Key Responsibilities:
- Assist with various assessments via mock interviews, participation in assessment activities and collection of evidence
- Assist with Continuous Monitoring via review of scans, identification of vulnerabilities, tracking of remediation and interaction with various teams on recommended mitigation / remediation
- Providing a QA function for security components of product builds
- Leverage security tooling and reporting to ensure technical security findings are addressed and corrected. Coordinate with Build and Operations teams to ensure security tooling and logging are in place
- Participate in overall security activities such as process improvement, ticket review and response
Minimum Qualifications:
- BS degree in Computer Science, MIS, Computer Engineering, or similar field, and 5-8+ years of technology experiences – or additional years of technology experiences in lieu of a BS degree
- 2+ years’ experience with security assessments of various frameworks such as FedRAMP, SOC, HIPAA, and ISO
- 2+ years’ experience with remediation of findings and vulnerabilities that are identified through assessment, scanning or penetration testing, including experience with analysis of scan results, Plan of Actions and Milestones, response to assessment findings, etc.
- 2+ years’ experience with Linux/Unix system administration, tools and architecture
- 2+ years’ experience with cloud applications and cloud SaaS architecture (web/app/db) on a variety of hyperscalers (AWS/Azure/GCP)
Preferred Qualifications
- 2+ years’ experience implementing and operationalizing security tools across a variety of applications and hyperscalers
- Demonstrated experiences logging into Windows and Linux systems to pull audit evidence, and troubleshooting and remediating security findings
- Effective communication and collaboration skills – experience working with other teams and customers on security challenges, assessment readiness, Continuous Monitoring tooling, vulnerabilities and remediations
- Continuous learning mindset to stay current with the tools and the rapidly evolving cyber threat landscape
- Motivated with a positive attitude and a strong bias towards taking corrective action and providing resolutions
Candidates with the following relevant certifications and experience will be given preferential consideration:
- Understanding of existing products and management workloads in the NS2 Cloud environment
- Experience / certifications in cyber and security concepts (Security+, ISC2 CC, ISC2 CISSP, etc.), focusing on documentation, assessments and/or continuous monitoring
- Red Hat Certified Systems Administrator
- Red Hat Certified Systems Engineer
- CrowdStrike experience / certifications
- AWS/Azure/GCP hyperscaler experience / certifications
- Prior DOD/FedRAMP experience
We win with inclusion
Washington DCJob Segment:Cloud, Open Source, ERP, Testing, Systems Engineer, Technology, Engineering