Jobs · Information Technology

Network Security Engineer

Titan Technologies · Destin, FL · Yesterday
RemoteRemoteInformation TechnologyFull-time

About the role

Zen Strategics, a Titan Technologies company, is seeking a Senior Network Engineer to support cybersecurity efforts for DHS USCIS systems. The Engineer will be part of Enterprise Security Architecture in Network Security which consists of the policies, processes, and practices to prevent, detect and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources. Network security involves the authorization of access to data in a network. This role supports security activities associated with evaluating and improving the security of the USCIS network.

Responsibilities

  • Establish a new cybersecurity architecture and a standard set of controls commensurate with the increased threat to USCIS systems and data, including risk indicators and alignment to current measures.
  • Evaluate current and future network designs to ensure that security is incorporated.
  • Establish an Enterprise Data Security Architecture that identifies sensitive data elements requiring protection.
  • Identify and evaluate information security threat models and methodologies. Manage the implementation and maintenance of the selected methodologies by applying the threat model to support ongoing, proactive protection of the USCIS enterprise environment, and to facilitate an efficient response to security incidents.
  • Develop standards, templates and automated mechanisms to support threat modeling and analysis of individual USCIS information systems and information.
  • Provide recurring inputs, triggers and reporting into the USCIS SIEM and Ongoing Authorization processes.
  • At the discretion of the Federal task lead, architect, deploy, operate, and support a wide range of enterprise security solutions to address a broad set of security needs including, but not limited to: Vulnerability Management, Configuration Management, Network Access Controls, Malware Defenses, Application Software Security, Secure Code and library Review, Software Asset Management, Hardware Asset Management, Vulnerability Remediation, Security Event and Log Management, Incident Response, Penetration Testing, Wireless Access Control, Least Privilege, Network Monitoring, Boundary Defense, Security Assessment, Account Monitoring and Control, Data Protection, Insider Threat, Continuous Monitoring, and/or others as requested by the Government.
  • Automate and streamline repetitive IT security processes, and the handling of vast amounts of security data, at the discretion of the Federal task lead, using programming and the Security Event Management framework to consolidate security information and reporting.
  • Create actionable intelligence through triggers, filters, and signatures that pinpoint threats contained within the SIEM for Security Operations to investigate from new and existing continuous monitoring security products, such as, but not limited to: ForeScout, Tenable.io, CrowdStrike, DbProtect, Splunk, and CISCO ISE/IDS/IPS.
  • Implement and support filters, plugins, access control lists, and monitoring rules for new and existing continuous monitoring security products, such as, but not limited to: Tenable.io, CrowdStrike, Burp Suite, Splunk, CISCO ISE/IDS/IOS, Microsoft SCCM, PortSwigger Burp Suite and Fortify, etc.
  • Attend meetings, design reviews, engineering conference calls, system readiness reviews, and participate in Integrated Planning Teams (IPTs) and/or Scrum Sprints/Increments as required by the Federal lead to monitor security requirement execution throughout the USCIS/DHS Systems Lifecycle process and deliver minutes, and any ad-hoc project reporting requested by the Government.
  • Write system lifecycle documentation for security products or security-relevant system components. This includes, but is not limited to: project architecture diagrams, project plans and timelines, Concepts of Operations, Standard Operating Procedures, use cases, user stories, change management documents, system lifecycle documentation, technical implementation strategies, and product specific configurations that align with USCIS policy and procedure, DHS policy and procedure, DHS continuous monitoring requirements and annual metrics, DoD STIGs, and NIST Special Publication 800 Guidance.
  • Perform product/standards comparisons based upon research, independent lab test result reports, intelligence agency recommendations, and other resources authoritative, mandatory, or compelling to a U.S. Federal agency.
  • Support the design and deployment of information security solutions at all layers of the OSI model, physical layer to application layer, to facilitate a comprehensive defense-in-depth strategy and intrusion defense chain methodology.
  • Be responsible for the technical configuration, installation, and/or monitoring of products into a pilot/evaluation location established via the USCIS Change Request (CR) process.
  • Generate procedures necessary to operate and maintain products under pilot/evaluation.
  • Generate USCIS/DHS Systems Lifecycle Process documentation necessary to obtain engineering approval for products under pilot/evaluation.
  • Generate the Enterprise Architecture (EA) documentation as necessary.
  • Schedule and attend meetings, file USCIS forms, tickets, and change requests necessary to facilitate successful deployment of security products/projects.
  • Generate and present formal reports and presentations that explain and defend the recommended product selections in meetings designated by the Government POC requesting the evaluation.
  • Assist with defining network architecture by ingress/egress micro-perimeters with some internal micro-segmentation.
  • Review existing configuration settings to identify potential security vulnerabilities and propose settings or architectural changes to address these vulnerabilities.
  • Work collaboratively with other teams to improve the use of automated configuration management capabilities to initiate network and environment changes and enforce security-relevant configuration settings.
  • Assist with the development of automation to discovery networks, devices, and services, with manual or dynamic authorization and automated remediation of unauthorized entities.
  • Perform security hardening and rule creation for firewalls, switches, routers and other network equipment. This includes reviewing new and re-evaluating existing configuration settings and rules to verify USCIS' security posture and eliminate unnecessary risk.

Requirements

  • 10 years of experience in network engineering and operations and 3 years specialized experience deploying security products (Firewalls, IDS/IPS devices, StealthWatch, FirePOWER, Cisco ISE, ForeScout CounterACT, etc.).
  • Proficiency in configuring, securing, and creating custom rule sets for: Cisco Nexus, FlexPod, IOS, Identity Services Engine (ISE), StealthWatch, FirePOWER and any other additional networking technologies introduced by the Government during the duration of the contract.
  • Prior experience utilizing Cisco Prime, Orion SolarWinds or another configuration management tool to create enforceable configuration templates.
  • One of the following active certifications: Cisco Certified Internetwork Expert (CCIE) Security, CCIE Wireless, CCIE Data Center, CCIE Routing & Switching, Cisco Certified Network Professional Security (CCNP Security), or other comparable certification or experience, which must be approved in advance by the Government Program Manager on a case-by-case basis.
  • Ability to get and maintain Public Trust Security Clearance or Existing Public Trust Clearance preferred.

Qualifications

  • A Bachelor's degree in Computer Science, Information Management or Engineering, or other comparable degree or experience, which must be approved in advance by the Government Program Manager.

Similar jobs

Network Security Engineer

Navitas Business Consulting, Inc.Beltsville, MD· 2 mo ago
Information Technologyapply on ajax.googleapis.com

Network Security Engineer

University of Southern CaliforniaLos Angeles, CA· 1 mo ago
Information Technology$135k–$145k/yrapply on usccareers.usc.edu