CISSP Certified Cyber Security Engineer

at Universal Technologies
Published May 25, 2023
Location Brooklyn, NY
Category Default  
Job Type Full-time  

Description

UNIVERSAL Technologies is seeking a CISSP Certified Cyber Security Engineerfor a one-year position in Brooklyn, NY. Applicants should be prepared for 100% onsite work in Brooklyn, NY.

Position: The selected candidate will play a key role in ensuring Cyber Security for the City of New York’s initiative to implement new technologies for the emergency 9-1-1 call answering system. Qualified candidate will have experience developing and implementing cybersecurity policies, documenting and assessing NIST framework and CJIS controls with hands on Cyber Security Firewall engineering experience.

WHO WE ARE:

UNIVERSAL Technologies, LLC is a Women-Owned (M/WBE) IT solutions and consulting company focused at delivering enterprise systems that significantly improve our clients IT performance. We work across the IT spectrum including Development, Business/Systems/Data Analysis, Project Management, Cyber Security, Network Engineering, and High-Level System Architecture.

The pride in the services we provide and the accessibility and flexibility we provide to employees are what make Universal Technologies stand out from the rest! We hope to propel your IT career to the next level and excite our employees with new and challenging projects.

WHAT WE OFFER:

Our W2 employees can expect the following benefits:

  • Competitive pay

  • Health/Dental Insurance

  • Group Life Insurance

  • 401K

  • HSA/FSA

  • Pre-Tax Transportation Program

  • Generous Paid Time Off/Holiday Policy

MANDATORY SKILLS/EXPERIENCE:

  • At least 12 years of IT security experience of which a minimum of three years must be in a senior position.

  • Determining and implementing cybersecurity and privacy principles to organizational requirements.

  • Strong background in documenting and assessing NIST 800-53 and CJIS controls.

  • Experience developing incident response process and procedures with internal and external stakeholders.

  • Knowledge of processes for seizing and preserving digital evidence.

  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth)

  • Knowledge of system and application security threats and vulnerabilities.

  • BS/BA undergraduate degree

  • Experience building defensible security architectures for operational technology with a focus in cloud security best practices

  • Experience with defining, establishing and directing techniques for detecting host and network-based intrusions using intrusion detection technologies

  • Writing business/process documentation, developing models and graphics and making oral presentations to senior officials

  • Overseeing and interfacing directly with agency and interagency leaders during cyber incidents

  • Assessing and providing strategic direction for resolution of mission-critical problems, policies, and procedures.

  • Knowledge of NIST’s Cybersecurity Framework (CSF) with a focus on response and recover control families.

  • Experience developing disaster recovery and continuity of operations policies, plans, and procedures.

  • Strong understanding of vulnerability scanning solutions, and the ability to clearly document the associated risks and remediation timelines.

  • Knowledge of malware with virtual machine detection.

  • Knowledge of anti-forensics tactics, techniques, and procedures.

  • Knowledge of legal governance related to admissibility (e.g. Rules of Evidence).

  • Knowledge of types of digital forensics data and how to recognize them.

  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.

  • Knowledge of applicable laws, statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code)

  • Knowledge of malware analysis tools (e.g., Oily Debug, Ida Pro).

  • Knowledge of DDoS appliances such as NetScout Arbor, Fortinet FortiGate.

  • Knowledge of Insider Threat investigations, reporting, investigative tools and laws/regulations

  • Valid CISSP Certification

SCOPE OF SERVICES:

  • Ensure security policies such as CJIS are in compliance throughout the design and build phase.

  • Engage in working session with the ESINET, GIS and L&R vendors on detail designs and provide input to their proposed solutions.

  • Provide Next Gen firewall architecture designs, configurations.

  • Provide expert Information Security firewall architecture vision, leadership, analytical guidance/process and security controls.

  • Implement cutting edge enterprise security solutions such as NGFW infrastructure; DNS/DNSSEC; enterprise MFA and NGFW infrastructure; and Data Loss Prevention (DLP) technology.

  • Manage the internal Security Solutioning & BOM process from Intake to implementation.

  • Evaluate the overall solution to ensure it is CJIS compliance.

  • Research, evaluate, test, recommend the implementation of new or updated information security hardware or software, and analyze its impact on the existing environment.

  • Provide technical and expertise guidance for the deployment of security tools.

UNIVERSAL Technologies is an Equal Opportunity Employer.

Drop files here browse files ...