Della Infotech
Cyber Security Specialist
Della Infotech, New York, New York, us, 10261
Job Title: Cyber Security Specialist
Duration: 13 months(35 hrs per week)
Location: Brooklyn, NY(Day 1 onsite)
SCOPE OF SERVICES
Ensure security policies such as CJIS are in compliance throughout the design and build phase.
Engage in working session with the ESINET, GIS and L&R vendors on detail designs and provide input to their proposed solutions.
Provide Next Gen firewall architecture designs, configurations.
Provide expert Information Security firewall architecture vision, leadership, analytical guidance/process and security controls.
Implement cutting edge enterprise security solutions such as NGFW infrastructure; DNS/DNSSEC; enterprise MFA and NGFW infrastructure; and Data Loss Prevention (DLP) technology. Manage the internal Security Solutioning & BOM process from Intake to implementation.
Evaluate the overall solution to ensure it is CJIS compliance.
Research, evaluate, test, recommend the implementation of new or updated information security hardware or software, and analyze its impact on the existing environment.
Provide technical and expertise guidance for the deployment of security tools.
SKILLS
Assessing and providing strategic direction for resolution of mission-critical problems, policies, and procedures.
At least 12 years of IT security experience of which a minimum of three years must be in a senior position.
BS/BA undergraduate degree.
Determining and implementing cybersecurity and privacy principles to organizational requirements.
Experience building defensible security architectures for operational technology with a focus in cloud security best practices
Experience developing disaster recovery and continuity of operations policies, plans, and procedures.
Experience developing incident response process and procedures with internal and external stakeholders.
Experience with defining, establishing and directing techniques for detecting host and network-based intrusions using intrusion detection technologies
Knowledge of anti-forensics tactics, techniques, and procedures.
Knowledge of applicable laws, statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code)
Knowledge of DDoS appliances such as NetScout Arbor, Fortinet FortiGate.
Knowledge of Insider Threat investigations, reporting, investigative tools and laws/regulations
Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
Knowledge of legal governance related to admissibility (e.g. Rules of Evidence).
Knowledge of malware analysis tools (e.g., Oily Debug, Ida Pro).
Knowledge of malware with virtual machine detection.
Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth)
Knowledge of NIST's Cybersecurity Framework (CSF) with a focus on response and recover control families.
Knowledge of processes for seizing and preserving digital evidence.
Knowledge of system and application security threats and vulnerabilities.
Knowledge of types of digital forensics data and how to recognize them.
Overseeing and interfacing directly with agency and interagency leaders during cyber incidents.
Strong background in documenting and assessing NIST 800-53 and CJIS controls.
Strong understanding of vulnerability scanning solutions, and the ability to clearly document the associated risks and remediation timelines.
Valid CISSP Certification
Writing business/process documentation, developing models and graphics and making oral presentations to senior officials
Duration: 13 months(35 hrs per week)
Location: Brooklyn, NY(Day 1 onsite)
SCOPE OF SERVICES
Ensure security policies such as CJIS are in compliance throughout the design and build phase.
Engage in working session with the ESINET, GIS and L&R vendors on detail designs and provide input to their proposed solutions.
Provide Next Gen firewall architecture designs, configurations.
Provide expert Information Security firewall architecture vision, leadership, analytical guidance/process and security controls.
Implement cutting edge enterprise security solutions such as NGFW infrastructure; DNS/DNSSEC; enterprise MFA and NGFW infrastructure; and Data Loss Prevention (DLP) technology. Manage the internal Security Solutioning & BOM process from Intake to implementation.
Evaluate the overall solution to ensure it is CJIS compliance.
Research, evaluate, test, recommend the implementation of new or updated information security hardware or software, and analyze its impact on the existing environment.
Provide technical and expertise guidance for the deployment of security tools.
SKILLS
Assessing and providing strategic direction for resolution of mission-critical problems, policies, and procedures.
At least 12 years of IT security experience of which a minimum of three years must be in a senior position.
BS/BA undergraduate degree.
Determining and implementing cybersecurity and privacy principles to organizational requirements.
Experience building defensible security architectures for operational technology with a focus in cloud security best practices
Experience developing disaster recovery and continuity of operations policies, plans, and procedures.
Experience developing incident response process and procedures with internal and external stakeholders.
Experience with defining, establishing and directing techniques for detecting host and network-based intrusions using intrusion detection technologies
Knowledge of anti-forensics tactics, techniques, and procedures.
Knowledge of applicable laws, statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code)
Knowledge of DDoS appliances such as NetScout Arbor, Fortinet FortiGate.
Knowledge of Insider Threat investigations, reporting, investigative tools and laws/regulations
Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
Knowledge of legal governance related to admissibility (e.g. Rules of Evidence).
Knowledge of malware analysis tools (e.g., Oily Debug, Ida Pro).
Knowledge of malware with virtual machine detection.
Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth)
Knowledge of NIST's Cybersecurity Framework (CSF) with a focus on response and recover control families.
Knowledge of processes for seizing and preserving digital evidence.
Knowledge of system and application security threats and vulnerabilities.
Knowledge of types of digital forensics data and how to recognize them.
Overseeing and interfacing directly with agency and interagency leaders during cyber incidents.
Strong background in documenting and assessing NIST 800-53 and CJIS controls.
Strong understanding of vulnerability scanning solutions, and the ability to clearly document the associated risks and remediation timelines.
Valid CISSP Certification
Writing business/process documentation, developing models and graphics and making oral presentations to senior officials