Job Type
Full-time
Description
Salary: $115,000 - $121,000/year
Work location: Hybrid with as-needed on site work, Washington, DC
Duties and Responsibilities:Conducting Security Assessments & Penetration Testing:
- Perform vulnerability assessments using various tools and techniques (e.g., network scanning, code reviews, penetration testing) to identify and document security weaknesses.
- Analyze security logs and identify suspicious activity.
- Generate comprehensive reports detailing findings, risks, and remediation recommendations.
Implementing & Managing Security Controls:
- Design, deploy, and configure security controls such as firewalls, Intrusion Detection System (IDS), Intrusion Prevention System (IPS), Endpoint Detection & Response (EDR), Zero Trust Security (ZTS), Security Information & Event Management (SIEM) solutions.
- Monitor security systems for alerts and anomalies, investigate security incidents, and respond to security breaches effectively.
- Manage security access controls, including user authentication, authorization, and access rights.
- Implement and maintain security policies, procedures, and standards.
Incident Response & Forensics:
- Develop and maintain incident response plans.
- Investigate security incidents, collect and analyze evidence, and assist in the remediation process.
- Conduct forensic analysis of systems and data to identify the root cause of security breaches.
Staying Current on Threats & Technologies:
- Research and stay updated on emerging cyber threats, vulnerabilities, and attack vectors.
- Attend industry conferences, training sessions, and read security publications to enhance knowledge and skills.
- Evaluate and recommend new security technologies and solutions to improve the Court's security posture.
Requirements
- Minimum of 7 years of professional experience in cybersecurity or a related field (e.g., systems administration, network engineering).
- Hands-on experience with security tools and technologies such as firewalls, Intrusion Detection System (IDS), Intrusion Prevention System (IPS), Endpoint Detection & Response (EDR), Zero Trust Security (ZTS), Data Loss Prevention (DLP), Security Information & Event Management (SIEM), vulnerability assessment solutions.
- Strong understanding of cybersecurity principles and best practices: Familiarity with common attack vectors (e.g., malware, phishing, social engineering), security frameworks (e.g., NIST Cybersecurity Framework, ISO 27001), and regulatory compliance requirements (e.g., GDPR, HIPAA).
- Proficiency in network security concepts: Deep understanding of network protocols (TCP/IP, UDP, DNS), network topologies, and network devices (routers, switches, firewalls).
- Technical expertise: Proficiency in scripting languages (e.g., Python, PowerShell), command-line interfaces (CLI), and various operating systems (Windows, Linux, macOS).
- Analytical and problem-solving skills: Ability to analyze complex security issues, identify root causes, and develop effective solutions.
- Excellent communication and interpersonal skills: Ability to communicate technical information clearly and concisely to both technical and non-technical audiences.
- Strong attention to detail and organizational skills: Ability to manage multiple tasks, prioritize effectively, and work independently.
At least one of the following technical certifications*:
- CompTIA Security+: A foundational certification demonstrating a broad understanding of cybersecurity concepts and principles.
- Microsoft Azure Security Technologies Certified
- Certified from Zscaler, CrowdStrike, or/and Splunk vendor programs....
- Certified Ethical Hacker (CEH): A certification focusing on the technical skills required to perform ethical hacking and penetration testing.
- Certified Information Systems Security Professional (CISSP): A globally recognized certification for information security professionals.
- GIAC certifications: A range of certifications offered by the GIAC (Global Information Assurance Certification) organization covering specific areas of cybersecurity (e.g., GCIH, GPEN, GCIA).
- *Agreement to recertify within 3 months of start date if certifications have lapsed
Desirable Qualifications:- Bachelor's degree in computer science, Information Technology, or a related field
Clearance Requirement: Ability to obtain and maintain a Public Trust.
The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:
- 3 weeks of Personal Leave your first year
- 11 paid Holidays each year
- 5 days of Flexible Time Off each year
- 401(k) company match at 50% up to 10% of your salary
- Medical, Dental and Vision Insurance
- Life and Disability Insurance
- Public Transportation Subsidies
- Certifications and Training Allowance - Up to $5,000/year!
Salary Description
$115,000 - $121,000/year