6 open positions available
Advise executive leadership on cybersecurity governance, risk, and compliance strategies aligned with federal mandates. | Requires 5+ years federal cybersecurity governance experience, advising CISOs and senior executives, with knowledge of federal cybersecurity frameworks and policies. | Job Title: Cybersecurity Strategy & Compliance Advisor $145,000-$150,000 Position Summary The Cybersecurity Strategy & Compliance Advisor serves as a trusted advisor to executive leadership, supporting the development, implementation, and maturation of enterprise cybersecurity governance, risk management, and compliance (GRC) programs. This role provides strategic guidance on federal cybersecurity policies, emerging regulations, executive directives, and security frameworks while ensuring alignment between cybersecurity initiatives and organizational business objectives. The ideal candidate possesses extensive experience advising Chief Information Security Officers (CISOs) and senior executives, interpreting Executive Orders and federal cybersecurity mandates, and translating complex regulatory requirements into practical governance, security, and compliance strategies. This individual will play a key role in advancing Zero Trust initiatives, continuous monitoring capabilities, AI governance, and enterprise risk management across the organization. Key Responsibilities Cybersecurity Strategy & Governance • Advise executive leadership and cybersecurity management on enterprise security strategy, governance, and risk management initiatives. • Align cybersecurity programs with organizational mission objectives, business priorities, and operational requirements. • Support the maturation of cybersecurity governance programs, policies, standards, and procedures. • Provide strategic guidance to Cybersecurity Strategy Center initiatives and cross-functional governance activities. • Develop executive-level briefings, strategic recommendations, and cybersecurity roadmaps. Governance, Risk & Compliance (GRC) • Lead and support Governance, Risk, and Compliance (GRC) activities across the enterprise. • Develop, review, and maintain cybersecurity and privacy policies aligned with federal requirements. • Interpret and operationalize Executive Orders, Office of Management and Budget (OMB) memoranda, CISA directives, NIST guidance, and other federal cybersecurity mandates. • Ensure organizational compliance with: • Federal Information Security Modernization Act (FISMA) • NIST Risk Management Framework (RMF) • NIST Special Publications (including 800-53 and 800-37) • Zero Trust Architecture guidance • Federal cybersecurity policies and directives • Support third-party risk management and supply chain security initiatives. • Identify opportunities to automate compliance monitoring, evidence collection, and reporting activities. • Advise on Artificial Intelligence (AI) governance, security guardrails, and responsible AI implementation. • Assess cybersecurity impacts of new technologies and recommend appropriate security controls. Continuous Monitoring & Authorization • Support modernization of Authorization to Operate (ATO) and continuous monitoring processes. • Develop strategies to automate security control assessments using NIST SP 800-53 controls. • Define technical controls suitable for automated assessment and continuous validation. • Evaluate security data sources including SIEM, endpoint detection, vulnerability management, and cloud security tools to improve continuous compliance monitoring. • Develop automated risk thresholds, monitoring criteria, and reporting mechanisms to support ongoing authorization. • Support alignment with FedRAMP 20X modernization initiatives and evolving federal cloud authorization requirements. • Research and provide recommendations for continuous monitoring of Artificial Intelligence systems consistent with Information Security Continuous Monitoring (ISCM) standards. • Evaluate automated monitoring solutions to identify anomalies, measure security performance, and improve organizational cyber resilience. Stakeholder Engagement • Conduct cybersecurity education, awareness, communication, and outreach activities. • Collaborate with executive leadership, technical teams, compliance organizations, and external stakeholders. • Present complex cybersecurity concepts to technical and non-technical audiences. • Facilitate governance meetings, working groups, and strategic planning sessions. Required Qualifications • Bachelor's degree in Cybersecurity, Information Assurance, Information Technology, Computer Science, or a related field. • 5+ years of experience supporting federal cybersecurity governance, compliance, or enterprise security programs. • Demonstrated experience advising CISOs, executive leadership, or senior government officials on cybersecurity strategy. • Extensive knowledge of: • Federal Information Security Modernization Act (FISMA) • NIST Risk Management Framework (RMF) • NIST SP 800-53, 800-37, and related publications • Zero Trust Architecture • Information Security Continuous Monitoring (ISCM) • FedRAMP and cloud security authorization processes • Experience interpreting Executive Orders, OMB memoranda, federal cybersecurity directives, and government-wide security policies. • Experience developing cybersecurity policies, governance documentation, and compliance frameworks. • Familiarity with Governance, Risk, and Compliance (GRC) platforms and compliance automation tools. • Strong understanding of enterprise risk management principles and cybersecurity governance. Preferred Qualifications • Certified Information Systems Security Professional (CISSP) • Certified Information Security Manager (CISM) • Certified in Risk and Information Systems Control (CRISC) • Project Management Professional (PMP) • Experience supporting Treasury, DHS, or other civilian federal agencies. • Experience with Artificial Intelligence governance, AI security, or emerging technology policy. • Knowledge of SIEM platforms, vulnerability management solutions, endpoint detection and response (EDR), and cloud security monitoring technologies. Knowledge, Skills, and Abilities • Ability to interpret complex federal cybersecurity regulations and translate them into actionable organizational guidance. • Strong understanding of executive-level cybersecurity governance and risk management. • Exceptional analytical, policy development, and strategic planning skills. • Ability to balance regulatory compliance with operational and business objectives. • Strong written and verbal communication skills, including development of executive briefings and policy documentation. • Ability to lead cross-functional initiatives involving technical, operational, and executive stakeholders. • Demonstrated ability to evaluate emerging cybersecurity technologies, evolving federal mandates, and industry best practices to support informed, risk-based decision making. Compensation & Benefits • Competitive salary • Employer-paid health insurance premiums (medical, dental, vision) • Employer-paid short/long term disability insurance and basic life/AD&D insurance • 401K with a 4% employer contribution • Professional development reimbursement options available (training, certification, education, etc) • Flexible and remote work policies for most positions • Paid Time Off (PTO) at a rate of three (3) weeks plus one (1) day per year of service up to four (4) weeks annually • 11 paid holidays per calendar year At SIXGEN, we are committed to fair and equitable compensation practices. The anticipated salary range for this role is $100,000 - $155,000 per year, depending on experience and qualifications. This range reflects our compensation philosophy, which takes into account various factors including the candidate's relevant experience, education, skills, LCATs rates and position level, and market competitiveness. In addition to base salary, employees may be eligible for other forms of compensation to include our growth incentive program, incentives and benefits. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure. We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work. SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.
Lead strategy, governance, and operational maturity of an enterprise Security Fusion Center integrating multiple cybersecurity functions. | Requires 6+ years cybersecurity operations experience, SOC/SFC program management, governance development, and strong leadership and communication skills. | Job Title: Security Fusion Center (SFC) Manager Position Summary The Security Fusion Center (SFC) Manager is responsible for leading the strategy, governance, and operational maturity of an enterprise Security Fusion Center. This role serves as the primary architect and coordinator for an intelligence-driven cybersecurity program that integrates threat intelligence, threat hunting, incident response, security engineering, insider threat, continuous monitoring, and attack surface management into a unified operational capability. The ideal candidate possesses extensive experience developing and managing enterprise cybersecurity programs, establishing governance frameworks, and driving cross-functional collaboration among cybersecurity operations, engineering, and executive leadership. This individual will lead the development of Security Fusion Center strategy, operational processes, performance metrics, and implementation roadmaps while continuously improving the organization's ability to identify, detect, respond to, and mitigate cyber threats. Key Responsibilities Security Fusion Center Program Leadership • Lead the strategic planning, governance, and operational management of the enterprise Security Fusion Center (SFC). • Develop and maintain the SFC mission, vision, operational scope, and long-term strategic roadmap. • Continuously assess and mature the Security Fusion Center's people, processes, technology, and operational capabilities. • Develop and maintain implementation plans aligned with evolving organizational priorities and the cyber threat landscape. • Establish governance structures supporting enterprise-wide cybersecurity collaboration and decision-making. Program Governance & Documentation • Develop, maintain, and update SFC governance documentation, including: • Program Charter • Concept of Operations (CONOPS) • Standard Operating Procedures (SOPs) • Operational Playbooks • Process Documentation • Ensure governance documentation remains current and aligned with organizational objectives and industry best practices. • Develop implementation strategies supporting adoption of Security Fusion Center capabilities across the enterprise. Security Operations Integration Coordinate and support enterprise cybersecurity functions including: • Threat Intelligence • Advanced Threat Hunting • Incident Response • Continuous Monitoring • Alerting and Detection • Security Solutions Engineering • Insider Threat Program • Attack Surface Management • Assessment and Authorization • Foster collaboration among technical teams to improve operational effectiveness and cyber resilience. • Identify opportunities to improve information sharing, operational workflows, and threat correlation across cybersecurity disciplines. Strategic Planning & Continuous Improvement • Assess organizational cybersecurity capabilities and identify gaps in people, processes, technology, and operational maturity. • Develop strategic recommendations for new cybersecurity tools, technologies, staffing, and operational enhancements. • Evaluate emerging threats and evolving cybersecurity trends to support proactive defense strategies. • Develop future-state operating models supporting enterprise cyber defense objectives. • Develop executive dashboards and reporting mechanisms that communicate program performance and operational maturity. • Analyze trends to recommend improvements in cyber operations and organizational readiness. Required Qualifications • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field. • 6+ years of experience in cybersecurity operations, cyber defense, or enterprise security program management. • Demonstrated experience developing or managing a Security Operations Center (SOC), Security Fusion Center (SFC), Cyber Fusion Center, or equivalent enterprise cybersecurity program. • Experience leading cross-functional cybersecurity initiatives involving multiple operational teams. • Strong understanding of: • Threat Intelligence • Advanced Threat Hunting • Incident Response • Continuous Monitoring • Security Engineering • Insider Threat Programs • Attack Surface Management • Experience developing governance documentation, operational procedures, playbooks, and Concepts of Operations (CONOPS). • Experience developing cybersecurity strategies, roadmaps, implementation plans, and executive-level reporting. • Strong knowledge of cybersecurity frameworks including the NIST Cybersecurity Framework (CSF), NIST Risk Management Framework (RMF), and MITRE ATT&CK. • Excellent communication, leadership, and stakeholder engagement skills. Preferred Qualifications • CISSP (Certified Information Systems Security Professional) • GIAC Certified Incident Handler (GCIH) • GIAC Cyber Threat Intelligence (GCTI) • Certified Information Security Manager (CISM) • Project Management Professional (PMP) • Experience supporting federal government cybersecurity programs. • Experience implementing enterprise SIEM, SOAR, XDR, EDR, threat intelligence platforms, or security analytics solutions. • Familiarity with Zero Trust Architecture and enterprise cyber modernization initiatives. Knowledge, Skills, and Abilities • Ability to lead large-scale cybersecurity transformation initiatives. • Strong understanding of intelligence-driven cybersecurity operations and Security Fusion Center concepts. • Ability to translate technical cybersecurity capabilities into strategic business value. • Expertise in cybersecurity program governance, operational planning, and organizational change management. • Ability to facilitate collaboration across engineering, operations, intelligence, risk management, and executive leadership teams. • Strong analytical and problem-solving skills with the ability to assess organizational cyber maturity and recommend strategic improvements. • Excellent written and verbal communication skills, including development of executive briefings, strategic plans, and governance documentation. Compensation & Benefits • Competitive salary • Employer-paid health insurance premiums (medical, dental, vision) • Employer-paid short/long term disability insurance and basic life/AD&D insurance • 401K with a 4% employer contribution • Professional development reimbursement options available (training, certification, education, etc) • Flexible and remote work policies for most positions • Paid Time Off (PTO) at a rate of three (3) weeks plus one (1) day per year of service up to four (4) weeks annually • 11 paid holidays per calendar year At SIXGEN, we are committed to fair and equitable compensation practices. The anticipated salary range for this role is $100,000 - $155,000 per year, depending on experience and qualifications. This range reflects our compensation philosophy, which takes into account various factors including the candidate's relevant experience, education, skills, LCATs rates and position level, and market competitiveness. In addition to base salary, employees may be eligible for other forms of compensation to include our growth incentive program, incentives and benefits. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure. We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work. SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.
Design, develop, and maintain enterprise security analytics and Splunk platform to support threat detection and response. | 5+ years experience with Splunk ES, SOAR, UEBA, CRIBL pipelines, detection engineering, scripting, and security operations workflows. | Job Title: Security Analytics Engineer $145,000-$150,000 Position Summary The Security Analytics Engineer is responsible for engineering, optimizing, and sustaining the enterprise security analytics platform that supports the organization's Security Fusion Center (SFC). This role designs, implements, and maintains security monitoring capabilities by developing advanced detection analytics, optimizing security telemetry, integrating enterprise security tools, and enabling automation across the cybersecurity ecosystem. The ideal candidate is an expert in Splunk Enterprise Security and the broader Splunk platform, with extensive experience implementing and managing CRIBL data pipelines, security analytics, detection engineering, and enterprise log management. This individual partners with Threat Intelligence, Threat Hunting, Incident Response, and Security Operations teams to ensure security technologies provide timely, high-fidelity detection of evolving adversary tactics, techniques, and procedures (TTPs). Key Responsibilities Security Analytics Engineering • Design, develop, and maintain enterprise security analytics supporting the Security Fusion Center. • Develop advanced detection logic, correlation searches, dashboards, reports, and alerts to identify emerging cyber threats. • Continuously improve detection capabilities by developing analytics aligned with current adversary tactics, techniques, and procedures (TTPs). • Engineer scalable solutions that improve security visibility, operational efficiency, and threat detection effectiveness. Splunk Platform Engineering • Administer, configure, and optimize Splunk Enterprise Security (ES), Splunk User and Entity Behavior Analytics (UEBA), and Splunk Security Orchestration, Automation, and Response (SOAR). • Develop and maintain Splunk searches, correlation rules, risk-based alerting, dashboards, and knowledge objects. • Optimize data ingestion, indexing, data models, and search performance across large enterprise environments. • Support lifecycle management, upgrades, performance tuning, and operational maintenance of the Splunk platform. CRIBL & Security Data Pipeline Engineering • Design, implement, and maintain CRIBL pipelines to efficiently collect, normalize, enrich, filter, and route enterprise security telemetry. • Optimize log ingestion and data transformation processes to improve analytics quality while reducing storage and licensing costs. • Develop parsing, enrichment, and routing logic supporting enterprise detection engineering. • Integrate data from cloud, endpoint, network, identity, and application security platforms into the Security Fusion Center analytics environment. Detection Engineering & Security Tool Integration • Develop and maintain detection analytics supporting proactive identification of advanced cyber threats. • Evaluate emerging security technologies and recommend enhancements aligned with enterprise cybersecurity strategy. • Support integration of enterprise security platforms, including SIEM, SOAR, EDR, identity security, vulnerability management, and cloud security tools. • Collaborate with Threat Hunting and Threat Intelligence teams to operationalize new detections based on emerging threats. Security Platform Operations • Operate, maintain, and continuously improve the Security Fusion Center Analytics Platform (SFCAP). • Support engineering efforts for enterprise security analytics platforms, including custom and commercial solutions. • Maintain an inventory of enterprise security tools and document system capabilities, integrations, and operational dependencies. • Support platform reliability, availability, scalability, and security. Automation & AI • Implement AI-enabled analytics and automation capabilities to improve ingestion, normalization, enrichment, correlation, and analysis of security telemetry. • Identify opportunities to automate repetitive engineering and operational tasks. • Research emerging technologies supporting security analytics, machine learning, and operational efficiency. • Assist in evaluating AI-enabled security operations capabilities and recommending implementation strategies. ServiceNow Security Integration • Develop security use cases supporting enterprise adoption of ServiceNow Security Incident Response (SIR). • Design and document integrations between ServiceNow and enterprise security platforms. • Collaborate with operational teams to improve incident workflows through automation and orchestration. Required Qualifications • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field. • 5+ years of experience designing and supporting enterprise security analytics platforms. • Extensive hands-on experience administering and engineering: • Splunk Enterprise Security (ES) • Splunk SOAR • Splunk UEBA • Splunk Enterprise • Extensive experience designing and managing CRIBL pipelines for enterprise log management and security telemetry. • Experience developing detection content, correlation searches, dashboards, and security analytics. • Strong understanding of SIEM architecture, log management, telemetry normalization, and security data engineering. • Experience integrating enterprise security technologies including EDR, IDS/IPS, cloud security, identity platforms, vulnerability management, and network security tools. • Experience with scripting or automation using Python, PowerShell, or similar languages. • Strong understanding of MITRE ATT&CK, detection engineering methodologies, and Security Operations Center workflows. • Excellent analytical and troubleshooting skills. Preferred Qualifications • Splunk Enterprise Certified Architect • Splunk Enterprise Certified Admin • Splunk Core Certified Power User • CRIBL Certified Administrator or equivalent experience • CISSP (Certified Information Systems Security Professional) • GIAC Certified Enterprise Defender (GCED) • Experience supporting federal government cybersecurity programs. • Experience supporting custom security analytics platforms, including proprietary Security Fusion Center analytics solutions. • Experience with ServiceNow Security Incident Response (SIR) integrations and workflows. Knowledge, Skills, and Abilities • Expert knowledge of Splunk Enterprise Security architecture, engineering, and optimization. • Deep understanding of CRIBL data engineering, log routing, parsing, enrichment, and telemetry optimization. • Ability to design scalable enterprise security analytics architectures supporting large and complex environments. • Strong understanding of detection engineering, threat analytics, and adversary behavior. • Ability to engineer integrations between enterprise security platforms and automate operational workflows. • Experience evaluating emerging security technologies and recommending enterprise adoption strategies. • Excellent collaboration skills with Security Operations, Threat Intelligence, Threat Hunting, Incident Response, and Security Engineering teams. • Ability to translate operational requirements into scalable, maintainable security engineering solutions. Compensation & Benefits • Competitive salary • Employer-paid health insurance premiums (medical, dental, vision) • Employer-paid short/long term disability insurance and basic life/AD&D insurance • 401K with a 4% employer contribution • Professional development reimbursement options available (training, certification, education, etc) • Flexible and remote work policies for most positions • Paid Time Off (PTO) at a rate of three (3) weeks plus one (1) day per year of service up to four (4) weeks annually • 11 paid holidays per calendar year At SIXGEN, we are committed to fair and equitable compensation practices. The anticipated salary range for this role is $100,000 - $155,000 per year, depending on experience and qualifications. This range reflects our compensation philosophy, which takes into account various factors including the candidate's relevant experience, education, skills, LCATs rates and position level, and market competitiveness. In addition to base salary, employees may be eligible for other forms of compensation to include our growth incentive program, incentives and benefits. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure. We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work. SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.
Lead and optimize enterprise vulnerability management using ServiceNow VR platform, integrating scanning tools, automating workflows, and reporting. | Requires 5+ years supporting enterprise vulnerability management with deep ServiceNow Security Operations and VR experience, strong automation and risk-based prioritization skills. | Job Title: ServiceNow Vulnerability Response Engineer $145,000-$150,000 Position Summary The ServiceNow Vulnerability Response (VR) Engineer is responsible for designing, implementing, and optimizing the Bureau's Enterprise Vulnerability Management Program (VMP) through the ServiceNow Security Operations platform. This role supports the engineering and enhancement of the Vulnerability Response (VR) application, integrating vulnerability data sources, automating remediation workflows, and improving enterprise vulnerability reporting. The ideal candidate possesses deep experience with ServiceNow Security Operations, particularly the Vulnerability Response (VR) module, and understands how vulnerability management integrates with Security Incident Response (SIR), Governance, Risk, and Compliance (GRC), Configuration Management Database (CMDB), and enterprise security operations. This individual will collaborate with cybersecurity, infrastructure, application, and business stakeholders to ensure vulnerabilities are prioritized, tracked, remediated, and reported effectively using risk-based methodologies and automation. Key Responsibilities ServiceNow Vulnerability Response Engineering • Configure, administer, and enhance the ServiceNow Vulnerability Response (VR) application within the ServiceNow Security Operations platform. • Design and implement workflows that improve vulnerability identification, prioritization, assignment, remediation, and reporting. • Develop and maintain integrations between ServiceNow VR and enterprise vulnerability scanning platforms. • Configure business rules, workflows, forms, notifications, dashboards, and reporting to support vulnerability management operations. • Continuously improve platform functionality to increase operational efficiency and automation. Enterprise Vulnerability Management • Support the organization's Enterprise Vulnerability Management Program (VMP) by improving vulnerability lifecycle management. • Integrate vulnerability findings from multiple scanning tools into ServiceNow to provide centralized visibility and workflow management. • Support risk-based vulnerability prioritization based on exploitability, business criticality, asset value, and operational impact. • Collaborate with remediation teams to ensure vulnerabilities are tracked through closure and validated appropriately. • Develop vulnerability reporting metrics and executive dashboards supporting organizational risk management. Security Operations & GRC Integration • Support integration between ServiceNow Vulnerability Response (VR), Security Incident Response (SIR), Governance, Risk, and Compliance (GRC), CMDB, and other ServiceNow modules. • Coordinate with Security Operations, Risk Management, Compliance, and Infrastructure teams to improve operational workflows. • Ensure vulnerability management processes align with enterprise governance and cybersecurity policies. • Assist in documenting vulnerability management procedures and operational processes. Automation & AI • Implement automation capabilities that improve vulnerability ingestion, enrichment, prioritization, and remediation workflows. • Utilize AI-enabled capabilities to identify high-risk vulnerabilities based on exploitability, threat intelligence, and business impact. • Research emerging automation and AI technologies that improve vulnerability management effectiveness and scalability. • Recommend workflow improvements that reduce manual effort and accelerate remediation activities. Reporting & Continuous Improvement • Develop executive-level vulnerability reporting, operational dashboards, and compliance metrics. • Monitor program performance and recommend enhancements to vulnerability management processes. • Analyze trends to identify recurring weaknesses and opportunities to improve organizational security posture. • Maintain documentation supporting platform configuration, integrations, workflows, and operational procedures. Required Qualifications • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field. • 5+ years of experience supporting enterprise Vulnerability Management Programs. • Extensive hands-on experience with: • ServiceNow Security Operations • ServiceNow Vulnerability Response (VR) • ServiceNow Security Incident Response (SIR) • ServiceNow Governance, Risk, and Compliance (GRC) • Experience integrating enterprise vulnerability scanners (such as Tenable, Qualys, Rapid7, or Microsoft Defender Vulnerability Management) with ServiceNow. • Strong understanding of vulnerability lifecycle management, remediation workflows, and risk-based prioritization. • Experience configuring ServiceNow workflows, dashboards, reporting, business rules, and automation. • Knowledge of vulnerability scoring methodologies, including CVSS, exploitability metrics, and business impact analysis. • Strong understanding of enterprise cybersecurity operations and vulnerability management best practices. • Excellent analytical, troubleshooting, and communication skills. Preferred Qualifications • ServiceNow Certified System Administrator (CSA) • ServiceNow Certified Implementation Specialist – Vulnerability Response (CIS-VR) • ServiceNow Certified Implementation Specialist – Security Incident Response (CIS-SIR) • ServiceNow Certified Application Developer (CAD) • CISSP (Certified Information Systems Security Professional) • Experience supporting federal government cybersecurity programs. • Familiarity with AI-enabled vulnerability prioritization and automated remediation capabilities. • Experience integrating ServiceNow with enterprise CMDB, ITSM, and Security Operations platforms. Knowledge, Skills, and Abilities • Deep knowledge of ServiceNow Security Operations, particularly Vulnerability Response (VR) and Security Incident Response (SIR). • Strong understanding of Governance, Risk, and Compliance (GRC) processes and their relationship to vulnerability management. • Ability to design scalable vulnerability management workflows that improve operational efficiency and accountability. • Experience developing executive dashboards, vulnerability reporting, and risk metrics. • Strong understanding of vulnerability scanning technologies, remediation processes, and enterprise risk management. • Ability to automate vulnerability workflows and improve operational maturity using ServiceNow capabilities. • Excellent collaboration skills with cybersecurity, infrastructure, compliance, application, and business teams. • Ability to translate business and operational requirements into effective ServiceNow security solutions. Compensation & Benefits • Competitive salary • Employer-paid health insurance premiums (medical, dental, vision) • Employer-paid short/long term disability insurance and basic life/AD&D insurance • 401K with a 4% employer contribution • Professional development reimbursement options available (training, certification, education, etc) • Flexible and remote work policies for most positions • Paid Time Off (PTO) at a rate of three (3) weeks plus one (1) day per year of service up to four (4) weeks annually • 11 paid holidays per calendar year At SIXGEN, we are committed to fair and equitable compensation practices. The anticipated salary range for this role is $100,000 - $155,000 per year, depending on experience and qualifications. This range reflects our compensation philosophy, which takes into account various factors including the candidate's relevant experience, education, skills, LCATs rates and position level, and market competitiveness. In addition to base salary, employees may be eligible for other forms of compensation to include our growth incentive program, incentives and benefits. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure. We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work. SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.
Lead strategic planning, governance, and operational management of an enterprise Security Fusion Center integrating multiple cybersecurity functions. | Requires 6+ years cybersecurity operations experience, SOC/SFC management, governance development, cross-functional leadership, and strong knowledge of cybersecurity frameworks. | Job Title: Security Fusion Center (SFC) Manager $142,000-$150,000 Position Summary The Security Fusion Center (SFC) Manager is responsible for leading the strategy, governance, and operational maturity of an enterprise Security Fusion Center. This role serves as the primary architect and coordinator for an intelligence-driven cybersecurity program that integrates threat intelligence, threat hunting, incident response, security engineering, insider threat, continuous monitoring, and attack surface management into a unified operational capability. The ideal candidate possesses extensive experience developing and managing enterprise cybersecurity programs, establishing governance frameworks, and driving cross-functional collaboration among cybersecurity operations, engineering, and executive leadership. This individual will lead the development of Security Fusion Center strategy, operational processes, performance metrics, and implementation roadmaps while continuously improving the organization's ability to identify, detect, respond to, and mitigate cyber threats. Key Responsibilities Security Fusion Center Program Leadership • Lead the strategic planning, governance, and operational management of the enterprise Security Fusion Center (SFC). • Develop and maintain the SFC mission, vision, operational scope, and long-term strategic roadmap. • Continuously assess and mature the Security Fusion Center's people, processes, technology, and operational capabilities. • Develop and maintain implementation plans aligned with evolving organizational priorities and the cyber threat landscape. • Establish governance structures supporting enterprise-wide cybersecurity collaboration and decision-making. Program Governance & Documentation • Develop, maintain, and update SFC governance documentation, including: • Program Charter • Concept of Operations (CONOPS) • Standard Operating Procedures (SOPs) • Operational Playbooks • Process Documentation • Ensure governance documentation remains current and aligned with organizational objectives and industry best practices. • Develop implementation strategies supporting adoption of Security Fusion Center capabilities across the enterprise. Security Operations Integration Coordinate and support enterprise cybersecurity functions including: • Threat Intelligence • Advanced Threat Hunting • Incident Response • Continuous Monitoring • Alerting and Detection • Security Solutions Engineering • Insider Threat Program • Attack Surface Management • Assessment and Authorization • Foster collaboration among technical teams to improve operational effectiveness and cyber resilience. • Identify opportunities to improve information sharing, operational workflows, and threat correlation across cybersecurity disciplines. Strategic Planning & Continuous Improvement • Assess organizational cybersecurity capabilities and identify gaps in people, processes, technology, and operational maturity. • Develop strategic recommendations for new cybersecurity tools, technologies, staffing, and operational enhancements. • Evaluate emerging threats and evolving cybersecurity trends to support proactive defense strategies. • Develop future-state operating models supporting enterprise cyber defense objectives. • Develop executive dashboards and reporting mechanisms that communicate program performance and operational maturity. • Analyze trends to recommend improvements in cyber operations and organizational readiness. Required Qualifications • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field. • 6+ years of experience in cybersecurity operations, cyber defense, or enterprise security program management. • Demonstrated experience developing or managing a Security Operations Center (SOC), Security Fusion Center (SFC), Cyber Fusion Center, or equivalent enterprise cybersecurity program. • Experience leading cross-functional cybersecurity initiatives involving multiple operational teams. • Strong understanding of: • Threat Intelligence • Advanced Threat Hunting • Incident Response • Continuous Monitoring • Security Engineering • Insider Threat Programs • Attack Surface Management • Experience developing governance documentation, operational procedures, playbooks, and Concepts of Operations (CONOPS). • Experience developing cybersecurity strategies, roadmaps, implementation plans, and executive-level reporting. • Strong knowledge of cybersecurity frameworks including the NIST Cybersecurity Framework (CSF), NIST Risk Management Framework (RMF), and MITRE ATT&CK. • Excellent communication, leadership, and stakeholder engagement skills. Preferred Qualifications • CISSP (Certified Information Systems Security Professional) • GIAC Certified Incident Handler (GCIH) • GIAC Cyber Threat Intelligence (GCTI) • Certified Information Security Manager (CISM) • Project Management Professional (PMP) • Experience supporting federal government cybersecurity programs. • Experience implementing enterprise SIEM, SOAR, XDR, EDR, threat intelligence platforms, or security analytics solutions. • Familiarity with Zero Trust Architecture and enterprise cyber modernization initiatives. Knowledge, Skills, and Abilities • Ability to lead large-scale cybersecurity transformation initiatives. • Strong understanding of intelligence-driven cybersecurity operations and Security Fusion Center concepts. • Ability to translate technical cybersecurity capabilities into strategic business value. • Expertise in cybersecurity program governance, operational planning, and organizational change management. • Ability to facilitate collaboration across engineering, operations, intelligence, risk management, and executive leadership teams. • Strong analytical and problem-solving skills with the ability to assess organizational cyber maturity and recommend strategic improvements. • Excellent written and verbal communication skills, including development of executive briefings, strategic plans, and governance documentation. Compensation & Benefits • Competitive salary • Employer-paid health insurance premiums (medical, dental, vision) • Employer-paid short/long term disability insurance and basic life/AD&D insurance • 401K with a 4% employer contribution • Professional development reimbursement options available (training, certification, education, etc) • Flexible and remote work policies for most positions • Paid Time Off (PTO) at a rate of three (3) weeks plus one (1) day per year of service up to four (4) weeks annually • 11 paid holidays per calendar year At SIXGEN, we are committed to fair and equitable compensation practices. The anticipated salary range for this role is $100,000 - $155,000 per year, depending on experience and qualifications. This range reflects our compensation philosophy, which takes into account various factors including the candidate's relevant experience, education, skills, LCATs rates and position level, and market competitiveness. In addition to base salary, employees may be eligible for other forms of compensation to include our growth incentive program, incentives and benefits. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure. We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work. SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.
Conduct penetration testing, phishing assessments, vulnerability risk assessments, and document findings with remediation recommendations. | US citizenship with Public Trust clearance eligibility, offensive security certification (OSCP, CRTO, CPTS, PNPT), familiarity with FISMA and NIST 800 standards, experience with offensive security tools and scripting, and strong teamwork and communication skills. | SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape. POSITION OVERVIEW • Position: Junior Offensive Cyber Operator • Job Type: Full Time • Location: Remote US. Proximity to Maryland or Virginia is a plus, but not required • Clearance Requirements: Must be able to obtain Public Trust • Travel: Up to 10% ABOUT THE TEAM SIXGEN supports cyber and intelligence missions by serving government and commercial organizations as they overcome global cybersecurity challenges. You'll work with our highly skilled operators conducting research and assessments based on real-world threats. You'll simulate adversaries and malicious actors and report details and actionable findings on critical assets and infrastructures. Using innovative processes, tools, and techniques, you'll predict and overcome cybersecurity vulnerabilities. Your successes will be supported by our diverse team of experienced, technical talent. WHAT YOU'LL DO • Conduct internal and external penetration testing of systems to identify vulnerabilities and recommend mitigation strategies. • Perform phishing assessments to evaluate organizational resilience. • Execute vulnerability risk assessments and support testing phases of security control evaluations. • Utilize offensive security tools (e.g., Metasploit, Nmap, Burp Suite, PowerSploit, Cobalt Strike) to simulate real-world threats. • Coordinate assessment equipment and support pen testing of externally exposed networks. • Write scripts, craft payloads, and contribute to bug bounty-style testing where applicable. • Document findings with clear reproduction steps and provide recommendations for remediation. REQUIRED QUALIFICATIONS • US Citizen with the ability to obtain Public Trust clearance. • At least one of the following certifications: OSCP, CRTO, CPTS, PNPT. • Familiarity with FISMA and NIST 800 series standards. • Experience with network mapping, vulnerability scanning, penetration testing, and/or web application testing. • Proficiency with offensive tools such as Metasploit, Nmap, Burp Suite, PowerSploit, or Cobalt Strike. • Demonstrated ability to write scripts and craft payloads. • Strong leadership, teamwork, and communication skills; willingness to help others. • Experience with bug bounty programs is a plus. • A lifelong learner committed to continuous skill development. COMPENSATION & BENEFITS Salary Range: $95,000 - $105,000 USD The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Additionally, SIXGEN offers top-tier benefits for full-time employees, including: • Employer-paid health insurance premiums (medical, dental, vision) for you and your family • Employer-paid short/long term disability insurance and basic life/AD&D insurance • 401K with a 4% employer contribution • Professional development reimbursement options available (training, certification, education, etc) • Flexible and remote work policies for most positions • Flexible PTO and holiday schedule OUR COMMITMENT SIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class. We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work.
Create tailored applications specifically for SIXGEN with our AI-powered resume builder
Get Started for Free