GovCIO - Tampa, FL
posted 4 months ago
GovCIO is currently hiring a Mid Cyber Security Engineer to provide operation and integration support for a multi-vendor infrastructure, including various networks, systems, and virtual training environment (VTE) vendors. This hybrid position will be located in Tampa, FL. The Cyber Security Engineer will be responsible for correlating threat data from various sources to establish the identity and modus operandi of hackers active in the client's networks and posing a potential threat. The role involves providing the customer with assessments and reports that facilitate situational awareness and understanding of current cyber threats and adversaries. Additionally, the engineer will develop cyber threat profiles based on geographic region, country, group, or individual actors, and produce cyber threat assessments based on entity threat analysis. The position may also require providing computer forensic and intrusion support to high technology investigations, which includes computer evidence seizure, forensic analysis, data recovery, and network assessments. The engineer will be expected to research and maintain proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding, network security, and encryption. The responsibilities include working in a fast-paced environment alongside a team of highly specialized engineers, providing engineering and implementation action for integration, modernization, and new installations for partner nations and allies in Eastern Europe and South America. A higher-level knowledge of cybersecurity tools, appliances, and architecture is essential. The engineer must have a full understanding of designing, testing, and implementing/integrating cybersecurity devices, how they interact with the network, and where best to deploy sensors, nodes, and agents to ensure maximum effect in the enterprise network. The role also requires providing operation and integration support for a multi-vendor infrastructure, including various network, systems, and cybersecurity vendors. Understanding core cybersecurity technologies and architectures involving equipment such as Gigamon appliances or similar vendors for packet forwarding, deduplication, and stream splitting is crucial. Familiarity with Trellix/FireEye/McAfee or similar vendors for security stack applications, HIPS agents, and signature file/heuristic analysis is also necessary. Furthermore, the engineer should have an understanding of SIEM implementation, integration, and performance tuning of the SIEM data sources, such as Network Intrusion Detection Systems (NIDS), Firewalls/Proxies, and Domain Controllers, to maintain a manageable level of security event monitoring. Lastly, the engineer must have a great ability to document all network, system, and cybersecurity changes and develop required checklists, engineering and installation plans, and other required documentation within the configuration baseline.