Senior Cyber Security Engineer
Senior
Cyber Security
Cybersecurity Tools
Endpoint Security
Engineer
Identity and Access Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Microsoft Defender For Endpoint
Microsoft Sentinel
Security
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Security Testing
Vulnerability Management
Job Description
ASRC Federal is hiring a Senior Cyber Security Engineer for the Shared Services team supporting enterprise security engineering and operations.
Responsibilities
- Operate and maintain enterprise vulnerability and compliance scanning platforms, including scan policies, repositories, asset groups, credentials, schedules, and reporting.
- Conduct vulnerability assessments, security configuration assessments, and compliance scans to identify, prioritize, and drive remediation of security weaknesses.
- Perform DISA STIG benchmarking, analyze results, execute technical adjudications, and document remediation plans or applicable exceptions.
- Manage and optimize security technologies including EDR/EPP/XDR and SIEM, and remediate gaps across coverage, configuration, logging, and telemetry.
- Investigate and respond to security alerts involving phishing, malicious URLs, malware, credential compromise, suspicious authentication activity, and endpoint threats.
- Act as a Tier II/Tier III escalation point for complex investigations, engineering issues, and cybersecurity incidents.
- Support incident response activities across triage, containment, eradication, recovery, and root cause analysis.
- Maintain a strong understanding of Windows and enterprise infrastructure, including Active Directory, Group Policy Objects (GPOs), permissions, authentication, authorization, and access controls.
- Support security engineering and assessment activities across Microsoft Azure and Microsoft 365, including GCC and GCC High where applicable.
- Develop automation and scripting using PowerShell, Python, or similar technologies for security operations, vulnerability management, assessment, and response.
- Collaborate with infrastructure, networking, endpoint, identity, cloud, and application teams during investigations, assessments, and remediation efforts.
- Document technical findings, assessment results, incident timelines, remediation recommendations, and risk-based adjudications.
- Develop and maintain security metrics, KPIs, dashboards, and on-demand reports to communicate security posture, trends, risks, and operational performance.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent professional experience.
- 9+ years hands-on experience in vulnerability scanning, compliance assessments, STIG benchmarking, security configuration assessments, and technical adjudication.
- Must be a U.S. Citizen or Permanent Resident (Green Card Holder).
- Experience in cybersecurity engineering, vulnerability management, security operations, incident response, or related areas.
- Strong knowledge of Windows operating systems and enterprise Windows architecture (Active Directory, GPOs, permissions, authentication, authorization, access control).
- Strong understanding of TCP/IP, DNS, HTTP/S, VPNs, firewalls, and enterprise network architecture.
- Experience with endpoint security technologies such as EDR, EPP, or XDR.
- Proficiency in PowerShell; experience with Python or similar scripting preferred.
- Strong analytical, troubleshooting, documentation, and communication skills.
- Ability to work independently and collaboratively in a fast-paced enterprise environment.
- At least one required certification: CISSP, GCIH, GCIA, Security+, CEH, or equivalent.
Technologies
- PowerShell, Python
- EDR, EPP, XDR
- SIEM
- Tenable Security Center, Tenable Vulnerability Management
- DISA STIGs, SCAP
- STIG adjudication
- Defender for Endpoint, Defender for Identity, Defender for Office 365
- Microsoft Sentinel
- Microsoft Azure, Microsoft 365
- GCC, GCC High
- MITRE ATT&CK, SOAR
- TCP/IP, DNS, HTTP/S, VPNs, firewalls
- Windows, Active Directory, Group Policy Objects (GPOs)
- CMMC, NIST 800-53, NIST 800-171, FedRAMP
Preferred Qualifications
- Experience with Tenable Security Center/Tenable Vulnerability Management, including enterprise architecture, repositories, asset tagging, scan configuration, credentialed scanning, and compliance scanning.
- Experience with DISA STIGs, SCAP, security benchmarks, and STIG adjudication.
- Experience with Microsoft security technologies such as Defender for Endpoint, Defender for Identity, Defender for Office 365, and Microsoft Sentinel.
- Experience with Microsoft Azure, Microsoft 365, GCC, and GCC High security configurations.
- Experience with MITRE ATT&CK, threat intelligence platforms, SOAR, or security automation.
- Experience supporting cybersecurity frameworks such as CMMC, NIST 800-53, NIST 800-171, FedRAMP, or DISA security requirements.
Work Location
- Hybrid/Primarily Remote (at least 2 days onsite)
- Shared Services team in Beltsville, MD
Compensation
- USD 111,000 - 180,000 per year
Benefits
- Health care
- Dental
- Vision
- Life insurance
- 401(k)
- Education assistance
- Paid time off including PTO, holidays, and any other paid leave required by law
ASRC Federal and its Subsidiaries are Equal Opportunity employers.