- Esperienza
- Qualsiasi
- Stipendio
- —
- Aperture
- 1
- Pubblicato
- 10 ore fa
- Modalità di lavoro
- Lavoro da casa
- Riprendere
- È necessario candidarsi
Descrizione del lavoro
About the Role
We are seeking a meticulous Cybersecurity Engineering Analyst to support remote Engineering Services, primarily aligned with CST or PST time zones. The ideal candidate must possess FedRAMP certification and have direct experience implementing FedRAMP controls, preferably on federal projects. This position demands solid organizational skills, a foundational grasp of security principles, and excellent communication capabilities.
Key Responsibilities
- Manage Privileged Access Management (PAM) platforms including Delinea's Thycotic Secret Server and BeyondTrust.
- Maintain proficiency with Active Directory, networking, and identity lifecycle management for both privileged and standard user accounts.
- Conduct vulnerability management leveraging tools such as Tenable and Wiz, performing routine scans that include PCI Compliance, web application, attack surface, and identity exposure assessments.
- Coordinate remediation activities with asset owners based on findings from Tenable, Wiz, and other sources.
- Support digital certificate processes with a fundamental understanding of certificate management principles.
- Perform privileged access and account termination reviews using tools like Google Sheets with mail merge and VLOOKUP, alongside knowledge of Active Directory structures.
- Address critical and high-severity security issues identified via Security Scorecard reports, including ransomware detection, exposure of services like DB or RDP, expired certificates, vulnerable software protocols, and more.
- Engage in incident detection and response efforts targeting ransomware, phishing, malware infections, and other security threats.
Requirements
- FedRAMP certification along with hands-on experience in FedRAMP implementation and compliance scanning.
- Extensive expertise in Privileged Access Management tools, specifically Delinea's Thycotic Secret Server and BeyondTrust.
- Strong knowledge of Active Directory, networking concepts, and identity lifecycle management.
- Experience with vulnerability scanners like Tenable and Wiz and conducting PCI Compliance-related scans.
- Familiarity with digital certificate management concepts.
- Competency in access review processes, using spreadsheet tools and Active Directory data for account validations.
- Experience interpreting and mitigating Security Scorecard's categorized issues ranging from critical to medium/low severity.
- Experience working on federal cybersecurity projects is required.
- Excellent organizational skills and an ability to work independently and collaborate effectively in teams.
Additional Information
This remote position demands availability during Central or Pacific Standard times to support project requirements. The role offers the chance to directly impact the cybersecurity maturity and resilience of a global technology enterprise by ensuring ongoing compliance and robust defense against advanced threats.