Chargement en cours

Cybersecurity Automation Engineer

NOUVELLE CALÉDONIE, FRANCE
il y a 1 jour

CyberSecurity Analyst SR Principal

Advance your career while impacting our national security in cyber as a Senior Principal Cybersecurity Automation Engineer at GDIT. This role supports cyber missions and operations across the federal government and requires strong expertise in Splunk Phantom and SOAR.

Key Responsibilities

  • Engineer and manage all SOAR using Splunk Phantom.
  • Integrate security use cases into Phantom.
  • Develop reusable, testable, and efficient Python-based Playbooks.
  • Configure and program to enable seamless integration of Phantom with other systems.
  • Extend the platform by developing Security Apps.
  • Train and mentor security development teams on the capabilities of Phantom.
  • Use available tools and the Phantom platform to enable automation and orchestration.
  • Collaborate with the customer to identify security integration and implementation strategies, developing their expertise in Phantom.
  • Define requirements for creative integrations and playbooks.
  • Partner with security operations teams, threat intelligence groups, and incident responders.
  • Codify workflows into automated playbooks.
  • Implement and develop Phantom’s flexible app model, using numerous tools and APIs.
  • Utilize Python scripts, PowerShell, and Linux commands for integrations.
  • Drive efficient communication with integrated collaboration tools.
  • Use Phantom event and case management for rapid triage of events.
  • Notify CND managers, incident responders, and team members of suspected CND incidents and provide detailed event histories, statuses, and potential impacts.
  • Coordinate with higher authorities on actual or attempted intrusions, viruses, and other events.
  • Implement and enforce CND policies and procedures adhering to applicable laws and regulations.
  • Provide incident reports, summaries, and situational awareness information to higher headquarters.
  • Manage incidents from inception to after-action reporting.

Required Qualifications

  • 8+ years of relevant experience.
  • 8570 Certification: Minimum certification IAT level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+ CE, SSCP); Level III preferred (e.g., CISSP, GCIH, GCFA, GCIA, GNFA, Linux+, CCNA R&S, Splunk Power User).
  • Experience with Splunk Phantom, Linux, and PowerShell.

Preferred Qualifications

  • Experience installing and configuring Phantom.
  • Experience in integrating security use cases into Phantom.
  • Expertise in developing Python scripts, PowerShell, and using Linux commands.

Critical Soft Skills

  • Ability to multi-task and adapt to changing priorities in highly stressful situations.
  • Highly resilient and motivated to investigate unfamiliar problems in a high OPTEMPO environment.
  • Critical thinking skills for applying and correlating data from multiple sources to solve complex problems.
  • Strong ability to articulate operational impacts of cybersecurity incidents/events to leadership.
  • Effective communication skills and the ability to build strong relationships with other teams.

Location

  • On Customer Site

Security Clearance

  • TS/SCI Required

Citizenship Required

  • US Citizenship

Salary range: $127,500 - $172,500 (subject to experience, location, and contractual requirements).

Scheduled Weekly Hours: 40

Travel Required: 10-25%

Telecommuting Options: Onsite

Work Location: USA NC Fort Bragg

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

#J-18808-Ljbffr
Entreprise
General Dynamics Information Technology
Plateforme de publication
WHATJOBS
Offres pouvant vous intéresser
MONTPELLIER, 34
il y a 1 jour
PARIS, 75
il y a 1 jour
PARIS, 75
il y a 1 jour
PARIS, 75
il y a 1 jour
Soyez le premier à postuler aux nouvelles offres
Soyez le premier à postuler aux nouvelles offres
Créez gratuitement et simplement une alerte pour être averti de l’ajout de nouvelles offres correspondant à vos attentes.
* Champs obligatoires
Ex: boulanger, comptable ou infirmière
Alerte crée avec succès