Logo
IBM

Cybersecurity Engineer

IBM, Hampton, Virginia, United States, 23661


IntroductionA career in IBM Consulting is rooted by long-term relationships and close collaboration with clients across the globe. You'll work with visionaries across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. Your ability to accelerate impact and make meaningful change for your clients is enabled by our strategic partner ecosystem and our robust technology platforms across the IBM portfolio; including Software and Red Hat. Curiosity and a constant quest for knowledge serve as the foundation to success in IBM Consulting. In your role, you'll be encouraged to challenge the norm, investigate ideas outside of your role, and come up with creative solutions resulting in groundbreaking impact for a wide network of clients. Our culture of evolution and empathy centers on long-term career growth and development opportunities in an environment that embraces your unique skills and experience.

Your Role and ResponsibilitiesPosition Location: Radford, VA or Ft. Belvoir (5 days per week)*** This position requires a Secret Security clearance or higher (US Citizenship is required) ***

As part of the Cybersecurity Division - Cyber Incident Response Team, deploy, install, manage, and operate Security Information and Event Management (SIEM) solutions to include Splunk and/or Elasticsearch.Responsible for assessment of threats and vulnerabilities to organizational computing assets and developing/integrating rules, queries, and filtering techniques to produce meaningful risk analysis for responses.Coordinate with team to ensure all devices and components report all relevant logs to the SIEM solution and perform troubleshooting and maintenance of assets.Monitor DoD and Army web application security standards and best practices as well as reported/disclosed vulnerabilities. Work with internal and external customers to track, remediate, and report compliance for disclosed vulnerabilities.Work with a team to review Army Cyber Tasking Orders (CTOs), determine applicability and response, and incorporate required changes.Validate technical security controls are in place for operating systems, applications, and network appliances, and recommend enhancements.Review proposed SIEM configuration changes for security impact.Work with technical and policy teams to implement, maintain, and monitor technical security configuration controls, including: STIGs, SRGs, and other industry security hardening guidance.Collaborate with internal and external parties to transform high-level technical objectives into comprehensive technical requirements.Interact with Army Cyber Security Service Providers and customer ISSOs/ISSMs on a regular basis.

Required Technical and Professional ExpertiseRequired Skills:Extensive experience implementing, tuning, and monitoring SIEM rulesets.Experience working with auditors, customers, and other stakeholders to develop meaningful alerts, dashboards, and reports.Strong understanding of common cyber threat patterns, indicators of compromise, and defenses.Strong understanding of Linux (preferred) and Windows Operating Systems.Working knowledge of DoD STIGs, and IA Vulnerability Management (IAVM).Strong verbal and written communication skills.Ability to work cooperatively as a member of a team.Ability to interpret and apply rules, regulations, and procedures.Ability to gather, analyze, and present facts.Basic understanding of DOD Risk Management Framework Assessment & Authorization (RMF A&A).Experience automating routine administrative tasks desired.Understanding of network, storage, server, and application technologies.

*** This position requires a Secret Security clearance or higher (US Citizenship is required) ***Required Certifications:DoD 8570.01-M IAT level II certification is required.

#J-18808-Ljbffr