L2 Cyber Solutions · 7 hours ago
IT Security Specialist
Maximize your interview chances
ConsultingInformation Technology
No H1BU.S. Citizen Only
Insider Connection @L2 Cyber Solutions
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Ensures security standards and best practices are appropriately integrated into development of cloud applications and deployments.
Provide guidance to developers and other technical stakeholders on security topics, and educate members on their responsibility regarding the shared security model
Document systems architecture, configuration & deployment plans with security aspects in mind
Directly contribute to security documentation (System Security Plan (SSP), FIPS 199 Criticality Assessment, FIPS 200 Control Tailoring, Configuration Management Plan (CMP), System Contingency Plan (CP), Business Impact Assessment (BIA), Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), Plans of Action and Milestones (POA&M)) IAW customer directives (e.g. NIST, NOAA/DOC) throughout the information system's A&A lifecycle
Support all Assessment & Authorization (A&A) activities
Draft and maintain Acceptance of Risk(s) documentation, and perform routine vulnerability/risk assessment analysis
Identify vulnerabilities, risks, and protection measures as it relates to information systems
Update system-level policies and assist in developing procedures that meet Federal IT security requirements
Assess new technologies and advise how to correctly implement security controls using those tools per NIST guidelines and cloud best practices
Achieve Control compliance with supporting artifacts and conduct gap analysis of security controls
Ensure IT systems have all security controls in place and functioning properly in accordance with NIST 800-53A publication
Conduct and evaluate/analyze vulnerability results from the following set of tools to include but not limited to: NESSUS/TenableSecurity Center, CSAM, Arcsight, BigFix, and WebInspect
Demonstrate understanding of the Federal Authority to Operate (ATO) process
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
BS/BA in relevant field, or equivalent experience
5+ years of relevant experience
Federal IT system cybersecurity experience
CISSP, GIAC certifications, CISA, CISM, SEC+, or a similar certification
Knowledge of TCP/IP networking, SMTP, HTTP, load-balancers and VPC’s
Experience with centralizing, querying, and setting up alerts based off AWS CloudTrail, AWS Config, and VPC Flow Logs
Familiar with enterprise cybersecurity architecture and its data collection points, as it relates to incident response and investigations (antivirus, firewalls, email gateways, DNS, web and content filtering proxies, logging infrastructure, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Security Event Information Management Systems (SEIMS), etc.)
Experience with CSAM, Tenable Security Center, Nessus, etc.
Ability to analyze and understand cyber threat actor capabilities and intentions, methodologies, methods, and motives
Ability to perform threat vector risk assessments
Ability to interact with other staff and senior Federal employees – technical and non-technical personnel
Ability to manage multiple tasks in a fast-paced environment
Possess a positive and self-motivating attitude
Excellent written, verbal, and analytical skills
Must have, or be able to, pass a US Government Background Investigation (this is a non-cleared position)
Must be a U.S. citizen
Benefits
Medical, vision, dental, life, and disability coverage
401(k) w/ matching contribution up to 3%
Education/professional development assistance
Competitive PTO w/ additional company paid Holidays
Remote office technology assistance
Company
L2 Cyber Solutions
L2 Cyber Solutions is an information technology company that providing process engineering; cybersecurity services.
Funding
Current Stage
Early StageCompany data provided by crunchbase