Cyber Security Engineer
Global Ordnance LLC · Sarasota, FL · 1 mo ago
On-siteInformation TechnologyFull-time
Cybersecurity Engineer
This critical position is for a highly skilled and experienced Cybersecurity Engineer who will play a key role in protecting the organization's sensitive data and systems.
Essential Duties & Responsibilities
- Cybersecurity Policy Implementation and Maintenance:
- Develop, implement, and maintain cybersecurity policies, procedures, and standards in accordance with industry best practices and regulatory requirements (e.g., NIST 800-171 Rev 3, ISO 27001, GDPR, UK Cyber Essentials, etc.).
- Ensure compliance with relevant regulations and frameworks.
- Conduct regular reviews and updates of security policies.
- Data Loss Prevention (DLP):
- Design, implement, and manage DLP solutions to protect sensitive data.
- Monitor DLP alerts and investigate potential data breaches.
- Fine-tune DLP policies to minimize false positives and maximize effectiveness.
- SharePoint Administration (Multi-Tenant):
- Administer and maintain SharePoint environments across three tenants.
- Manage user access, permissions, and security settings.
- Implement and enforce security policies within SharePoint.
- Troubleshoot SharePoint related security issues.
- GCC High Tenant Implementation:
- Assist in the planning, implementation, and configuration of a new GCC High tenant.
- Ensure security best practices are followed during the migration process.
- Collaborate with other teams to integrate GCC High with existing systems.
- Data Tagging and Migration:
- Implement data tagging strategies to classify and categorize sensitive information in alignment with both best practices and compliance programs.
- Plan and execute data migration projects, ensuring data integrity and security.
- Automate data tagging and migration processes where possible.
- Automate process and workflows for secure sharing with only vetted and approved users.
- Vulnerability Management:
- Monitor security alerts and vulnerability scans.
- Analyze vulnerability reports and prioritize remediation efforts.
- Implement timely patches and fixes to address identified weaknesses.
- Track and report on vulnerability remediation progress.
- Respond to security incidents and breaches.
- Security Awareness Training:
- Contribute to the development and delivery of security awareness training programs.
- Educate employees on best practices for cybersecurity.
- Collaboration & Communication:
- Collaborate with other IT teams and business units to ensure security is integrated into all aspects of the organization.
- Communicate effectively with technical and non-technical stakeholders.
- Provide regular updates on security status and initiatives.
Qualifications & Requirements
- Required Qualifications:
- Candidates must meet Authorized US Persons criteria under ITAR – candidates must be either US Citizen, Lawful Permanent Resident or other certain protected authorized asylees. Additionally, qualified candidates may not be otherwise disbarred from having access to ITAR controlled information.
- Current US Government Secret Clearance (or higher) is required.
- Bachelor's degree in Computer Science, Cybersecurity, or a related field.
- Proven experience in cybersecurity engineering, preferably in a regulated industry.
- Strong understanding of cybersecurity frameworks and regulations (e.g., NIST, ISO 27001, HIPAA, etc.) and GRC tools.
- Expertise in data loss prevention (DLP) technologies.
- Extensive experience in SharePoint administration, including multi-tenant environments.
- Hands-on experience with Microsoft 365 security features.
- Experience with GCC High implementation and management is highly desirable.
- Knowledge of data tagging and classification techniques.
- Relevant degrees, skilled trades certifications or licenses preferred
- 1 to 3 years of relevant experience.
- Experience with DoD acquisition process, and DoD contracting requirements preferred
- Demonstrated ability to build and maintain relationships with government officials, defense organizations, and industry stakeholders
- Excellent communication, negotiation, and presentation skills
- Self-starter with strong analytical and problem-solving skills
- Ability to work independently and as part of a team in a fast-paced and dynamic environment
- Willingness to travel
- ISO 9001:2015 training preferred
- Proficient in the use of Microsoft Office suite (Word, Excel, Outlook, PowerPoint, and Project)
- Preferred Qualifications:
- Relevant certifications (e.g., CISSP, CISM, Security+)
- Experience with scripting languages (e.g., PowerShell, Python)
- Knowledge of cloud security best practices
- Experience with security information and event management (SIEM) systems