Jobs and Careers
ON

CyberSecurity Specialist

Oneida Innovations Group
United States, United Statesfull_timeVerifiedPosted 17 Aug 2023
💰 $140,000/yr($120,000/yr$140,000/yr)

About the role

Oneida Technical Solutions (OTS) is a tribally-owned 8(a) certified IT Network and Telecommunications Services company, wholly owned and operated by the Oneida Nation of New York through Oneida Nation Enterprises, LLC. Headquartered in Oneida, New York, OTS is the direct parent company of Croop-LaFrance, Inc.

We are currently seeking a Cybersecurity Specialist to join our team at West Point Academy.

The contracted cyber technician assigned to support the Cybersecurity Branch mission must analyze general information assurance-related technical problems and provides basic engineering and technical support in solving these problems. The contractor will assist in the design, development, engineering, and implementation of solutions that meet network security requirements. The contractor will perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.

The contracted technician will be tasked with the following additional duties within their scope of work:


a) Firewall Monitor multiple firewalls and Intrusion Prevention & Detection Systems for optimal performance, correct configuration, local events, and logging (remote and local). Review events to determine impact, if any, and severity of the event. Brief Cyber leadership on events of interest, incidents, and configuration issues. Incidents must be reported within certain time thresholds which are defined by the severity of the incident. Provide configuration recommendations to Cyber and Implementation teams on ways to improve security without impacting mission requirements to include industry best practices. Evaluates proposed changes and performs impact analysis for any proposed change, validates changes that are approved through the USMA Change Control process are correctly implemented, and monitors performance and security posture to ensure the change is correctly implemented without negative impacts. Makes recommendations as to deployment of additional IDS/IPS systems and configurations to protect the WREN enclave.

b) Security Information and Event Management (SIEM) Will monitor CIOG6 SIEM product, multiple alerting systems within a number of different cloud-based and local products such as but not limited to Microsoft Office 365 and Microsoft Defender Advanced Threat Protection, and determine whether events are incident-related. Will brief Cyber team on incidents based on severity and impact. Will ensure local systems are correctly logging to SIEM product and will work with infrastructure and system owners to aid as needed. Will advise on policy tuning and baseline configuration tuning to reduce false alerts while ensuring true alerts are captured through alerting systems and will recommend courses of action based on alerts. Will recommend implementation procedures for automatic remediation processes and ways to streamline alert remediation process based on alert types, frequency, impact, severity, and other alert criteria as defined by G6 Cyber. Will compile weekly, monthly, and annual reports highlighting alert and threat trends.

c) End-point Protection Evaluates alerts from end point security system reporting products, and SIEM alerts as they relate to end point security. Differentiates between actual alerts and false positives and makes tuning recommendations to reduce the rate of false positives. Makes recommendations on cloud-based security policies and local machine policies which can help reduce threat surface and increase overall security posture without impacting mission requirements. Assist with implementation as required. Assists Cyber team with research into different settings and tools such as VMWare and VirtualBox. Evaluates recommended changes for system impact, ability to implement, and security enhancement. Collection information from end user to determine whether an incident has occurred and does initial incident information collection. Assists G6 Cyber with forensics or LE investigative tasks if required but does not conduct investigative tasks independently. Maintains visibility on new configuration abilities in bleeding edge software releases, tests changes in lab, makes recommendations for security adjustments based on findings,

d) Vulnerability Management Evaluate endpoint security posture against configured compliance baselines, make recommendations to G6 Cyber and G6 CTO on changing of baselines to enhance security without compromising mission functionality, provide mission impact and risk analysis for any recommendations. Determine which software packages must be maintained at the enterprise level, through enterprise patching in software center, and make recommendations to Cyber on priority of patching. Assist Enterprise and IT Support branches in defining package requirements and configuration in Software Center if required.

e) Assist Cyber Protection

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Oneida Innovations Group

View company profile →