Logo
Versar

DHS HSEN – Security Architect (SIEM & SOAR)

Versar, Washington, District of Columbia, us, 20022


Position SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Security Architect (SIEM & SOAR) to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This resource will be a member of a high functioning team of network and security engineers, data center specialists, and stakeholder groups, such as the DHS Network Operations Security Center – Cyber (NOSC-Cyber), ISSOs, and industry vendors, working to continually strengthen and secure HSEN and its data.The candidate’s primary responsibility is to maintain and mature the existing DHS Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solutions, and lead the analysis, integration, and testing of this and new security tools and technologies.This role is eligible for full-time telework.Duties / ResponsibilitiesDesigning, implementing, and maintaining SIEM and SOAR solutions by collaborating effectively with NOSC-Cyber and other key stakeholder groups.Work in partnership with network and security engineers and cloud development teams to drive improvements to security requirements.Research the latest capabilities of SIEM, SOAR platforms and IT technologies (e.g. firewalls, operating systems, networks, storage, virtualization, AD, IPS, Proxies etc.) and be able to present findings to management.Optimize SIEM, SOAR and NOSC-Cyber architecture to improve efficiency and effectiveness of the platforms and processesDesign and implement threat detection, automate incident response processes, integration of various security tools with SIEM and SOAR platforms via APIsMaintain SIEM applications to collect and aggregate IDS and IPS data from network sensors, raw data from collection agents, firewalls, proxy servers, DLP, antivirus, vulnerability scanner elements, and other security‐relevant devicesDesign and document existing production Swimlane environment to include Visio diagrams.Minimum Qualifications / RequirementsAt least six (6) years of professional experience cybersecurity, NOC/SOC environments, and IT Services environment, providing incident responseDemonstrated experience with SIEM and SOAR tool suites, with an emphasis on Swinlane and SplunkDemonstrated experience endpoint security, network security (Firewalls, IPS/IDS, DNS, Proxy, etc.), data and application security, cloud security and technologiesMust be resourceful in learning a very complex and dynamically changing networkMust be a self-starter, able to work independently, and able to manage time effectivelyWorking knowledge of cloud platforms such as AWS, AzureAbility to communicate effectively with all levels of an organization from engineering, operations, and managementU.S. citizenship required and eligibility for a DHS EOD is required to be considered for this position.EducationBA or BS (Cyber Security, Computer Science, Information Systems, Software Engineering, Computer Engineering, or related field); relevant experience may be a substitute for education.Certifications Desired But Not RequiredCertification involving cybersecurityComptia Security+SplunkCISSPCCNP SecurityCCIE SecuritySoftware/Hardware DesiredSplunkSwimlaneKnowledge of at least one programming or scripting language (ex. Python, PowerShell, PHP, Perl)Windows/Linux experience

#J-18808-Ljbffr