Posted:
8/7/2024, 5:00:00 PM
Location(s):
Ashburn, Virginia, United States ⋅ Virginia, United States
Experience Level(s):
Mid Level ⋅ Senior
Field(s):
IT & Security ⋅ Software Engineering
Job Description:
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, various cloud environments, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.
Primary Responsibilities:
The Cyber Security Engineer Mid will support the full system engineering life-cycle, including requirements analysis, design, development, test, implementation, maintenance, integration, and documentation of SOC infrastructure and SOC tool suite.
The Security Engineer will be installing, configuring, monitoring, and troubleshooting network security solutions and related monitoring tools including L2/L3 network security devices, IDS/IPS, Full packet capture, DLP, Endpoint (AV, DLP, Endpoint Detection & Response), and infrastructure supporting SEIM (Splunk).
The Security Engineer must have understanding and knowledge of LAN/WAN security solutions including creating and maintaining LAN/WAN security standards and design documentation.
Knowledge and familiarity with new LAN/WAN security applications and hardware as assigned.
Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell
Strong written and oral communication with the ability to communicate with team members, management and customer.
Below are some tools/skills the candidate should have knowledge or experience on:
3-5 years’ experience in Systems Engineer/Admin role or an equivalent of 3-5 years in Cybersecurity.
Hands on experience on AWS – Majority of the environment systems are in AWS. These may include EC2, Storage, Lambda, S3, VPC, Storage Gateways
Hands on experience with Linux – More than half of the systems being managed are Linux. This ranges from CentOS, Amazon Linux 2, RHEL, Kali Linux, and Rocky Linux. Knowledge/experience in patching and updating these will be key.
Knowledge/experience with Windows – Need knowledge in setting up and building using images. Someone who knows the ins and outs of where logs and other locations of data are on a windows system is a plus.
Hands on experience with Troubleshooting – Mid to high level troubleshooting skills. Have the knowledge and experience on where to look for logs and errors within applications and OS’s.
Knowledge and understanding of Networking and how it all ties together – networking knowledge, VPNs, DNS, DHCP, AWS VPCs, Firewalls.
H knowledge/experience on Applications – automation software such as Ansible, Windows SCCM, or any automation software.
Understanding of cybersecurity processes and protocols.
Knowledge and understanding of some Antivirus software such as McAfee and CrowdStrike. Any HIPS software and how it works.
Understanding of SOPs, Playbooks, and experience in creating documentation.
Basic Qualifications:
Bachelor’s degree in computer science, Engineering, Software Development, Information Technology, Cyber Security, or related field and 6 years of related experience. Additional years of experience and cyber certifications may be considered in lieu of degree.
Familiar with the management, operational, and technical aspects of IT Security in a complex enterprise environment. Additional experience in cyber risk management and assessments will be considered.
Knowledge and familiarity with in-depth analysis of Zero Trust Capabilities, Infrastructures and Architecture.
Clearance:
All Department of Homeland Security CBP SOC employees are required to favorably pass a 5-year (BI) Background Investigation.
Preferred Qualifications:
Ability to learn and support new systems and applications.
Redhat, Cisco or Microsoft, Security+, Linux+, or Network+ certifications
Cisco Hardware and Storage
Expertise in Networking, Linux and Windows
Sourcefire (snort) or RSA Security Analytics (network) experience a plus
Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell
While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Website: https://www.leidos.com/
Headquarter Location: Reston, Virginia, United States
Employee Count: 10001+
Year Founded: 1969
IPO Status: Public
Industries: Computer ⋅ Government ⋅ Information Services ⋅ Information Technology ⋅ National Security ⋅ Software