Overview
Skills
Job Details
Hi
Position : Security Analyst with DevSecOps Automation
Location : Columbia, SC
Position id : 8390
Client : State of SC
Key duties and Responsibilities
Champion DevSecOps through Security Automation: Leverage your full-stack development expertise to design, implement, and maintain security tools and automation. This includes building scripts to automate critical tasks like data security checks, vulnerability scanning, and user access control, streamlining security processes and improving overall efficiency.
Monitor and analyze security events: You'll be responsible for monitoring security information and event management (SIEM) tools to identify potential threats and suspicious activity. Along with determine security gaps in these controls to improve overall security posture. This will also involve analyzing logs, investigating alerts, and using your knowledge of security frameworks (NIST, CIS, CISA) to assess risk.
Support secure application development: You'll collaborate with developers to ensure secure coding practices are followed throughout the Software Development Lifecycle (SDLC). This might involve code reviews, threat modeling, and providing guidance on secure development principles.
Investigate and respond to security incidents: In the event of a security breach, you'll be part of the incident response team, helping to identify the root cause, mitigate damage, and implement recovery procedures.
Document security procedures and best practices: You'll develop clear and concise documentation for security policies, procedures, and best practices. This may involve creating training materials or user guides to ensure everyone understands their role in maintaining security.
Provide on-call support when needed and other related duties as required.
Required Skills
5 years of Expert level experience with C#, Python, Powershell, or Rust
1 year of Understanding of automation principles, including the use of AI, ML, and scripting, to streamline security tasks
3 years of Understanding of the Software Development Lifecycle (SDLC) and DevSecOps principles to integrate security considerations throughout the application development process.
3 years of Proficiency in CLOUD SECURITY principles, including identity and access management, data security, and compliance.
Education Requirement
A bachelor's degree in information technology systems, computer science, cybersecurity, or a related field. Relevant experience may be substituted for the degree on a year-for-year basis
Preferred Skills
1 Year of Experience with SIEM (Security Information and Event Management) tools, including configuration, tuning, threat hunting, and alert creation.
1 Year of In-depth knowledge of security frameworks, including NIST, CIS, and CISA, and their application in a hybrid environment.
1 Year of Expertise in data classification and DLP (Data Loss Prevention) configuration to safeguard sensitive information.
Required Skills
Skill Type
Skill Name
5 years of Expert level experience with C#, Python, Powershell, or Rust
1 year of Understanding of automation principles, including the use of AI, ML, and scripting, to streamline security tasks
3 years of Understanding of the Software Development Lifecycle (SDLC) and DevSecOps principles to integrate security considerations throughout the application development process.
3 years of Proficiency in CLOUD SECURITY principles, including identity and access management, data security, and compliance.
Preferred Skills
Skill Type
Skill Name
1 Year of Experience with SIEM (Security Information and Event Management) tools, including configuration, tuning, threat hunting, and alert creation.
1 Year of In-depth knowledge of security frameworks, including NIST, CIS, and CISA, and their application in a hybrid environment.
1 Year of Expertise in data classification and DLP (Data Loss Prevention) configuration to safeguard sensitive information.
Attachment:
Statement of Work (SOW) for Contingent Labor Request
Primary Work Location: | ||||||
# of Openings: | ||||||
Company / Department culture (why do you enjoy working for the company selling points for potential candidates): | ||||||
Why is this position open (new role, increased workload, new dept, resignation, promotion)? This is a ReBid. | ||||||
What types of staffing challenges or headaches have you experienced in the past?
Resume needs to be specific and describe, not just list, candidate's experience with the relevant technologies in a professional capacity. Non-professional experience may be referenced but will not be highly regarded.
Candidate must demonstrate positive attitude and be able to work with a diverse team of varying skill levels contributing Constructive ideas and criticism. Excellent communication skills are required. | ||||||
Scope of the project: | ||||||
Position: | Open to visa transfer? Yes x No | |||||
Start Date: | Duration: | Possibility of Extension? | ||||
Bill Rate: 93.00 | Public sector/gov't experience required? | Remote work possibility? | ||||
Pre-employment Checks (drug, credit, criminal, motor vehicle)? | ||||||
| ||||||
Required Skills (rank in order of importance):
| Preferred Skills (rank in order of importance):
| |||||
Required Education: | Preferred Certifications: | |||||