Apply📍 United States
🧭 Full-Time
🔍 Driver & Vehicle solutions for government entities
- Bachelor's degree in Computer Science (or similar) or an equivalent combination of relevant education and work experience
- Knowledge of vulnerability management (scanning, reporting)
- SIEM – network and agent based (installation, operation, triage)
- Centralized log management
- Compliance frameworks (NIST 800-53, SOC II, ISO 27001, PCI-DSS)
- ITIL
- 2 or more years in an IT operations related position
- 1 or more years in an IT security related position is considered an asset
- Automation Languages: Python, Ruby, Bash, PowerShell
- O/S: Linux/Unix, Windows
- Security Technologies: IAM, MFA, H/NIDS, Traditional Perimeter and Endpoint security
- Cloud: Azure and/or AWS
- Software: MS O365
- Experience with Open-Source projects is considered an asset
- Collaborate with Risk and Compliance personnel to gather evidence for Compliance requirements (SOC II, ISO 27001, PCI, NIST 800-53, etc.).
- Develop and implement processes for evidence collection, ensuring accuracy, completeness and timeliness in response to audit requests.
- Collaborate with stakeholders to address compliance gaps and implement corrective actions.
- Design, implement and maintain automated processes within the SIEM environment to enhance threat detection, incident response and log management.
- Collaborate with cross-functional teams to integrate security controls and enhance the overall effectiveness of the SIEM solution.
- Develop and maintain automated responses to common security incidents.
- Monitor SIEM alerts and investigate security incidents to determine the root cause and appropriate remediation actions.
- Design, implement and maintain automated security processes to enhance efficiency and reduce response times.
- Prioritize and remediate identified vulnerabilities in collaboration with system owners and IT teams.
- Create and maintain documentation related to security policies, procedures and configurations.
- Communicate security risks and findings to technical and non-technical audiences effectively.
- Build relationships with stakeholders across groups to understand needs and requirements and the associated notification process.
AWSBashCybersecurityAzureLinuxCompliance
Posted about 1 month ago
Apply