Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailWEEKENDS AND HOLIDAYS CONTRACTOR POSITIONS SCOPE AND KNOWLEDGE/SKILLS/ABILITIES
Scope Of Work:
No. 1
40% Security Operations and Network Operations (SOC):
Responsible for the Weekends and HolidaysMidnight to Noon (12:00 AM 12:00 PM) and two weekdays 12:00 AM 9:00 AM. Specifically Fri & Mon 12AM 9AMSat & Sun Holidays 12AM noon. Additionally weekly team meeting on Mon at 9AM.
Assist in maintaining the NCAOC SecurityOperations Center security posture.
Responsible on Weekends and Holidays to respondto Network Operations Center priority one circuit outages.
Responsible for creating triaging updatingand seeing closure of Security Operations Incident Request and EnterpriseChange Management tickets.
Monitors and maintains Firewalls andcorresponding management tools (FMC ASDM) Intrusion Prevention Systems (IPS)Vulnerability Management (VM) Cisco Umbrella domain name security ISE networkAccess Control Posturing and Profiling IPsec VPN tunnels AnyConnect remoteusers and security module Third Party Partner Security Incident and EventManager (SIEM) and other network and cloud security tools.
Use tools (Wireshark and interface captures andlog searching) to assist in troubleshooting network device configuration and networksecurity related problems.
Responsible for firewall cleanup processestasks and learning firewall tools to assist in performing these processes andtasks.
Follow and maintain SOC process and technologydocumentation.
Open and work to closure vendor TAC casesmostly Cisco to resolve incidents and device issues.
Provide reports and metrics for the SOCSupervisor or Operations and Administration Manager as requested.
Interface with all other TSD technical teams ininitiatives and activities the require Security Operations Center resources.
No. 2
20% Network Security and Cybersecurity:
Monitor and respond to Third Party Partnerinitiated security investigations.
Provide support of the established IncidentResponse Policy from beginning preparation and prevention through postincidentactivity.
Subscribe to and monitor Security ProductAdvisories and Cybersecurity Organization Bulletins researching and ensuringcoverage of security device risks and Common Vulnerability Enumerations (CVE)
Update PSIRT/CVE spreadsheet or other reporttracking mechanism to report progress and coverage of Security ProductAdvisories and Cybersecurity Organization Bulletins.
Monitor and Maintain the IPS signatures Blocklists URL reputation lists and malware file lists to ensure latest securityrecommendations are implemented.
Use monitoring and security diagnostic tools tothreat hunt for network and device vulnerabilities security risks andpotential threats.
Research trends to assist the SecurityOperations team in staying up to date on industry best practices and current Cybersecuritytrends tools techniques and procedures.
No. 3
30% Network Patching Upgrading and Maintenance:
Evaluate plan and implement network devices (switchesrouters management tools etc.) and network security devices and tools(firewalls IPS ISE etc.) upgrades and patches on a monthly and as neededschedule.
Coordinates with various TSD teams in theevaluation planning and implementation of patching upgrading and maintenance.
Update patching spread sheet to reflect historicand current versioning.
Uses software tools to manage patchingupgrading and maintenance of network and security devices (Visio MicrosoftOffice etc.)
No. 4
10% Security Industry and Product Research andTraining
Attend classes seminars webinarsconferences training sites and research product documentation to enhanceprofessional development and to progress in the field of Network andCybersecurity trends and developments.
Use NCAOC provided resources to attain SecurityProfessional Certificates (Ex. Cisco CCNA routing and switching CCNASecurity CCNP Security CISSP)
Knowledge Skills and Abilities:
Knowledge:
Knowledge of enterprise network security technologies:Cisco FTD and ASA firewalls IPS FMC IPsec tunnels AnyConnect client Cisco ISECisco Umbrella Third Party SIEM DDI DNS VLANS NAT Cisco Secure Endpoint(AMP) Load Balancing IP/Domain/URL security intelligence sources (Virus TotalTALOS etc.)
Knowledge and or possession of Security Profession Certificates(Cisco CCNA routing and switching CCNA Security CCNP Security CISSP) ispreferred but not required.
Knowledge of NCAOC security policy and Criminal JusticeInformation System (CJIN) policies is preferred but not required.
Skills:
Skills in enterprise security technology; fundamentalknowledge of the following IPsec IPS/IDS Snort Engine SIEM IdentityServices Engine (ISE) Vulnerability Management Access Control/AAA; networkingfundamentals in the areas of enterprise network topology routers switchesservers NAT DNS; TCP/IP architecture and functionality Wireshark andinterface captures and log searching to assist in troubleshooting configurationand network security related problems.
Abilities:
Ability to plan and manage complex projects independentlyand within a team; communicate effectively with users to determine and resolveproblems; communicate technical information to lay persons; interpret andfollow established employment and policies; produce highly technical documents;consider the implications of new technology implementations; balance theapplication and system access business needs of users with network securityprotections.
Full Time