Logo
ZipRecruiter

Senior Security Operations Engineer

ZipRecruiter, Richmond, Virginia, United States, 23214

Save Job

Overview

Senior Security Operations Engineer

– onsite position. *This is an onsite position Description: The client is seeking an experienced Senior Security Operations Engineer with in-depth knowledge and hands on experience in security policy, intrusion detection/prevention systems, perimeter security technology and information security. The client is seeking an experienced Senior Security Operations Engineer with in-depth knowledge and hands on experience in information systems security, security policy, intrusion detection/prevention systems, firewalls, antivirus software, anti-malware, anti-phishing, authentication systems, log analysis, and management of web content filtering, network protocols and security/authentication protocols at all layers of the OSI model with emphasis on TCP/IP, web security gateways, network access control, endpoint security and perimeter security technologies. The Senior Security Operations Engineer contributes to the overall technology roadmap.

Responsibilities

Participates in the design, implementation and support of security infrastructure for the Department. Identifies network and information security risks across the enterprise; designs, engineers and implements security solutions to address the risks at an enterprise level. Works closely with the IT Division and outside vendors to design, plan, deploy, secure and update network projects in the environment. Collaborates with the Office of Information Security (OIS) and other ITD groups. Completes Strategic Plan items pertinent to the Network Security Operations group. Creates, documents and maintains system policies and procedures. Performs network scans and penetration testing. Monitors log analysis and management tools for threats. Evaluates vulnerability scan results and notifies business, application and infrastructure teams of vulnerabilities needing remediation. Evaluates and participates in agency Azure cloud solutions review of network security and general project involvement. Ensures daily functions to maintain security of applicable systems and applications are documented. Works with the agency’s ISO team and IT Auditors to review security audit findings and vulnerability scan results. Identifies recommended corrective actions and communicates with stakeholders. Device configurations are based on best practices. Keeps relevant documentation up to date. Coordinates the handling and resolution of incidents related to security.

Required Skills/Knowledge/Experience

Considerable knowledge and hands-on experience in information systems security and security policy; typically requires 7+ years. Considerable knowledge and hands-on experience with web security gateways, network access control, endpoint security, and perimeter security technologies; typically requires 7+ years. Considerable knowledge and hands-on experience with firewalls, antivirus software, anti-malware, anti-phishing, authentication systems; typically requires 7+ years. Considerable knowledge and hands-on experience with intrusion detection/prevention systems, log analysis and management, web content filtering; typically requires 7+ years. Considerable knowledge and hands-on experience with network protocols and security/authentication protocols at all OSI layers with emphasis on TCP/IP; typically requires 7+ years. Demonstrated ability to identify security risks across the enterprise and perform day-to-day operations; typically requires 7+ years. Demonstrated ability to administer and protect the integrity, confidentiality, and availability of information assets and technology infrastructure; typically requires 7+ years. Considerable knowledge and hands-on experience detecting, responding, and remediating security incidents; typically requires 7+ years. Considerable knowledge and hands-on experience remediating System Security Plans (SSP) and Risk Assessments (RA) in cybersecurity; typically requires 7+ years. Solid experience with performing threat, vulnerability, risk assessments and coordinating the resolution of incidents related to security breaches; typically requires 7+ years. Considerable knowledge and hands-on experience with web-related technologies and penetration testing tools; typically requires 7+ years. CISSP, highly desired.

#J-18808-Ljbffr