Please note that this position is with our direct client
We are looking for ecurity Architect - Consultant (Min 8+yrs Exp) REMOTE (Webcam or In Person Interview)
Number of positions: 1
Length: 12Months +
Work Address: South Carolina Columbia 29201
Immediate Interviews Webcam or In Person Interview
looking for a Security Architect Consultant
Work Location: Fully Remote.
Candidate Location: No South Carolina residency required. Open to nationwide candidates; must be able to work eastern time zone hours. All travel-related costs for onsite work will be the responsibility of the resource, regardless of the frequency of onsite work.
Position Title: Security Architect-Consultan
Project Overview
New engineering role directly supporting cybersecurity automations, security tool development, IAM, enterprise security platforms and security operations.
Daily Duties / Responsibilities:
THIS POSITION IS 100% REMOTE AND WILL PARTICIPATE IN AN ON-CALL ROTATION
SUPPORTING A 24X7 SECURITY OPERATIONS CENTER SERVING MULTIPLE STATE
AGENCIES. OTHER AFTER-HOURS WORK MAY BE REQUIRED AS NEEDED.
PRIMARY RESPONSIBILITIES:
-
PRIMARILY ASSIST IN PLANNING, DESIGN, DEVELOPMENT, DEPLOYMENT,
-
ADMINISTRATION AND OPERATIONAL SUPPORT OF ENTERPRISE SECURITYAUTOMATION AND CUSTOM SECURITY TOOLS, INCLUDING:
-
PYTHON-BASED AUTOMATIONS, INTERNAL WEB APPLICATIONS, APIS, SDKS, SCRIPTS,
-
DASHBOARDS, COMMAND-LINE UTILITIES AND SYSTEM INTEGRATIONS
-
AUTOMATED WORKFLOWS FOR ALERT ENRICHMENT, TRIAGE, INCIDENT RESPONSE,CASE MANAGEMENT, NOTIFICATIONS, CONTAINMENT, ESCALATION AND REPORTINGCUSTOM TOOLS TO ASSIST WITH CVE VETTING, VULNERABILITY ENRICHMENT,PRIORITIZATION, TRACKING AND SECURITY DECISION SUPPORT
SECONDARY RESPONSIBILITIES:
-- SECONDARILY ASSIST IN THE PLANNING, DESIGN, DEPLOYMENT AND OPERATIONAL SUPPORT OF A BROAD RANGE OF SECURITY PLATFORMS, INCLUDING: DSPM, ASM, IAM, VULNERABILITY MANAGEMENT, EMAIL SECURITY, ENDPOINT SECURITY, SIEM, XDR, SOAR, LOGGING, MONITORING, NETWORK SECURITY, CLOUD SECURITY AND THREAT INTELLIGENCE TECHNOLOGIES INTEGRATIONS WITH TICKETING, CASE MANAGEMENT, NOTIFICATION, IDENTITY, DATA SOURCES, APIS, SDKS AND OTHER ENTERPRISE SYSTEMS AS NEEDED SUPPORT FOR TECHNOLOGIES SUCH AS PALO ALTO NETWORKS, PROOFPOINT, TENABLE, CRIBL, WHATSUP GOLD AND OTHER CURRENT OR FUTURE SECURITY PRODUCTS
-- DEVELOP, TEST, DEPLOY AND MAINTAIN AUTOMATED SECURITY WORKFLOWS,
APPLICATIONS AND SCRIPTS USING PYTHON, POWERSHELL, BASH, REST APIS, JSON,
YAML, VENDOR SDKS AND OTHER APPROPRIATE TECHNOLOGIES.
-- ASSIST WITH IDENTITY AND ACCESS MANAGEMENT FUNCTIONS, INCLUDING USERPROVISIONING, DEPROVISIONING, ACCESS REVIEWS, ROLE-BASED ACCESS CONTROL, SERVICE ACCOUNTS, API CREDENTIALS, AUTHENTICATION, AUTHORIZATION AND IDENTITY-BASED SYSTEM INTEGRATIONS.
-- DEPLOY, CONFIGURE, PATCH, MONITOR, OPTIMIZE AND TROUBLESHOOT LINUX
SYSTEMS SUPPORTING SECURITY SENSORS, COLLECTORS, CONNECTORS,
APPLICATIONS, CONTAINERS AND DATA-PROCESSING SERVICES, INCLUDING DOCKER- BASED ENVIRONMENTS.
-- SUPPORT SECURITY ARCHITECTS, ENGINEERS, SOC ANALYSTS, INCIDENT
RESPONDERS AND AGENCY CUSTOMERS THROUGH PLATFORM TROUBLESHOOTING,
AUTOMATION DEVELOPMENT, SYSTEM INTEGRATION, TECHNICAL ESCALATION,
KNOWLEDGE TRANSFER AND OPERATIONAL HANDOFFS.
-- MONITOR AND REPORT ON AUTOMATION HEALTH, APPLICATION AVAILABILITY,
SYSTEM PERFORMANCE, SENSOR STATUS, INTEGRATION FAILURES, API ERRORS,
VULNERABILITY STATUS, PLATFORM ISSUES AND OTHER SECURITY ENGINEERING AND OPERATIONAL METRICS.
-- ENSURE HIGH AVAILABILITY, RESILIENCE, BACKUP, RECOVERY, PATCHING, LIFECYCLE
MANAGEMENT, SECURE CONFIGURATION AND CONTROLLED CHANGE PROCESSES
FOR SECURITY TOOLS, LINUX SYSTEMS, APPLICATIONS, AUTOMATIONS AND
SUPPORTING SERVICES.
-- COLLABORATE WITH SECURITY ARCHITECTS, ENGINEERS, ANALYSTS, INCIDENT
RESPONDERS AND AGENCY STAKEHOLDERS TO ALIGN SOLUTIONS WITH BUSINESS
GOALS, INDUSTRY-STANDARD FRAMEWORKS, REGULATORY REQUIREMENTS AND
ORGANIZATIONAL RISK TOLERANCE
Required Skills (Ranked by Importance):
-- BROAD HANDS-ON SECURITY ENGINEERING EXPERIENCE SUPPORTING MULTIPLE
CYBERSECURITY TECHNOLOGIES, SYSTEMS, INTEGRATIONS AND OPERATIONAL FUNCTIONS.
-- Experience developing security automations, scripts, integrations, utilities and custom tools using Python.
-- Strong experience troubleshooting complex technical issues across applications, security platforms, operating systems, networks, identity services and integrations.
-- LINUX SYSTEM DEPLOYMENT, CONFIGURATION, PATCHING, SCRIPTING, SERVICE MANAGEMENT, MONITORING, TROUBLESHOOTING AND LIFECYCLE MANAGEMENT
-- Experience developing automation and response workflows using Python, PowerShell, Bash, REST APIs, JSON, YAML and vendor SDKs.
-- Experience supporting IAM, DSPM, ASM, vulnerability management, email security,
Endpoint security, SIEM, SOAR, logging, monitoring, cloud security and other enterprise security technologies.
-- Strong understanding of enterprise security architecture, incident response,
networking, access control, secure software development, systems administration and industry-standard cybersecurity frameworks.
Preferred Skills (Rank in order of Importance )
-- HANDS-ON EXPERIENCE SERVING AS A SECURITY ENGINEERING GENERALIST IN A
LARGE, MULTI-TENANT, SHARED- SERVICES OR MANAGED-SERVICE ENVIRONMENT.
-- Hands-on Linux, Docker, security sensor, monitoring, scripting and platform administration
experience.
-- Experience supporting SOC analysts, security engineers, incident responders, agency customers and rapidly changing operational priorities.
-- Familiarity with Palo Alto Networks, Proofpoint, Tenable, Cribl, WUG or other enterprise
security technologies and experience developing playbooks, runbooks, procedures and
technical documentation
Required Education:
-- BACHELOR'S DEGREE IN AN INFORMATION TECHNOLOGY, COMPUTER SCIENCE, SOFTWARE ENGINEERING OR INFORMATION SECURITY RELATED FIELD
-- EIGHT YEARS OF RELEVANT WORK EXPERIENCE (EXPERIENCE MAY BE SUBSTITUTED IN LIEU OF EDUCATION)
-- FIVE YEARS OF EXPERIENCE IN SUPPORTING LARGE IT ENVIRONMENTS, SECURITY SYSTEMS, SOFTWARE DEVELOPMENT AND/OR SYSTEM DEPLOYMENTS
Preferred Certifications:
CISSP, Security+, GIAC OR OTHER
RELEVANT CYBERSECURITY CERTIFICATION
LINUX, PYTHON, CLOUD, IAM OR OTHER RELEVANT SECURITY ENGINEERING OR PLATFORM CERTIFICATION
Additional Skills/Duties:
-- Experience integrating enterprise technologies using APIs, SDKs, web services, structured data formats, authentication methods and vendor-supported interfaces.
--Experience developing or supporting internal web applications, APIs, dashboards, databases, command-line tools and related software components
-- Advanced Python development experience and familiarity with full-stack development, internal web applications, APIs, databases, source control, testing and software deployment practices.
THIS POSITION IS HOUSED 100% REMOTE AND WILL PARTICIPATE IN A MONTHLY ON-CALL ROTATION SUPPORTING THE 24X7 SOC. AFTER-HOURS MAINTENANCE, INCIDENT ESCALATION SUPPORT AND OPERATIONAL HANDOFFS MAY BE REQUIRED AS NEEDED. ALL WORK MUST BE PERFORMED WITHIN THE CONTIGUOUS UNITED STATES. PREFERENCE WILL BE GIVEN TO LOCAL SOUTH CAROLINA BASED CANDIDATES CAPABLE OF FIELDING SERVICE
Candidates must have ALL the "Required" skills in order to be considered for the position. "Desired" or "Highly Desired" skills are a PLUS but may NOT be required.
Skill Matrix
| Experience with Business workflow processes | Required / Desired | Amount of Experience | Years of Expe Years rience |
| Bachelors Degree in an Information Technology, Computer Science, Software Engineering or Information Security related field; 8+ years of relevant experience may be substituted in lieu of education | Required | 8 | Years |
| 5+ years of experience in supporting large IT environments, security systems, software development, and/or system deployments | Required | 5 | Years |
| Hands-on security engineering experience supporting multiple cybersecurity technologies, systems, integrations, and operational functions. | Required | | |
| Experience developing security automations, scripts, integrations, utilities and custom tools using Python | Required | | |
| Strong experience troubleshooting complex technical issues across applications, security platforms, operating systems, networks, identity services and integrations | Required | | |
| Linux system deployment, configuration, patching, scripting, service management, monitoring, troubleshooting and lifecycle management | Required | | |
| Experience developing automation and response workflows using Python, PowerShell, Bash, REST APIs, JSON, YAML and vendor SDKs | Required | | |
| Experience supporting IAM, DSPM, ASM, vulnerability management, email security, endpoint security, SIEM, SOAR, logging, monitoring, cloud security and other enterprise security technologies | Required | | |
| Strong understanding of enterprise security architecture, incident response, networking, access control, secure software development, systems administration and industry-standard cybersecurity frameworks | Required | | |
| CISSP, Security+, GIAC or other relevant cybersecurity certification | Preferred | | |
| Linux, Python, Cloud, IAM or other relevant security engineering or platform certification | Preferred | | |
| Hands-on experience serving as a security engineering generalist in a large, multi-tenant, shared services, or managed service environment | Preferred | | |
| Hands-on Linux, Docker, security sensor, monitoring, scripting and platform administration experience | Preferred | | |
| Experience supporting SOC analysts, security engineers, incident responders, agency customers and rapidly changing operational priorities. | Preferred | | |
| Familiarity with Palo Alto Networks, Proofpoint, Tenable, Cribl, WUG or other enterprise security technologies and experience developing playbooks, runbooks, procedures and technical documentation | Preferred | | |