Washington, District of Columbia, United States
OVERVIEW: Are you looking for an ambitious new work environment to test & enhance your skills? Have you ever wanted to work for a company where you felt like part of a family? Are you interested in joining an amazing technical team?
phia, LLC is seeking a highly skilled Cybersecurity Engineer to join our team of qualified, diverse individuals supporting the U.S. Department of Energy (DOE). DOE is responsible for the protection of vital national security information and technologies, representing intellectual property of incalculable value throughout nearly thirty sites and laboratories nationwide. This position is located in Washington, D.C. and requires an active DOE Q SCI. Current Pandemic rotating schedule one week onsite; two weeks offsite.
- Develop derived requirements for Information Assurance Services (Confidentiality, Integrity, Nonrepudiation, and Availability), Basic Information Assurance mechanisms (e.g., Identification, Authentication, Access Control, Accountability) and Security Mechanism Technology (Passwords, cryptography, discretionary access control, mandatory access control, hashing, key management, etc.).
- Code and work API integration using python, Java, etc.
- Apply a broad understanding of monitoring, analyzing, detecting, and responding to cyber events and incidents within information systems and networks.
- Manage system requirements and derived requirements to ensure the delivery of production systems that are secure and compatible with the defined system architectures.
- Work with a variety cyber defense and IT tools such as: Splunk, ElasticSearch, MISP, FireEye, Cisco Sourcefire, Palo Alto firewalls, Tanium, Snort, Bro, SolarWinds, Apache NiFi, and RedSeal.
- Advise on an integrated, dynamic cyber defense and leverages cyber security solutions to deliver cyber security operational services such as: intrusion detection and prevention (IDPS), situational awareness of network intrusions, security events and data spillage and incident response (IR) actions.
- Test, implement, deploy, and operate, the infrastructure hardware and software which are required to effectively manage the organization’s cyber security operational services.
- Install operate maintain cybersecurity systems, tools, and integrate data from sources.
- Apply/integrate cybersecurity engineering principles into infrastructure planning, design, and deployment.
- Lead or participate in an Integrated Product Team review to ensure security architecture integration.
- Generate alternative system concepts, physical architectures, security architectures and design solutions.
- BA/BS in Computer Science, Information Technology, Information Security, or a related field or equivalent experience (two years of experience for each year of schooling).
- 6-12+ years of experience working in the areas of IT, systems administration, engineering, architecture, cyber, intelligence, information security, hunt, cyber operations, network forensics, insider threat, etc.
- Active Top Secret or Q clearance with an investigation within the last 5 years (sponsorship opportunities available for highly qualified candidates)
- Experience with coding in python, PowerShell, shell scripting, RESTful API, etc.
- Possess engineering and architecture skills to make efficient advisement for systems requirements.
- Experience providing full system’s lifecycle (design, testing, implementation, operations, maintenance and disposal) support for commercial and open-source tools
- Excellent knowledge of a wide variety of security solutions and technologies, including Linux, network architecture/implementation/configuration experience, firewall technologies, proxy technologies, anti-virus, spam and spyware solutions (gateway and SaaS), malware/security experience
- Must be highly motivated with the ability to self-start, prioritize assignments, and work in a collaborative team environment
- CERTIFICATIONS: one or more preferred – GCIH, GCFE, RHCE, CPTE, or CEH.
- MA/MS in computer science, information security, or a related field or equivalent experience.
- Preferred background with knowledge in incident response with experience in threat analysis.
- Knowledge and understanding of the MITRE ATT&CK framework with associated tactics, techniques and tools for attack method types and their usage in targeted attacks such as phishing, malware implantation, perimeter vulnerabilities, application vulnerabilities, lateral movement, etc.
WORK SCHEDULE: Core Hours (8am-5pm; start/end time flexible)
WORK LOCATION: Washington, D.C.
TRAVEL: < 5%
TELEWORK ELIGIBILITY: Pandemic rotating schedule one week onsite; two weeks offsite; normal operations ad-hoc with approval
SECURITY REQUIREMENTS: DOE Q Clearance / DoD Top Secret; Current SCI required. Must have had a valid investigation within last 5 years
phia LLC ("phia") is a Northern Virginia based, 8a certified small business established in 2011 with focus in Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, Information Assurance/Security, Compliance, Certification & Accreditation, Communications Security, Traditional Security, and Facilities Security. phia also provides cyber operations support functions such as: Program and Process Management, Engineering, Development, and Systems Administration that allows for Cyber Operations to efficiently integrate our customer’s missions and objectives. phia supports various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.
phia offers excellent benefits for full time W2 candidates to enhance the work-life balance, these include the following:
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Life Insurance
- Short Term & Long-Term Disability
- 401k Retirement Savings Plan with Company Match
- Paid Holidays
- Paid Time Off (PTO)
- Tuition and Professional Development Assistance
- Flex Spending Accounts (FSA)
- Parking Reimbursement
- Monthly Payroll