IW
Cybersecurity Engineer
Info Way Solutions LLC
🇺🇸 United States
On-site
7 months ago
- SIEM
- EDR
- Threat Modeling
- Incident Response
- Threat Intelligence
- Risk Management
- PCI DSS
- Regulatory Compliance
- Unix
- Linux
- Windows
- CISSP
- GSEC
- GCIA
- GCIH
- GCFA
7 months ago
Duration of Role: 6-12 months with possibility of full-time employment
Work hours: 8AM-5PM Monday-Friday;
Flexibility of work hours while in contract status
On-call: rotating
Location: Required to be on site; Potential flexibility while in contract status
Provided Equipment: laptop and mobile phone
Summary of Responsibilities
Security Architecture & Engineer
ï‚· Design and implement secure architectures for applications, networks, and cloud
environments.
ï‚· Design, implement, tunes, maintains and administers corporate cybersecurity stack
including, SIEM, EDR and Firewall
ï‚· Develop and maintain security baselines, hardening guides, and configuration
standards for enterprise security stack
ï‚· Lead threat modeling and security design reviews for new systems and major
changes.
Threat Detection & Incident Response
ï‚· Build and tune detection rules, alerts, and automated response playbooks
ï‚· Lead proactive threat hunting operations to identify unknown threats, anomalous
behavior, and early indicators of compromise
ï‚· Develop hypotheses, hunt methodologies, and repeatable procedures based on
threat intelligence and environment-specific risks
ï‚· Analyze telemetry from SIEM, EDR, network sensors, and cloud logs to uncover
stealthy adversary activity
ï‚· Lead investigations of security incidents and coordinate response, containment,
remediation and recovery
ï‚· Perform root-cause analysis and drive long-term corrective actions
Vulnerability & Risk Management
ï‚· Oversee vulnerability scanning, prioritization, and remediation projects and
workflows
ï‚· Creates on demand ad-hoc assessments of computing environment for exposure to
threat intelligence reports
ï‚· Conduct risk assessments for systems, vendors, and new technologies
ï‚· Partner with IT infrastructure and other internal and third-party teams to remediate
findings and reduce attack surface
Governance, Compliance & Policy
ï‚· Models and promotes adherence to security policies, standards, procedures and
best practices.
ï‚· Has working knowledge of PCI-DSS requirements as applies to MNAA scope.
 Supports PCI-DSS audit and compliance eƯorts by gathering PCI-DSS requirement
evidence.
ï‚· Has working knowledge of TSA EA-23-01in order to support regulatory compliance.
ï‚· Assists with executing remediation plans for any gaps reported in audits or
recommended process improvements that aƯect core information security
services.
Knowledge, Skills, Abilities and other Characteristics
ï‚· Working knowledge of Unix, Linux and Windows operating systems
ï‚· Supports Client's commitment to its culture and values, including Respect,
Integrity, Service and Excellence (RISE).
 Relationship Building: Skill in establishing and maintaining eƯective and
professional working relationships with others.
Certifications, Education and Experience
ï‚· Not required but highly preferred certifications: CISSP, GSEC, GCIA, GCIH, GCFA or
other security related certifications.
ï‚· Bachelor's degree in computer science, Management Information Systems, or
relevant field of study. 7-10 years of relevant work experience with minimum of a
high school diploma may be considered in lieu of educational requirement
ï‚· 2-4 years of progressive experience in computing and information security, including
experience with Internet technology, security technology, issue resolution and
leading teams in a cross functional.
Cybersecurity Engineer · Info Way Solutions LLC