About this opportunity
FM Talent Source lists this Cloud Network Security Engineer opportunity in bethesda, Maryland. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Overview
Security Engineer role based in Bethesda, MD. The position provides support for cloud architecture, data interoperability, and security engineering for the SCHARE platform and related data environments, including secure cloud configuration, metadata architecture, system integration across platforms, API enablement, and compliance with agency and federal government cybersecurity and information management regulations and requirements. The role also supports ATO-related activities in coordination with the agency CIO organization, including preparation of technical artifacts, remediation support, and implementation and maintenance of technical controls, vulnerability remediation, and securing data environments to ensure ongoing compliance.
Responsibilities
Create network traffic rules in Azure
Create network routing maps
Maintain documentation of subnets (13+), VLANs, and VoIP
Manage SSL certificate requests
Run PowerShell reports on Active Directory objects
Process DNS requests for public websites and IT resources (IPAM, Infoblox)
Interface with external IT service providers regarding networking change requests from lab staff
Test data transfer rates and channel bandwidth between buildings
Gather data storage requirements from lab staff for implementation into the existing IT data storage architecture
Perform analysis, diagnosis, and troubleshooting of complex system security issues
Recommend, design, develop, test, configure, and implement a broad array of system security solutions
Inform and escalate security risk problems, such as high/critical vulnerabilities and risk acceptance methods
Support a federal healthcare enterprise environment by collaborating with and providing support to other IT Operational Service Areas (Server/Storage, Network, Service Desk, Application Development) in the design, development, and testing of solutions, as well as diagnosing, troubleshooting, and remediation of issues
Draft and maintain technical design and Standard Operating Procedure (SOP) documents
Document work performed in issue tracking system
Provide recommendations for mitigations or corrective actions to resolve identified vulnerabilities or security concerns, and take corrective actions at the direction of the customer
Qualifications
Bachelor’s degree in computer science, engineering, or a related field or an equivalent combination of education and experience and appropriate technical certifications, with at least twelve (12) years of experience in information technology and four (4) years leading or performing systems engineering or related functions.
Strong written and verbal technical communication skills, excellent organization and time management, and the ability to handle multiple competing priorities.
Experience supporting, designing, configuring, implementing and/or administering at least three (3) of the following:
Antivirus and malware protection solutions
Privileged access management solutions
Security Information and Event Management (SIEM) solutions
Automation of log collection
Analysis of log data
Development of monitors and alerts based on security and operational requirements
Vulnerability analysis and remediation solutions
Active Directory Group Policy
Disk Encryption technologies and solutions
Experience managing private networks within Azure
Comprehensive RBAC and EntraID knowledge
Able to work with vendors to evaluate, procure, implement, and maintain SaaS tools
Able to work within a ticketing system (Snow) to process various engineering related requests
Basic understanding of SQL, database, and web-app resources
Exposure to and experience managing resources within Azure and AWS
Experience managing SaaS/PaaS tiered storage tools
Experience with Kubernetes, Docker, or other containerization tools
Experience with endpoint management tools such as Intune/Ivanti/PDQ/Jamf
Experience with Cisco ISE (NAC), Infoblox (IPAM), and AWS (archival storage)
Ability to quickly learn new tools and approaches
Ability to adapt to rapidly changing requirements with a flexible and creative engineering-focused approach to brainstorming, troubleshooting, and problem-solving
Must be able to obtain a Public Trust clearance
Preferred Certifications
One or more certifications from (ISC)², CompTIA, SANS, or other well-recognized certifying body:
(ISC)² CISSP
CompTIA CASP+
Microsoft Certified Solutions Expert (current or current version)
Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status or other characteristics protected by law.
#J-18808-Ljbffr
Worksite address
bethesda, MD, 20811, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.