSOs, and industry vendors, working to continually strengthen and secure HSEN and its data.

The candidate’s primary responsibility is to maintain and mature the existing DHS Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solutions, and lead the analysis, integration, and testing of this and new security tools and technologies.

This role is eligible for full-time telework.

Duties / Responsibilities

  • Designing, implementing, and maintaining SIEM and SOAR solutions by collaborating effectively with NOSC-Cyber and other key stakeholder groups.
  • Work in partnership with network and security engineers and cloud development teams to drive improvements to security requirements.
  • Research the latest capabilities of SIEM, SOAR platforms and IT technologies (e.g. firewalls, operating systems, networks, storage, virtualization, AD, IPS, Proxies etc.) and be able to present findings to management.
  • Optimize SIEM, SOAR and NOSC-Cyber architecture to improve efficiency and effectiveness of the platforms and processes.
  • Design and implement threat detection, automate incident response processes, integration of various security tools with SIEM and SOAR platforms via APIs.
  • Maintain SIEM applications to collect and aggregate IDS and IPS data from network sensors, raw data from collection agents, firewalls, proxy servers, DLP, antivirus, vulnerability scanner elements, and other security‐relevant devices.
  • Design and document existing production Swimlane environment to include Visio diagrams.

Minimum Qualifications / Requirements

  • At least six (6) years of professional experience in cybersecurity, NOC/SOC environments, and IT Services environment, providing incident response.
  • Demonstrated experience with SIEM and SOAR tool suites, with an emphasis on Swimlane and Splunk.
  • Demonstrated experience in endpoint security, network security (Firewalls, IPS/IDS, DNS, Proxy, etc.), data and application security, cloud security and technologies.
  • Must be resourceful in learning a very complex and dynamically changing network.
  • Must be a self-starter, able to work independently, and able to manage time effectively.
  • Working knowledge of cloud platforms such as AWS, Azure.
  • Ability to communicate effectively with all levels of an organization from engineering, operations, and management.
  • U.S. citizenship required and eligibility for a DHS EOD is required to be considered for this position.

Education

BA or BS (Cyber Security, Computer Science, Information Systems, Software Engineering, Computer Engineering, or related field); relevant experience may be a substitute for education.

Certifications Desired But Not Required

  • Certification involving cybersecurity.
  • Comptia Security+.
  • Splunk.
  • CISSP.
  • CCNP Security.
  • CCIE Security.

Software/Hardware Desired

  • Splunk.
  • Swimlane.
  • Knowledge of at least one programming or scripting language (ex. Python, PowerShell, PHP, Perl).
  • Windows/Linux experience.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

DHS HSEN - Security Architect (SIEM & SOAR)

VERSAR, INC.

Remote

USD 120,000 - 132,000

8 days ago