Designs, tests, and implements secure operating systems, networks, security monitoring, tuning and management of I.T. security systems and applications, incident response, digital forensics, loss prevention, and eDiscovery actions.
Conducts risk and vulnerability assessment at the network, system, and application level. Conducts threat modeling exercises.
Develops and implements security controls and formulates operational risk mitigations along with assisting in security awareness programs.
Involved in a wide range of security issues, including architectures, firewalls, electronic data traffic, and network access.
Researches, evaluates, and recommends new security tools, techniques, and technologies and introduces them to the enterprise in alignment with the I.T. security strategy.
Utilizes c and custom tools and processes / procedures to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions.
Assists in implementing the required government policy (i.e., NISPOM, DCID 6 / 3) and makes recommendations on process tailoring. Performs analyses to validate established security requirements and to recommend additional security requirements and safeguards.
Supports the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
Periodically conducts a review of each system s audits
and monitors corrective actions until all actions are closed.
Periodically conducts a review of each system s audits and monitors corrective actions until all actions are closed.
May support cyber metrics development, maintenance, and reporting. May provide briefings to senior staff. Utilizes COTS / GOTS and custom tools and processes / procedures to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions.
Assists in implementing the required government policy (i.e., NISPOM, DCID 6 / 3) and makes recommendations on process tailoring. Performs analyses to validate established security requirements and to recommend additional security requirements and safeguards.
Supports the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
May support cyber metrics development, maintenance, and reporting.