Cybersecurity Engineer - Middle in Arlington, Virginia at Saliense Consulting LLC
Explore Related Opportunities
Job Description
About Saliense
At Saliense, we are committed to fostering a culture of continuous learning and professional growth. Our employees are encouraged to take on challenging and meaningful work, with ample opportunities for career advancement. We offer competitive compensation and benefits, including:
- 20 Days PTO + 40 Hours of Paid Sick & Safe Time
- 11 Federal Holidays + 2 Corporate Holidays
- Health, Vision, Dental, and Life Insurance
- 401(k) with Tiered Match & 100% Vesting
- Parental Leave for Birthing and Non-Birthing Parents
- Professional Development Reimbursement Program
We believe in empowering our team members to achieve their professional goals while contributing to impactful projects that make a difference. Join us at Saliense and be part of a growing organization dedicated to innovation, collaboration, and excellence. Visit www.saliense.com to learn more.
There are many more - connect with us to get a preview of the full benefits package.
Security Engineer - Middle will conduct technical security assessments, audits, penetration testing, and forensic IT functions of USMS client/server systems (native and virtual), databases, networks, and vehicle/appliance technology systems. In-depth experience configuring and managing one or more SIEM tools. Be able to identify current security infrastructure and define future programs, design and implementation of security related to IT systems.
Must have a minimum of three (3) years of proven information systems security engineering experience. At minimum, an in-depth knowledge and management of one or more Security Incident and Event Management (SIEM) tools is required. Additionally, the Security Engineer - Middle shall possess hands-on experience in penetration testing and router/firewall management.
Technical Skills:
· In-depth, hands-on configuration and management of one or more SIEM tools.
· Log collection, aggregation, normalization, and correlation from diverse sources (e.g., servers, network devices, and applications).
· Event monitoring, analysis, and reporting.
· Experience with conducting penetration testing and technical security assessments.
· Vulnerability and patch management.
· Automated and manual security testing techniques.
· Router and firewall management, including installation, configuration, and troubleshooting.
· Intrusion detection and prevention systems (IDS/IPS).
· Operating system security, including experience with Windows and Linux environments.
· Securing virtualized client/server systems.
· Database security.
· Coordinating and managing security incident response efforts.
· Forensic IT functions to investigate security breaches and determine root cause.
· Log analysis for security incidents.
· Defining, reviewing, and enforcing information security policies, standards, and guidelines.
· Ensuring compliance with relevant regulatory requirements.
· Knowledge of current security trends and threats.
· Researching new attack vectors.
· Thinking like a hacker to anticipate vulnerabilities.
· Familiarity with scripting languages (e.g., Python, Bash) for automating security tasks and managing systems.
· Experience with security automation frameworks.
Responsibilities:
· Define, review, and enforce information security policy, standards and guidelines for business operations and technology implementations.
· Proactively speculate and identify IT security risks from technical and functional perspectives.
· Conduct technical security assessments as part of the enterprise vulnerability and patch management program.
· Conduct as needed technical security assessments, audits, penetration testing, and forensic IT functions of USMS client/server systems (native and virtual), databases, networks, and vehicle/appliance technology systems.
· Coordinate and conduct event collection, log management, event management, compliance automation, and identity monitoring activities for the USMS enterprise.
· Analyze data collected by the event monitoring system(s), identifying results that dictate immediate corrective action, trends that drive prompt action and areas that require continued monitoring and/or further analysis.
· Maintain awareness of current security trends and threats, respond to reported incidents to conclusion, and provide awareness to system users.
· Coordinate IT security matters such as incident response, intrusion detection management, and customer security advisories.