2 open positions available
Conduct technical security assessments, audits, penetration testing, manage incident response, enforce security policies, and monitor logs for threats. | Minimum three years of security engineering experience, bachelor's degree, proficiency in SIEM, penetration testing, and network security. | Security Engineer - Middle will conduct technical security assessments, audits, penetration testing, and forensic IT functions of client/server systems (native and virtual), databases, networks, and vehicle/appliance technology systems. In-depth experience configuring and managing one or more SIEM tools. Be able to identify current security infrastructure and define future programs, design and implementation of security related to IT systems. Must have a minimum of three (3) years of proven information systems security engineering experience. At minimum, an in-depth knowledge and management of one or more Security Incident and Event Management (SIEM) tools is required. Additionally, the Security Engineer - Middle shall possess hands-on experience in penetration testing and router/firewall management. This role requires one day onsite in Arlington, VA. Technical Skills: In-depth, hands-on configuration and management of one or more SIEM tools. Log collection, aggregation, normalization, and correlation from diverse sources (e.g., servers, network devices, and applications). Event monitoring, analysis, and reporting. Experience with conducting penetration testing and technical security assessments. Vulnerability and patch management. Automated and manual security testing techniques. Router and firewall management, including installation, configuration, and troubleshooting. Intrusion detection and prevention systems (IDS/IPS). Operating system security, including experience with Windows and Linux environments. Securing virtualized client/server systems. Database security. Coordinating and managing security incident response efforts. Forensic IT functions to investigate security breaches and determine root cause. Log analysis for security incidents. Defining, reviewing, and enforcing information security policies, standards, and guidelines. Ensuring compliance with relevant regulatory requirements. Knowledge of current security trends and threats. Researching new attack vectors. Thinking like a hacker to anticipate vulnerabilities. Familiarity with scripting languages (e.g., Python, Bash) for automating security tasks and managing systems. Experience with security automation frameworks. Responsibilities: Define, review, and enforce information security policy, standards and guidelines for business operations and technology implementations. Proactively speculate and identify IT security risks from technical and functional perspectives. Conduct technical security assessments as part of the enterprise vulnerability and patch management program. Conduct as needed technical security assessments, audits, penetration testing, and forensic IT functions of USMS client/server systems (native and virtual), databases, networks, and vehicle/appliance technology systems. Coordinate and conduct event collection, log management, event management, compliance automation, and identity monitoring activities for the USMS enterprise. Analyze data collected by the event monitoring system(s), identifying results that dictate immediate corrective action, trends that drive prompt action and areas that require continued monitoring and/or further analysis. Maintain awareness of current security trends and threats, respond to reported incidents to conclusion, and provide awareness to system users. Coordinate IT security matters such as incident response, intrusion detection management, and customer security advisories. Requirements: Required Education BS/BA in Computer Science, Information Systems, Engineering, Business, Physical Science, or other technology-related discipline. Required Skills • In-depth, hands-on configuration and management of one or more SIEM tools. • Log collection, aggregation, normalization, and correlation from diverse sources (e.g., servers, network devices, and applications). • Event monitoring, analysis, and reporting. • Experience with conducting penetration testing and technical security assessments. • Vulnerability and patch management. • Automated and manual security testing techniques. • Router and firewall management, including installation, configuration, and troubleshooting. • Intrusion detection and prevention systems (IDS/IPS). • Operating system security, including experience with Windows and Linux environments. • Securing virtualized client/server systems. • Database security. • Coordinating and managing security incident response efforts. • Forensic IT functions to investigate security breaches and determine root cause. • Log analysis for security incidents. • Defining, reviewing, and enforcing information security policies, standards, and guidelines. • Ensuring compliance with relevant regulatory requirements. • Knowledge of current security trends and threats. • Researching new attack vectors. • Thinking like a hacker to anticipate vulnerabilities. • Familiarity with scripting languages (e.g., Python, Bash) for automating security tasks and managing systems. • Experience with security automation frameworks.
Lead and coordinate cybersecurity incident response operations, managing technical teams and executive communications during major incidents. | Extensive experience in cybersecurity incident response leadership, crisis management, forensic coordination, and executive stakeholder communication. | What you'll do • The Incident Commander serves as the senior operational leader during cybersecurity incidents and is responsible for directing, coordinating, and managing all response activities throughout the incident lifecycle. This position acts as the central decision-maker during major cyber events, ensuring that technical teams, business stakeholders, executive leadership, and external partners operate in a coordinated and effective manner. • The Incident Commander leads incident response efforts involving ransomware, data breaches, cloud compromises, insider threats, business email compromise, advanced persistent threats, and other high-impact security incidents. The role is responsible for establishing response priorities, coordinating technical investigations, managing escalation activities, directing containment and recovery actions, and ensuring timely communication with executive leadership and stakeholders. • The Incident Commander serves as the bridge between technical teams and organizational leadership by translating complex technical findings into actionable business information. The position oversees incident status reporting, executive briefings, operational decision-making, forensic coordination, threat intelligence integration, and post-incident reviews. The Incident Commander is ultimately accountable for ensuring incidents are managed efficiently, risks are minimized, and business operations are restored as quickly and safely as possible. Qualifications • Candidates must possess extensive experience leading cybersecurity incident response operations within enterprise, government, defense, critical infrastructure, or managed security service environments. The successful candidate should demonstrate strong expertise in incident response, crisis management, cyber defense operations, threat intelligence, digital forensics coordination, and executive communications. • The candidate must have experience managing complex security incidents involving multiple teams, technologies, stakeholders, and business units. Strong knowledge of incident handling methodologies, cyber attack lifecycles, ransomware response, breach management, cloud security incidents, and enterprise security operations is required. Experience coordinating technical teams during high-pressure situations while maintaining operational awareness and decision-making discipline is essential. • The position requires exceptional leadership, communication, and organizational skills. Candidates must be capable of delivering executive briefings, managing stakeholder expectations, facilitating crisis communications, and translating technical information into business-focused recommendations. Experience coordinating forensic investigations, threat intelligence activities, legal considerations, regulatory reporting, and recovery operations is highly desirable. • Preferred certifications include CISSP, GCIH, GCFA, CISM, CASP+, PMP, ITIL, or equivalent industry-recognized certifications. Equivalent experience leading major cybersecurity incidents, crisis response operations, or cyber defense missions may be considered in lieu of specific certifications. Core Skills ● Incident Response Leadership ● Crisis Management ● Executive Briefings and Communications ● Threat Intelligence Integration ● Digital Forensics Coordination ● Major Incident Management ● Cybersecurity Operations ● Risk Assessment and Decision Making ● Stakeholder Management ● Recovery and Business Continuity Coordination ● Regulatory and Reporting Awareness ● Cross-Functional Team Leadership
Create tailored applications specifically for Saliense with our AI-powered resume builder
Get Started for Free