These are the requirements for the Lead/Senior Cybersecurity Engineer & A&A Assessor position:
Core Responsibilities:
- Partner with System POCs to design, validate, and harden system architectures (on-prem, cloud, hybrid).
- Develop and maintain system boundary definitions, segmentation plans, and firewall/segmentation controls.
- Define and enforce least-privilege access models across roles (OS, application, database, service accounts).
- Lead encryption strategies (data in transit, data at rest — file, database, backup) and key management.
- Design and validate logging, monitoring, SIEM event coverage (including M-21-31-relevant audit events).
- Oversee vulnerability scanning (internal/external), interpret results, and guide remediation.
- Document System Security Plans (SSP) by interviewing POCs, collecting artifacts, and walking through configurations.
- Participate in independent assessments: evidence collection, demos, walkthroughs of security controls.
- Conduct Business Impact Analyses (BIAs), Continuity Plans (CP), and participate in CP testing.
- Provide guidance on cloud IAM, hardening (e.g., CIS, STIG), and cloud-native logging (e.g., CloudTrail, Audit Logs).
Qualifications / Required Background:
- Deep technical understanding of network segmentation, protocols, ports, services.
- Experience with OS hardening (Linux, Windows) using CIS Benchmarks or STIGs.
- Experience with database security (hardening, encryption, audit logging, least privilege).
- Strong cloud security architecture experience (SaaS, IaaS, PaaS), especially around IAM, logging, and monitoring.
- Hands-on with vulnerability scanning, SIEM tools, and security event audit.
- Experience writing security documentation (System Security Plans) and working with assessors.
Company Description
NetSecurity, a leader in endpoint threat protection, vulnerability detection, and forensics investigations, seeks an "SA&A Analyst" or "Lead SA&Analyst."
Our game-changing ThreatResponder® Platform is an all-in-one cloud-native and machine learning powered innovation that helps organizations detect, prevent, respond to, hunt, and forensically investigate sophisticated cyber attacks, data breaches, and insider threats. NetSecurity is based in Reston, VA.