Responsibilities
- Deploy and manage enterprise-grade security systems such as firewalls, endpoint protection, identity management, and security monitoring solutions.
- Support the rollout and ongoing operation of security controls in on-premises, cloud, and hybrid infrastructure environments.
- Perform security evaluations, vulnerability scans, and risk assessments on systems and applications.
- Monitor and analyze security events and alerts using Security Information and Event Management (SIEM) tools.
- Investigate cybersecurity incidents and assist in containment, resolution, and recovery efforts.
- Support proactive threat hunting and analyze indicators of compromise (IOCs) to detect malicious activity.
- Conduct regular vulnerability assessments and coordinate remediation actions with system owners.
- Support secure configuration and patch management processes across systems and networks.
- Assess technical systems for potential security risks and recommend effective mitigation strategies.
- Collaborate with engineering teams to integrate security measures into system designs and platform deployments.
- Help develop and maintain security policies, procedures, technical standards, and documentation.
- Support compliance with regulatory, contractual, and organizational security requirements.
- Participate in security audits, risk assessments, and system authorization processes.
- Assist in implementing and maintaining cybersecurity frameworks such as NIST CSF, NIST SP 800-53, RMF, and ISO/IEC 27001.
- Provide technical expertise during cybersecurity design reviews, planning sessions, and engineering discussions.
Work Arrangement
On-site — north Colorado Springs, Chidlaw, Peterson AFB
Physical demands
Remain seated for long durations; operate computers and office equipment using hands and fingers; communicate verbally and electronically; move around the office as needed; lift or carry up to 15 pounds; maintain close vision and ability to adjust focus.
Work environment
Work is conducted in a secure, classified setting requiring strict adherence to security protocols, access controls, restrictions on personal electronic devices, and proper handling of sensitive information.