Cyber Security Engineer Senior
Advance your career while impacting our national security in cyber as a Cybersecurity Engineer Senior at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. As a Cybersecurity Engineer Senior, you will play a crucial role in joining our team as a subject matter expert for all activities related to implementing, configuring, and maintaining security tools including SkyHigh Web Gateway, Cisco FirePower, CrowdStrike Falcon, and Palo Alto NGFW, and responding to potential and confirmed security incidents in the CCSQ Cloud Environment.
Responsibilities
- Administer, configure, deploy, and maintain Cisco FirePower Threat Defense (FTD) and SkyHigh Web Gateway appliances across the authorization boundary and enterprise-level environments.
- Implement advanced intrusion prevention systems (IPS) using Cisco FirePower to identify and block malicious traffic.
- Implement Cisco routers (CSRs) to do Policy Based Routing (PBR) on all network traffic from the Virtual Private Clouds (VPC).
- Design and optimize Security Rule Sets (SRUs) and tailor policies to meet organizational and mission-critical security requirements.
- Perform threat analysis, event correlation, and deep packet inspection to mitigate emerging cyber threats.
- Configure and manage Cisco FireSight/FirePower Management Center (FMC) for centralized policy management, event monitoring, and system reporting.
- Integrate FirePower NGIPS with other security solutions such as SIEM or SOAR platforms to enable automated threat response capabilities.
- Perform system upgrades, signature/engine updates, and antivirus pattern maintenance to ensure continued protection.
- Conduct regular audits and vulnerability assessments within FirePower systems to identify gaps in coverage.
- Troubleshoot Cisco FirePower appliances for performance issues, ensuring high availability and resilience across the network.
- Collaborate with cross-functional IT and security teams to optimize firewall configurations and enforce Zero Trust principles.
- Collaborate with CCSQ Security Operations Center (SOC), Cloud Solutions Engineers, and Application Development Organizations on blocking notifications and proactive optimization of the tools.
- Create and maintain detailed documentation for system configurations, policies, procedures, and operational tasks.
- Provide technical expertise, guidance, and training to internal teams on Cisco FirePower operations and best practices.
- Support Security audits as needed and advise Application Development Organizations (ADO) from a Tier 2 or 3 perspective, supporting security events of interest.
Requirements
- Bachelor's Degree in Computer Science or related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience.
- 5+ years of related experience in maintaining security systems in cloud environments.
- Experience in Amazon Web Services (AWS) Cloud Environments and the CMS CCSQ/QNET.
- Documented history configuring, maintaining, tuning, reporting, and remediating from multiple security tools and services.
- Background in AWS Security services including Guard Duty, Security Hub, Inspector.
- Proven ability to resolve security findings from security scanning.
- Ability to pivot and learn new tools on demand.
- Knowledge of system hardening benchmarks such as USGCB & STIG.
- SIEM experience with Splunk.
- Strong communication skills.
- Experience working in an Agile environment.
- Strong background with AWS security concepts, tools, and services.
- Self-motivated with a strong ability to work in a multi-tasking and changing environment.
- Demonstrated experience with security appliances such as Cisco FirePower, SkyHigh Web Gateway, CrowdStrike Falcon, and Palo Alto NGFW.
Skills
- Cisco FirePOWER, Firewalls, McAfee Web Gateway, Network Firewalls.
- Preferred certifications: AWS Certified Security Specialty, CISSP, or other security-related discipline.
- Strong understanding of key management and certificate management.
- Knowledge of system hardening benchmarks such as CIS.
- Experience with CrowdStrike Falcon, Palo Alto NGFW, and Snyk.
Benefits
- Comprehensive benefits and wellness packages.
- 401(k) with company match.
- Competitive pay and paid time off.
- Full-flex work week to own your priorities at work and at home.
- Paid leave including vacation (15 days per calendar year), sick and personal time, and 10 paid holidays per year (prorated based on hire date).
- GDIT Paid Family Leave program providing up to 160 hours of paid leave in a rolling 12-month period for eligible employees.
- Short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance.
Pay
The likely salary range for this position is $97,968 - $120,750. Salary will be set based on experience, geographic location, and possibly contractual requirements.
Schedule
- Scheduled Weekly Hours: 40
- 100% remote working.
Applicants must be able to possess and maintain a Public Trust clearance. Applicants shall have lived in the United States at least 3 out of the last 5 years prior to going through the public trust background investigation. Work visa sponsorship will not be considered for this role.