Jobs and Careers
VO

Senior Cybersecurity Technical Specialist with Secret

VOSAGO
Washington, United StatesRemotefull_timeVerifiedPosted 27 Sept 2024

About the role

Background: The Department of Homeland Security (DHS), Office of Inspector General (OIG) conducts and supervises independent audits, investigations, and inspections of the programs and operations of DHS, and recommends ways for DHS to carry out its responsibilities in the
most effective, efficient, and economical manner possible. We also seek to deter, identify and address fraud, abuse, mismanagement, and waste of taxpayer funds invested in Homeland Security.
The OIG, specifically the Office of Innovation (OIN), Cybersecurity Risk Assessment (CRA) Division, conducts IT security assessments of DHS’ component information technology systems to ensure computer resources are implemented according to applicable policies, standards, and procedures. Which in turn ensure their availability, integrity, authentication, confidentiality, and non-repudiation. As IT evolves, so do the threats to data security, individual privacy, and the continued operation of the Federal Government’s IT assets

Qualifications
• Minimum of 10 years of experience in task areas assigned, and familiarity with IT security assessment standards and methodologies and;
• Preference of bachelor’s degree, or higher, in Cybersecurity, or a related field.
• Minimum of five (5) years serving in a Senior Subject Matter Expert role applying subject matter knowledge, directly related technical assessments, to perform assessment, analysis, and documentation of results. Additionally, a senior IT SME should have the ability to resolve problems, which necessitates an intimate knowledge of the related technical subject matter.
• Certifications in tasks topics is certifications preferred.
• Experience with advanced IT testing methodologies and the various IT technologies.
• Familiar with Federal policy requirements for information systems, including Office of Management and Budget (OMB) Circulars, National Institute of Standards and Technology Special Publications (NIST SP), Presidential Orders, Federal Information Processing Standards (FIPS), and the Risk Management Framework (RMF) process.
• Strong customer service skills and team building skills, and the ability to collaborate within a cross-functional team.
• Ability to research and resolve problems efficiently and accurately with knowledge and experience of IT assessments.
• Performs detail-oriented task independently.
• Excellent written and verbal communication skills.
• Experience providing project briefs to senior management and executives.

Experience with:
  • Tenable Nessus SecurityCenter/Professional/Expert
  •  Trustwave DbProtect/AppDetectivePro
  • Burp Suite Professional
  • SpecterOps BloodHound
  • Fortify Static Code Analyzer

Secret clearance is required

Location: The majority of work described in this SOW shall be done at DHS OIG HQ (395 ESt. SW), or at approved personnel telework locations. Additionally, technical assessments is conducted at DHS Components sites, mostly located near the Washington, D.C. area,
but also throughout the Continental United States.

Anticipated start date: 8/31/2023; duration: 5 yrs

Tasks:
Security Information and Event Management (SIEM) Subject Matter Expertise Security Information and Event Management, also known as audit trail or audit logs, is a security relevant chronological record, set of records, or destination and source of records that provide
documentary evidence of the sequence of activities that have affected at any time a specific operation, procedure, or event. The Contractor shall provide expertise in audit and event logging methodologies, protocols, technologies to archive, organize, and alert to trends in logs, as well as understanding of the different types and sources of logs such as network, hardware, operating system, application, and event. The Contractor will also understand the different outcomes that can be derived from event monitoring and analysis, such as, user and asset behavior analysis, and incident response via Security, Orchestration, Automation, and Response (SOAR).
Expert knowledge and skills required for security information and event management include but not
limited to:
• Technologies used to generate, collect, secure, and analyze logs such as, but not limited to, Splunk, IBM Security QRadar SIEM, McAfee Enterprise Security Manager, and SolarWinds Security Event Manager.
• Federal government requirements and industry best practices for log retention.
• Cryptographic log integrity mechanisms such as Blockchain.
• Log retention and management and visibility technologies such as dashboards.
• Technologies used to read logs, transfer logs, and ingest into dashboards or other
analytical tools.
• Understanding of logging retention and use for third parti

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

VOSAGO

View company profile →