Overview
Skills
Job Details
Job Description:
***Crop to Crop resumes are accepted
Location Requirement: This position requires candidates to be in onsite 5 days a week. Candidates must be LOCAL.
Work involves assisting in supervision and service delivery control of the TxDOT Cybersecurity Operations tools team comprising of seven (8) staff augmentation contractors. Employee will ensure real-time data, metrics, and correlated incident input to the CSOC Incident Response Team. Works under minimal supervision, with extensive latitude for the use of initiative and independent judgment.
Employee will assist in supervising and managing the TxDOT Cybersecurity Operations Tools Team; will work under the management of the TXDOT Cybersecurity Officer; will be responsible for administration, maintenance, and resilience of Cybersecurity tools; real-time data, metrics, and correlated incident input to the CSOC Manager for use in daily monitoring and incident response; and support of daily operations and incident response activities. Employee will provide tooling input for end of month and annual reporting requirements as dictated by TxDOT. As appropriate, Employee will provide recommendations for improvements in daily operations, resilience, and Cybersecurity operational maturity. Employee will be responsible for planning and management of tooling deployment and operating\managing the security tool sets. Employee will be responsible for assisting in managing ongoing agency cybersecurity programs (e.g. Tabletop exercises).
Team members will provide services in the following areas:
- Custom Managed Scanning Services
- Custom Managed Endpoint Protection
- Managed CISCO Secure Network Analytics Service
- Security Information and Event Management (SIEM) administration
Required Skills:
- 8 Technical Team Management experience
- 8 Deployment and configuration of Network Security monitoring and incident response tools (EDR, Scanners, SIEM, Netflow, etc)
- 8 Administration of Network Security monitoring and incident response tools (EDR, Scanners, SIEM, Netflow, etc)
- 8 Participation and experience in intrusion detection and incident response activities
- 8 Effective, professional business communication and reporting
Desired Skills:
- 8 Experience with the CISCO security suite of tools
- 8 Experience with Microsoft EDR tools
- 8 Experience with Microsoft Sentinel
- 8 Experience with the Tenable suite of tools