cFocus Software Incorporated
Security Engineer IV Security Tools and Analytics - HHS STIM
cFocus Software Incorporated, Atlanta, Georgia, United States, 30383
Job Overview
cFocus Software is seeking a highly skilled Security Engineer IV (Security Tools and Analytics) to support the Security Tools and Infrastructure Modernization (STIM) contract with the U.S. Department of Health and Human Services (HHS). The Security Engineer IV will provide enterprise-level expertise in deploying, managing, and optimizing security tools and analytics platforms to strengthen cybersecurity operations, monitoring, and compliance. Responsibilities
Deploy, configure, and maintain enterprise security tools such as SIEM, vulnerability management, and IDS/IPS platforms. Perform advanced security analytics and monitoring for threat detection, correlation, and incident response. Integrate security tools into SOC workflows and federal reporting requirements. Support vulnerability scanning, remediation planning, and compliance dashboards. Develop and manage automation/orchestration workflows across security platforms. Provide guidance and mentorship to junior security engineers and analysts. Collaborate with stakeholders to design and implement enterprise security solutions. Ensure compliance with NIST SP 800-53 Rev. 5, CIS Controls, FISMA, and FedRAMP standards. Document technical specifications, SOPs, and security engineering processes. Participate in 24/7/365 operations and on-call rotations as required. Required Experience
10+ years of cybersecurity engineering and operations experience. Extensive expertise with enterprise security tools including SIEM, endpoint protection, and vulnerability management platforms. Proven ability to support incident response and forensic investigations using security analytics. Experience leading enterprise security engineering initiatives in federal environments. Strong communication and documentation skills for reporting and compliance activities. Lead and coordinate initiatives, managing requirements, schedules, and actions to ensure timely and successful project delivery in alignment with organizational objectives. Collaborate with Security, Infrastructure, and Operations teams to develop, implement, and manage automation scripts, enhancing the efficiency and effectiveness of security operations. Candidate will possess knowledge and/or familiarity with Armis and/or Axonius solutions relating to Cyber Asset Attack Surface Management (CAASM) and the Elastic Stack solution for searching, analyzing, and visualizing SIEM data with regard to search, observability, and security. Maintain and troubleshoot existing security infrastructure, working closely with server and networking teams to resolve issues and optimize performance. Implement and manage advanced solutions to support and enhance infrastructure management, security operations, and threat intelligence activities, ensuring seamless integration with existing security tools and processes. Provide knowledgeable troubleshooting for Information Security Systems, offering strategic guidance on optimizing and extending functional capabilities to meet evolving operational challenges. Continuously assess and improve existing or future frameworks, staying up to date with the latest security and automation technologies to ensure best practices are applied across all projects. Create, implement, maintain, troubleshoot, and/or utilize advanced scripting (in BASH, Perl, JavaScript, or Python, for example) to automate tasks, enhance system functionalities, and troubleshoot issues. Must also be comfortable performing administration and operations and maintenance tasks from the command line. Maintain detailed documentation for system designs, configurations, processes, and service records. Lead and mentor junior team members in best practices and technical challenges. Ability to participate in a 24/7/365 on-call rotation. Organized, detail-oriented, and excellent problem-solving skills with the ability to work independently or as part of a team. Capability to troubleshoot and resolve LAN/WAN connections, performance/throughput issues, and other related network problems. Strong communication and documentation skills, with the ability to explain complex technical concepts to non-technical stakeholders. Analyzes development and implementation requirements and makes appropriate modifications to existing systems and prepares specifications based on customer requests. Possess knowledge and/or familiarity with security hardening framework standards and regulations from CIS Controls, NIST SP 800-53 Rev. 5, and DISA STIGs. Education & Certifications
Candidate will hold a ComSci/CIS/InfoSec/IT related bachelors degree (or higher) with ~8+ years of Information Security work experience or an equivalent combination of education, certifications, and IT experience. Candidate will hold and maintain a current Information Security certification such as CISSP, CISM, or higher InfoSec related certification (e.g., ISC2 ISSEP). Clearance Requirement
Must be eligible to obtain and maintain a Public Trust (High-Risk, Level 5) clearance.
#J-18808-Ljbffr
cFocus Software is seeking a highly skilled Security Engineer IV (Security Tools and Analytics) to support the Security Tools and Infrastructure Modernization (STIM) contract with the U.S. Department of Health and Human Services (HHS). The Security Engineer IV will provide enterprise-level expertise in deploying, managing, and optimizing security tools and analytics platforms to strengthen cybersecurity operations, monitoring, and compliance. Responsibilities
Deploy, configure, and maintain enterprise security tools such as SIEM, vulnerability management, and IDS/IPS platforms. Perform advanced security analytics and monitoring for threat detection, correlation, and incident response. Integrate security tools into SOC workflows and federal reporting requirements. Support vulnerability scanning, remediation planning, and compliance dashboards. Develop and manage automation/orchestration workflows across security platforms. Provide guidance and mentorship to junior security engineers and analysts. Collaborate with stakeholders to design and implement enterprise security solutions. Ensure compliance with NIST SP 800-53 Rev. 5, CIS Controls, FISMA, and FedRAMP standards. Document technical specifications, SOPs, and security engineering processes. Participate in 24/7/365 operations and on-call rotations as required. Required Experience
10+ years of cybersecurity engineering and operations experience. Extensive expertise with enterprise security tools including SIEM, endpoint protection, and vulnerability management platforms. Proven ability to support incident response and forensic investigations using security analytics. Experience leading enterprise security engineering initiatives in federal environments. Strong communication and documentation skills for reporting and compliance activities. Lead and coordinate initiatives, managing requirements, schedules, and actions to ensure timely and successful project delivery in alignment with organizational objectives. Collaborate with Security, Infrastructure, and Operations teams to develop, implement, and manage automation scripts, enhancing the efficiency and effectiveness of security operations. Candidate will possess knowledge and/or familiarity with Armis and/or Axonius solutions relating to Cyber Asset Attack Surface Management (CAASM) and the Elastic Stack solution for searching, analyzing, and visualizing SIEM data with regard to search, observability, and security. Maintain and troubleshoot existing security infrastructure, working closely with server and networking teams to resolve issues and optimize performance. Implement and manage advanced solutions to support and enhance infrastructure management, security operations, and threat intelligence activities, ensuring seamless integration with existing security tools and processes. Provide knowledgeable troubleshooting for Information Security Systems, offering strategic guidance on optimizing and extending functional capabilities to meet evolving operational challenges. Continuously assess and improve existing or future frameworks, staying up to date with the latest security and automation technologies to ensure best practices are applied across all projects. Create, implement, maintain, troubleshoot, and/or utilize advanced scripting (in BASH, Perl, JavaScript, or Python, for example) to automate tasks, enhance system functionalities, and troubleshoot issues. Must also be comfortable performing administration and operations and maintenance tasks from the command line. Maintain detailed documentation for system designs, configurations, processes, and service records. Lead and mentor junior team members in best practices and technical challenges. Ability to participate in a 24/7/365 on-call rotation. Organized, detail-oriented, and excellent problem-solving skills with the ability to work independently or as part of a team. Capability to troubleshoot and resolve LAN/WAN connections, performance/throughput issues, and other related network problems. Strong communication and documentation skills, with the ability to explain complex technical concepts to non-technical stakeholders. Analyzes development and implementation requirements and makes appropriate modifications to existing systems and prepares specifications based on customer requests. Possess knowledge and/or familiarity with security hardening framework standards and regulations from CIS Controls, NIST SP 800-53 Rev. 5, and DISA STIGs. Education & Certifications
Candidate will hold a ComSci/CIS/InfoSec/IT related bachelors degree (or higher) with ~8+ years of Information Security work experience or an equivalent combination of education, certifications, and IT experience. Candidate will hold and maintain a current Information Security certification such as CISSP, CISM, or higher InfoSec related certification (e.g., ISC2 ISSEP). Clearance Requirement
Must be eligible to obtain and maintain a Public Trust (High-Risk, Level 5) clearance.
#J-18808-Ljbffr