Job Title -Cyber Security Architect (Network)
Location- Remote | West Coast preferred (Remote Occasional travel to Arizona)
Duration- 6+ months
Visa-and GC
Interview-Virtual
Availability to interview candidate: Friday afternoon
🔐 Palo Alto, Cisco/Meraki, Splunk, Cloudflare, Defender, Azure AD⚓ Maritime exp. + TWIC preferred | 🎓 SSCP required
Cyber Security Architect (Network) • Experience working in the maritime industry- was a nice to have before, now they need/ want it. • Have a Transportation Worker Identification Credential (TWIC). ( Client stated that not having one will be a long process to obtain one. They don't want to wait) Additionally, they prefer someone who is in the West Coast area over East Coast. Reason being they want someone closer to Arizona or neighboring states, so in the event that there was an incident or an all hands-on deck scenario, that could easily get on a plane and be in AZ in a couple to a few hours. They noted this feedback after a Cyber Arch based in Philadelphia interviewed. “ Cyber Security Architect (Network Remote Occasional travel to Arizona. They will cover expense. Architecting a cyber system for a maritime system Tech stack Domain Firewall / network Switching / wireless Edge / web SIEM Tool Palo Alto Networks Cisco + Meraki Cloudflare Splunk (onprem) Notes Approximately 30 firewalls; primary/secondary HA pair per site. Security controls being enabled now. Being replaced. Storage-constrained; needs hot/cold tiering and a six-month cold archive. POC underway with Google SecOps and a second candidate (recorded as "Mazah" — VERIFY name). Endpoint / EDR Email security Penetration testing DLP PAM / secrets Identity Other Job Overview · Microsoft Defender Abnormal AI NodeZero Varonis Delinea Secret Server (Thycotic) Azure hybrid AD, MFA M365, OpenAI Codex Enterprise Not Defender for Identity. Defender for Vulnerability Management in use — Horizon3 findings to be correlated against it. With M365; tied to IdP and MFA. Autonomous pen testing already licensed. Data-protection setup review is an open action. Policies tightening; existing open permissions will be restricted. Roughly 24–25 standard apps/services. As a cyber security architect, you will help the Information Technology Team take our current cyber security program to the next level. You will work closely with various teams within the IT group and across our organization to ensure we are remaining proactive and ensuring our software and systems are designed and implemented following best security practices. You will also be responsible for maintaining operational effectiveness of our terminal by mitigating risk all while increasing our security posture and protecting a part of the nation’s critical infrastructure. · The primary purpose of this position is to provide the maintenance, upkeep and provide front line support of our cyber-security program. How You Will Make An Impact • Measure and analyze cyber security posture across the organization and recommend improvements and solutions to current cyber security issues and risks • Stays up to date on current threats, vulnerabilities, attacks, and countermeasures – maintains our CVE remediation program • Enhances security team accomplishments and competencies by planning the delivery of solutions and answering technical questions. • Plans, researches, and designs security architecture for IT systems. • Develops, reviews, and approves installation requirements for LANs, WANs, VPNs, firewalls, routers, and related network devices. • Determines security protocols by evaluating business strategies and requirements. • Responds to, and investigates, security incidents and provides thorough postevent analyses. • Develops project timelines for ongoing system upgrades. • Reviews system security measures and implements necessary enhancements. • Conducts regular tests and monitoring of network security. • Verifies security systems by developing and implementing test scripts. • Updates job knowledge by tracking and understanding emerging security practices and standards, participating in educational opportunities, reading professional publications, and participating in professional organizations. What You Will Need To Succeed • Strong working knowledge of IT risks, cyber security, and computer operating software • Advanced understanding of security protocols, cryptography, and security • Experience implementing multi-factor authentication • Great communication and interpersonal skills • Experience implementing security solutions • Comfortable working within a team • Experience and knowledge of DevOps tools (Git, Jenkins, Docker, etc.), including familiarity with scripting • Experience with virtualization, required • CISSP or similar certification, preferred, SSCP required • Experience designing secure networks, systems, and application architectures, preferred • Experience planning, researching, and developing security policies, standards, and procedures, preferred • Must be able to obtain a valid Transportation Worker Identification Credential (TWIC). • Familiarity with ITIL processes (ITIL Certification preferred) • Good communication & “people skills” Preferred Qualifications • Bachelor of Administration or Bachelor of Science degree Computer Science, Engineering, Information Systems, or equivalent experience • Minimum 5 years in Information Technology including at least 3-5 years' experience in an Information Security Engineering or similar capacity