We''re seeking a Cybersecurity Security Engineer with the following certifications:
Cybersecurity Certifications: At least one of the following: CISSP, CCSP, CCNA,CISSP-ISSAP,CISSP-ISSEP, GIAC, SSCP, Security+ (or equivalent as approved by the Government)
• Experience with developing/integrating cybersecurity designs for systems and networks
• Experience implementing Zero Trust Architecture (ZTA) principles
• Experience developing and producing strategic technology roadmaps aligned with mission requirements.
• Experience conducting market research analysis on new cybersecurity tool technologies.
• Experience performing technical evaluations and Proof of Concepts for cybersecurity objectives.
• Experience with documenting and addressing organizational information security, cybersecurity architecture, and systems security engineering requirements
• Experience with developing system security context, a preliminary system security CONOPS, and define baseline system security requirements in accordance with applicable cybersecurity requirements
• Experience documenting the protection needs (i.e. security controls) for information system(s) and network(s)
• Ability to perform security reviews, identify gaps in security architecture, and develop a security risk management plan
• Ability to develop a system security context, a preliminary system security CONOPS, and define baseline system security requirements in accordance with applicable cybersecurity requirements
• Experience with securing at least one of the following Cloud Service Provider (CSP) types: Infrastructure as a Service (IaaS), Software as a Service (SaaS), and Platform as a Service (PaaS)
• Experience or knowledge of integrating cybersecurity principles with Artificial Intelligence (AI) or GenerativeAI (GenAI).
• Experience providing support for the integration of security into the DevSecOps pipeline activities
• Experience with vulnerability scanning tools to include those supporting operation system, web application, database assessments,
• Skill in translating operational requirements into protection needs (i.e. security controls)
• Work experience or knowledge with architecting, engineering, deploying, and tuning of Network Detection and Response (NDR) platforms.
• Experience or knowledge of network modeling and behavior technology solutions.
• Experience or working knowledge of Cyber Threat Intelligence (CTI) technologies
• Experience or knowledge of Security Orchestration, Automation, and Response (SOAR) solutions
• Work experience or knowledge of Security Information & Event Management (SIEM)
• Mobile security engineering knowledge or experience to include at least one of the following:
~ Mobile Threat Detection (MTD)
~ Mobile Device Management (MDM) security controls
~ Mobile Application Management (MAM) security controls.
• Work experience or knowledge of providing technical security engineering support for secure authentication.
• Work experience or knowledge integrating of secure authentication / Single SignOn (SSO)
• Work experience or knowledge of Post Quantum Cryptography (PQC) concepts and technology, which may include any of the following:
~ Extensive experience with certificate lifecycle management, cryptographic algorithms (RSA, ECC, AES), digital signatures, and cryptographic principles, including emerging post-quantum encryption standards (e.g., NIST PQC algorithms).
~ Experience using tools and technologies to enable discovery of cryptographic assets across enterprise networks using network and infrastructure telemetry data.
~ Experience with requirements gathering to prototype, develop, validate, and build systems to support quantum-ready encryption.
~ Experience implementing technologies and associated roadmaps to create new telemetry for cryptographic inventorying.
~ Experience designing, implementing, and evaluating PQC-enabled network protocols for different layers of the OSI model, e.g., PQC-enabled TLS.
~Solid understanding of various protocols like TLS, X.509, BGP, DHCP, IPsec, DNSsec, etc.
• At least 2 years of experience working with network packet capture tools like WireShark, tcpdump, nmap, or similar.
• Proven experience scripting and automating administrative functions (PowerShell, Python).