Cyber Senior Systems Engineer
Pantex Plant · Amarillo, TX · 1 wk ago
Information TechnologyFull-time
Location: Amarillo, TX - Pantex Plant
About the Role
Pantex is seeking a highly skilled and motivated Senior Systems Engineer with a specialized focus on Cybersecurity Operations. In this critical role, you will be the cornerstone for designing, implementing, and optimizing the vital infrastructure that secures our enterprise. We are looking for a seasoned System Engineer with a profound operational understanding of cybersecurity principles, capable of transforming complex security requirements into robust, scalable, and resilient technical solutions across on-premise, cloud, virtualized, and containerized environments.
Responsibilities
- Cybersecurity Operations Platform Engineering: Lead the engineering, deployment, and operational sustainment of core cybersecurity platforms. Serve as a subject matter expert for Splunk (Enterprise Security highly desired), optimizing its performance for security logging, correlation, and advanced threat detection. Manage and enhance Cisco network security devices (e.g., Firewalls, Intrusion Prevention System (IPS), Proxies), Corelight Open Network Detection and Response (NDR) platform sensors, and critical network visibility infrastructure like Gigamon packet brokers.
- Secure System Architecture & Hardening (Linux/Windows/Red Hat): Architect and implement secure configurations and hardening standards for enterprise operating systems, with a strong focus on Red Hat Enterprise Linux and Microsoft Windows Server.
- Cloud Security Operations & Infrastructure (Azure/M365): Design, implement, and maintain the operational security posture within our Azure/M365 environment, including managing secure configurations, implementing and monitoring cloud security controls, and integrating cloud-native security services with our broader security operations framework.
- Advanced Virtualization & Container Security Engineering: Develop and implement operational security for Virtual Desktop Infrastructure (VDI), virtualized platforms, and containerized environments (e.g., Docker, Kubernetes). Engineer solutions for secure image deployment, runtime protection, and integration of container security into monitoring and response workflows.
- Endpoint Security Management & Automation: Engineer, deploy, and manage enterprise-wide Endpoint Detection and Response (EDR) platforms. Create, automate, and optimize security policies, ensuring effective endpoint protection, detection, and integration with incident response playbooks.
- Email Security System Ownership: Own the engineering, configuration, and operational management of enterprise Email Security Gateways (e.g., Cisco Secure Email / IronPort). Develop and enforce advanced email security policies to combat phishing, malware, and other sophisticated threats.
- Proactive Threat Detection, Hunting & Incident Response Integration: Collaborate with security analysts and incident responders to enhance threat detection capabilities. Engineer and automate data collection, correlation rules within Splunk, and operationalize threat intelligence to support proactive threat hunting and rapid incident response, leveraging rich network evidence from platforms like Corelight and Gigamon.
- Network Security Infrastructure & Data Flow Optimization: Design and optimize network security infrastructure, including Cisco devices, Corelight sensors, and Gigamon packet brokers, to ensure comprehensive visibility and efficient data flow for security monitoring.
- Application Security Operations Support: Provide operational support for Application Security Testing (AST) platforms (e.g., Burp Suite) and Web Application Firewalls (WAFs), translating application security findings into actionable system-level defenses.
- Enterprise Vulnerability Management & Remediation Engineering: Design and implement automated processes for vulnerability scanning, analysis, and remediation tracking across all IT assets.
- Security Controls Engineering & Effectiveness: Translate security architecture requirements into robust, operational security controls across various technologies. Continuously assess their effectiveness and optimize their performance within the operational environment.
- Automation & Integration for Security Operations: Lead initiatives for automating security tasks, integrating disparate security tools, and developing scripts to streamline security operations workflows, enhancing overall efficiency and response times.
Qualifications
- A Hands-On Security Operations Leader: Highly experienced Systems Engineer with a deep operational understanding of cybersecurity, passionate about building and securing robust infrastructure.
- Proactive & System-Oriented Problem-Solver: Exceptional ability to anticipate complex security challenges within systems and networks, proactively identify issues, and engineer practical, scalable solutions.
- Deep Technical Expertise: Profound skill set in system administration, networking, and security tool engineering, with verified experience in Splunk, Cisco, Corelight, Gigamon, and Red Hat.
- Autonomous & Adaptable Engineer: Self-starter who consistently seeks to deepen technical knowledge and adapt solutions to an ever-changing threat landscape and evolving technologies.
- Analytical & Detail-Oriented: Excel at dissecting complex system and security data, identifying root causes, and implementing precise, effective operational changes.
- Effective Communicator & Collaborator: Clearly articulate complex technical system and security challenges and solutions to both technical and non-technical audiences, fostering strong collaboration across engineering and security teams.
Skills
- Expert-level engineering and operational management of Splunk, especially Splunk Enterprise Security (ES), for security logging, correlation, and advanced threat detection.
- Proven, hands-on experience with Cisco network security devices, including firewalls, IPS, and proxy solutions, with a strong emphasis on operational configuration and troubleshooting.
- Extensive experience in system administration, hardening, and securing enterprise operating systems, including deep expertise with Red Hat Enterprise Linux and Microsoft Windows Server environments.
- Demonstrated experience with Corelight sensors and the Corelight Open NDR platform, including deployment, configuration, optimization, and leveraging its network telemetry for advanced threat detection and incident response.
- Proven experience with Gigamon packet brokers (GigaVUE Fabric Manager, GigaSMART features for traffic mapping, deduplication, slicing, and tool load balancing), including deployment, maintenance, and integration with security tools like SIEM and IDS/IPS systems.
- Strong experience in designing, implementing, and securing cloud environments, particularly Azure/M365, including Azure Security Center, Entra ID, and cloud-native security controls.
- Proficient engineering skills for Endpoint Detection and Response (EDR) platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint), including policy creation, automation, and incident response integration.
- Demonstrated experience with Email Security Gateway solutions (e.g., Cisco Secure Email / IronPort), including advanced policy configuration to prevent phishing and malware.
- Solid experience in engineering and operationalizing security for virtualized environments (e.g., VMware, Hyper-V) and Virtual Desktop Infrastructure (VDI).
- Deep practical experience in securing containerization and orchestration technologies (e.g., Docker, Kubernetes), including image scanning, registry security, and runtime protection for operational environments.
- Advanced understanding of networking protocols (e.g., TCP/IP, DNS, HTTP/S, SMTP) and significant experience using tools like Gigamon packet brokers and Corelight sensors for network traffic analysis and security monitoring.
- Ability to perform vulnerability scans, analyze results from an operational perspective, and engineer effective remediation strategies across diverse system types.
- Strong scripting and automation skills (e.g., Python, PowerShell, Bash) to streamline security operations tasks and integrate security tools.
- Experience with Application Security Testing (AST) tools (e.g., Burp Suite) and Web Application Firewalls (WAFs) from an operational management and configuration standpoint.
- Ability to design and validate security controls to meet operational objectives across various technological landscapes.
- Knowledge of critical infrastructure systems and associated information communication technology security considerations.
- Proven ability to design and implement robust system access controls for sensitive information systems and networks.
- Experience with technology integration processes, especially in complex hybrid, virtualized, and containerized environments.
- Familiarity with industry standards and frameworks (e.g., NIST, ISO 27001) as they apply to operational cybersecurity.
Requirements
- Bachelor's degree in engineering/science/information technology discipline with a minimum of 2 years of relevant experience (typical experience ranges from 3 to 7 years).
- OR Master's degree in engineering/science/information technology discipline.
- OR applicants without a bachelor's degree may be considered based on a combination of at least 10 years of completed education and/or relevant experience.
Preferred Requirements
- A minimum of 7+ years of hands-on experience in Systems Engineering with a significant focus on Cybersecurity Operations.
- Demonstrated experience and/or certifications in Splunk, Cisco network security, Corelight, Gigamon packet brokers, and Red Hat Enterprise Linux.
- Relevant advanced industry certifications such as Corelight Certified Engineer, Gigamon Certified Professional, Splunk Enterprise Certified Admin/Architect, Cisco Certified Network Professional Security (CCNP Security), Red Hat Certified Engineer (RHCE), Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC) GIAC Certified Incident Handler.