Full-Time Senior Cybersecurity Engineer – Senior Cybersecurity Engineer
Job Description
GENERAL PURPOSE:
Under general direction, performs at a senior professional level supporting the operation of the technical controls outlined by the Agency’s Information Security Program for its corporate IT infrastructure; evaluates, designs, builds, and documents security solutions; evaluates proposed projects and activities to identify information security risks and available mitigating controls; evaluates systems for compliance with internal policies and standards, as well as applicable regulatory frameworks, recommending solutions to address any gaps; and acts as primary handler in the execution of the incident response plan for IT.
ESSENTIAL FUNCTIONS:
The following duties are a representative summary of the primary duties and responsibilities. Incumbent(s) may not be required to perform all duties listed and may be required to perform additional, position-specific duties.
• Identifies and assesses technology-related risks to information security associated with current and prospective technology solutions; and recommends appropriate mitigating controls.
• Develops technical standards to interpret and implement applicable information security policies and controls; evaluates any prospective technology solution for adherence to documented company standards, policies, and regulatory responsibilities.
• Collaborates with other IT engineering and administration disciplines to ensure security best practices are incorporated into design, implementation, and sustainment of systems and services within the enterprise.
• Assesses and classifies any identified system vulnerabilities in accordance with pre-defined risk criteria; advises and consults with internal customers on risk assessment, threat modeling, and mitigation of vulnerabilities.
• Develops Incident Response dashboard and metrics; leads information security incident investigation and response efforts; conducts computer and network forensic investigations in support of incident response activities; performs root‐cause analysis when incidents occur and prepare incident reports.
• Evaluates, implements, and supports security-focused tools and services required to support information security controls.
• Assists in promoting a culture of information security at Sound Transit.
• Conducts regular security reviews of both software and processes. Reviews and creates threat models and recommends security enhancements consistent with information security strategy and evolving threats.
• Interacts with penetration testers and other external vendors as needed.
• Keeps up to date on latest information security trends, “best practices”, threats, and countermeasures.
• Reviews log-based data, both in raw form and utilizing SIEM or aggregation tools.
• Champions and models Sound Transit’s core values and demonstrates values-based behaviors in everyday interactions across the agency.
• Contributes to a culture of diversity, equity and inclusion in alignment with Sound Transit’s Equity & Inclusion Policy.
• It is the responsibility of all employees to follow the Agency safety rules, regulations, and procedures pertaining to their assigned duties and responsibilities, which could include systems, operations, and/or other employees.
• It is the responsibility of all employees to integrate sustainability into everyday business practices.
• Other duties as assigned.
MINIMUM QUALIFICATIONS:
Education and Experience:
Bachelors Degree in computer science, information technology, business management information systems, five years of information systems security (or cyber security) experience, or closely related field; OR an equivalent combination of education and experience.
Preferred Licenses or Certifications:
• Certified Information Systems Security Professional (CISSP), or ability to obtain certification within 12 months of hiring.
• Preferred Certifications: CEH, CCFP, GCIH (or other GIAC), CCSP, or others that are considered field-relevant.
Required Knowledge and Skills:
• Experience with the application of threat modeling or other risk identification techniques.
• Working understanding of Operating System architecture as it relates to the functions of the following components: OS kernel, OS kernel modules and device drivers, memory management, inter-process communication, security subsystem, user account rights, user group rights, system logs, I/O functions, network services, file-system permissions, and application interaction with the Operating System.
• Strong understanding of Microsoft OS (Server and Workstation) products.
• Technical skills proficiency in the following areas: security information event management, network protocols (e.g. TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols), system administration, malware (propagation, infection, types), intermediate knowledge of network security controls and technologies (proxy, firewall, IDS/IPS, router/switch, open source information collection platforms), cryptography, and Microsoft Active Directory.
• Deep knowledge of security operations: perimeter defense, forensics, incident response, kill chain analysis, risk assessment, and security metrics.
• Strong understanding of internet-facing, web applications.
• Relevant experience and detailed technical knowledge in security engineering, system and network security, authentication and security protocols, and cryptography.
• Good knowledge of information security incident handling and investigation procedures.
• Demonstrated skills in conducting forensic analysis of digital evidence, network traffic, managing event analysis/correlation, and related incident investigations.
• In-depth knowledge of security software threats and vulnerability mitigation techniques.
• Working understanding of cloud platforms (Azure, AWS).
• Working knowledge of risk-based methodologies and one or more of the following frameworks: ISO 27001/2:2013, PCI-DSS, or NIST 800-53.
• Scripting skills (e.g., PowerShell) are desirable.
• Project management practices and principles.
• Principles of business letter writing and basic report preparation.
• English usage, spelling, grammar, and punctuation.
• Modern office procedures, methods, and equipment including computers and computer applications such as word processing, spreadsheets, and statistical databases.
• Lead/supervisory principles, methods, and techniques.
• Establishing and maintaining effective working relationships with other department staff, management, vendors, and other stakeholders.
• Documenting and explaining risks, recommendations, and incident data to technical stakeholders.
• Interpreting and administering information security policies, standards, and procedures sufficiently to administer, discuss, resolve, and explain them to staff and other constituencies.
• Generating metrics and preparing reports to facilitate decision-making on security-related activities.
• Utilizing personal computer software programs affecting assigned work and in compiling and preparing spreadsheets and reports.
• Preparing and analyzing complex data and comprehensive reports.
• Writing of technical documentation and standards.
• Responding to inquiries and in effective oral and written communication.
• Researching, analyzing, and evaluating new security processes, products, and techniques.
• Candidate should have excellent time management skills including the ability to prepare, prioritize, and complete work plans.
• Ability to work effectively and organize priorities independently.
• Results oriented, highly organized, proactive, and self-motivated.
• Working effectively under pressure, meeting deadlines, and adjusting to changing priorities.
• Researching, analyzing, and evaluating new service delivery methods and techniques.
• Working cooperatively with other departments, Agency officials, and outside agencies.
Physical Demands / Work Environment:
• Work is performed in a standard office environment.
• Subject to standing, walking, bending, reaching, stooping, and lifting of objects up to 25 pounds.
• The Agency promotes a safe and healthy work environment and provides appropriate safety and equipment training for all personnel as required.
Sound Transit is an equal employment opportunity employer. No person is unlawfully excluded from employment action based on race, color, religion, national origin, sex (including gender identity, sexual orientation and pregnancy), age, genetic information, disability, veteran status or other protected class.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)
How to Apply
To apply, please visit the link below or visit soundtransit.org/get-to-know-us/jobs and click on "current job listings". https://recruiting.ultipro.com/SOU1036SOUND/JobBoard/dcc5dbea-875e-4cd1-bfd2-8e046cecc54f/OpportunityDetail?opportunityId=2813341f-b1b5-4a94-ba70-b93a890c52e4can340 total views, 0 today