Job SummaryDUTIES AND RESPONSIBILITIES:Primary FocusIncident response, risk analysis, and advanced troubleshooting. Responsible for the day-to-day management and monitoring of security systems after implementation by the Cybersecurity teams. Performs network observability, threat detection, security metrics reporting, and automation-driven operational workflows to maintain continuous visibility into the organization's security posture and enable rapid identification and response to security events. Escalates complex changes or advanced troubleshooting to engineers. This role is part of the Cybersecurity Defense Operations career track, focusing on security monitoring, enforcement, and operational risk reduction.
Security Policy Enforcement & EngineeringImplement and integrate enterprise security technologies, ensuring security policies are effectively enforced across hybrid environments. Analyze policy effectiveness, recommend policy adjustments. Ensures that security policies remain enforced across security systems and services as part of operational security responsibilities. Work closely with engineers for major updates and reconfigurations. Leverage networks observability data and security telemetry to support threat detection, validate policy effectiveness, and produce actionable metrics for reporting for operational and executive visibility. Automation workflows should be applied to policy enforcement and validation processes where applicable.
Technical Consulting & Business SupportAdvise internal teams on security control best practices, aligning security solutions with business needs. Provide data-driven consulting, supported by metrics and threat intel to improve decision making. This role will provide on-site support for cybersecurity, infrastructure, and business solutions.
Cybersecurity Asset & Patch ManagementMonitor patch compliance, troubleshoot patch-related security issues. Incorporates security telemetry and network observability to identify patch-related risk exposure, enhance threat coverage, and support metrics reporting on compliance posture.
Complex Security Solution DevelopmentDevelop scripts and automation to streamline security solution deployments, focusing on segmentation and VPN automation. Expand workflow observability and metrics reporting pipelines to measure solution deployment effectiveness and security impact.
Security System Implementation & OptimizationOptimize security tools for better efficiency and integration. Maintain and manage deployed security systems such as firewalls, VPNs, and segmentation controls, ensuring continued security enforcement and policy compliance. Optimize enterprise security enforcement technologies, ensuring efficiency and seamless integration. Support the design and implementation of security enforcement technologies. Integrates network observability frameworks and threat detection capabilities into deployed systems and provide performance, risk, and compliance visibility. Automation workflow should be used to enhance monitoring, tuning, and operational response processes.
Collaboration with Cybersecurity TeamsSupport operational security teams by ensuring all security technologies are correctly integrated and aligned with enforcement policies. Create and advance automation workflows that improve operational efficiency and incident response effectiveness. Mentor other analysts and engineers. Contribute to process improvements.
Career ProgressionThis track leads to advanced roles in security operations, incident response, and strategic cybersecurity defense leadership.
Job Qualifications- Typically requires a bachelors degree in a related discipline and two or more years of progressive professional experience in cyber security or a related field. Equivalent professional experience may be substituted in lieu of education.
- 3-5 years of hands-on cybersecurity experience preferred.
- Some understanding of security practices and threat landscapes.
- Quickly adopts new tools and contributes to process improvement.
- Effective communicator with end users and technical teams.
- Capable of resolving moderately complex technical issues.
- Works well independently and collaboratively.
- Desired: GSEC, CEH, CySA+, or equivalent intermediate certification.
- Desired: Experience in Next-Generation Firewall (NGFW) technologies
- Desired: Experienced in some of the following: Python, Powershell, Java, Bash, KQL/SQL
- Relevant: AWS Solutions Architect - Associate, Microsoft Azure Administrator, CompTIA Cloud+, Cisco CCNA, Palo Alto, M365 Security.
- Effective communicator, collaborative team player, and adaptable under pressure.
- Ability to obtain and maintain a DoD Secret clearance.
This position may transition to fully on-site as the business demand/requirements change.