Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via email$ 102000 - 170000
1 Vacancy
Job Family:
IT Cyber Security
Travel Required:
Clearance Required:
What You Will Do:
OurSecurity Engineer Lead plays a pivotal role within the Information Security Operations group that is dedicated to supporting Security Operations and Incident Management/Response processes SIEM engineering Threat Hunting Automation Cyber Architecture and Threat Intelligence.
This position is responsible for enhancing SIEM and tool monitoring tuning detection and alerting across multiple domains to support cyber incident response capabilities and tooling with the goal of identifying analyzing and mitigating security threats across the Guidehouse environment to protecting Guidehouse and Client data within systems networks and cloud environments.
You will be mentoring and working with SOC analysts to increase knowledge and skill with detection techniques and other SecOps technologies. You may also participate on IT Security projects to enhance IT Security capabilities improve monitoring coverage drive detection and threat hunting efforts leading to an overall improvement of enterprise cybersecurity posture.
The successful candidate applies technical knowledge and experience to drive innovation and performance improvement while demonstrating critical thinking problem solving and sound logic when assessing problems and opportunities in generating solutions. This position reports to the IT Security Information Protection Associate Director.
Job Function:
Solid understanding of platform network application and cloud security fundamentals threats attack techniques and mitigations
Knowledge of cybersecurity concepts and network/web protocols
Designs and configures monitoring and alerts using SIEM Azure Purview Defender CSPM etc.
Experience with one or more of SIEMs SOAR technologies building/maintaining IR tools and processes programming/scripting threat hunting SIEM detection engineering/tuning.
Demonstrates effective written and verbal communication skills; delivered in a professional respectful and timely manner
Produces high quality work product leveraging existing templates tools and methodologies that align to applicable professional standards and best practices
Clearly and concisely conveys more complex messages to IT Security Operations team; effectively presenting facts and recommendations
Identifies risk issues (e.g. technical client service engagement team internal and external) and escalate them to IT Security supervisors and senior leaders
Helps with issue resolution risk mitigation and contingency planning in alignment with IT Security risk mitigation plans
Uses critical thinking analysis expertise and collaboration to develop technical solutions and solve problems
Works in unstructured or unclear circumstances
Mentor train and guide IT Security technical staff across the organization fostering a culture of technical excellence continuous learning and securityfirst principles.
Promotes the development of new technical knowledge and skills within IT Security Operations team
Takes ownership of tasks resolving issues and escalating as appropriate
Presents themselves and the company in a manner that always promotes a positive lasting impression of high quality promptness and professional service
Draws from experience to propose solutions to meet needs focusing the team accordingly
Builds a high level of trust with stakeholders by meeting and anticipating needs and expectations
Stays current on cybersecurity events trends and issues in the news relevant to IT Security
Can map issues to prescribed IT Security policies procedures and standards determine if they are followed and identifying opportunities for system and process enhancements
Works independently on mid to large or complex projects and assignments with minimal guidance and to influence parties within and outside the job function at an operational level regarding policies best practices and procedures
Strong understanding and ability to apply standards principles theories and technical concepts obtained through learning and experience
What You Will Need:
Bachelors degree with 6 years of experience; OR 10 Years of experience in lieu of degree
United States Citizenship
Must be able to work East Coast US business hours
Experience supporting Microsoft Windows operating systems
Experience supporting Microsoft Azure and M365 cloud environments
Knowledge of the MITRE ATT&CK framework
Experience working with Security Operation Centers physically or virtually
Experience executing processes and procedures in compliance with required NIST and IT standards
Experience using a SIEM such as Splunk or Sentinel to do analysis of security anomalies and events
Experience creating writing queries with Search Processing Language (SPL) or Kusto Query Language (KQL)
Ability to work on many concurrent and changing priorities
Actionoriented and able to manage and meet aggressive timelines and deadlines.
Must have excellent organizational and time management skills
What Would Be Nice To Have:
Experience with AWS and/or Azure cloud services
Degree in computerrelated or cyber field
Working knowledge of NIST SP 800171 NIST 80061 and NIST SP 80053
Experience in one or more of application security security architecture security code reviews security/pentesting cloud security cyber threat intelligence incident response or security infrastructure
Experience interpreting vulnerability scan data and CVEs assessing and responding to vulnerabilities including a foundational understanding of risk management
Assists in conducting risk assessments and security audits to identify vulnerabilities and recommending mitigations to enhance security posture
Demonstrated knowledge of adversary TTPs (Tactics Techniques and Procedures)
Experience working with Executive Leadership
Active US government security clearance (DoE DoD etc..
One or more of the following certifications:
(ISC)2 Certified Information Security Professional (CISSP)
SANs GIAC certification (e.g. GCIH GCFA etc.
OffensiveSecurity Certified Professional (OSCP)
ECCouncil Certified Ethical Hacker (CEH)
CompTIA Security
AWS and/or Azure Cloud
Microsoft Security (Operations Analyst/Engineer/Administrator) Associate
Experience working with firewalls/web application firewalls implementing changes and monitoring status
Experience conducting Incident Response and Security Investigations
Working knowledge of Active Directory Exchange SharePoint and Teams
Demonstrated ability to learn and document new technologies/solutions
Experience with ServiceNow is a plus
Experience working in an ITIL environment
Preference will be given to candidates who are located within 50 miles of a Guide house office.
What We Offer:
Guidehouse offers a comprehensive total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical Rx Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Position may be eligible for a discretionary variable incentive bonus
Parental Leave and Adoption Assistance
401(k) Retirement Plan
Basic Life & Supplemental Life
Health Savings Account Dental/Vision & Dependent Care Flexible Spending Accounts
ShortTerm & LongTerm Disability
Student Loan PayDown
Tuition Reimbursement Personal Development & Learning Opportunities
Skills Development & Certifications
Employee Referral Program
Corporate Sponsored Events & Community Outreach
Emergency BackUp Childcare Program
Mobility Stipend
About Guidehouse
Guidehouse is an Equal Opportunity EmployerProtected Veterans Individuals with Disabilities or any other basis protected by law ordinance or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities or to apply for a position and you require an accommodation please contact Guidehouse Recruiting ator via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @ or . Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse please report the matter to Guidehouses Ethics Hotline. If you want to check the validity of correspondence you have received please contact . Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicants dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
Full-Time