About the Role
This role is for our client in the cybersecurity sector. The successful candidate will work in a dynamic environment, supporting the agency's cybersecurity and data protection operations. The focus will be on DLP, Insider Risk Management, Copilot/AI data security, auditing, vendor security reviews, and device patching. The ideal candidate will have 3-5+ years of experience supporting enterprise cybersecurity operations, including threat monitoring, incident response, and risk analysis.
Key Responsibilities
- Analyze and respond to security incidents in a timely and effective manner.
- Monitor and report on security threats, vulnerabilities, and compliance issues.
- Develop and implement security policies, procedures, and standards.
- Conduct regular security audits and risk assessments.
- Collaborate with cross-functional teams to ensure security is integrated into all aspects of the organization.
- Stay up-to-date with emerging security threats and technologies.
- Develop and maintain relationships with vendors and partners to ensure security is integrated into their products and services.
- Provide training and awareness programs to employees on security best practices.
- Develop and implement incident response plans and procedures.
- Collaborate with law enforcement and other agencies to respond to security incidents.
Required Skills & Experience
- 3-5+ years of experience supporting enterprise cybersecurity operations, including threat monitoring, incident response, and risk analysis.
- Strong knowledge of security frameworks, regulations, and standards.
- Experience with security information and event management (SIEM) systems.
- Knowledge of cloud security, including AWS and Azure.
- Experience with security orchestration, automation, and response (SOAR) tools.
- Strong analytical and problem-solving skills.
- Excellent communication and collaboration skills.
- Ability to work in a fast-paced environment and prioritize multiple tasks.
Tools & Technologies
- SIEM systems (e.g. Splunk, ELK).
- Cloud security platforms (e.g. AWS, Azure).
- SOAR tools (e.g. Phantom, Demisto).
- Security frameworks and regulations (e.g. NIST, HIPAA).
- Incident response and management tools (e.g. IRMA, Splunk).
Work Schedule & Duration
- Duration of the Contract: 12 months.
- Possibility for Extension: Yes.
- Work Location: Hybrid (3 days in office, 2 days remote).
Interview Process
The process typically includes an initial screening followed by a technical/panel interview via Teams.
Position Details
- Employment Type: Contract
- Duration: Approximately 12 months (with potential for extension)
- Work Authorization: Must be authorized to work in the United States