Over 1 Million Paying Vacancies Available. Discover Your Dream Vacancy with Us!

Are you looking for a Senior IT Specialist (Security Information and Event Management Security Engineer)? We suggest you consider a direct vacancy at Supreme Court of the United States in Washington. The page displays the terms, salary level, and employer contacts Supreme Court of the United States person

Job opening: Senior IT Specialist (Security Information and Event Management Security Engineer)

Salary: $117 962 - 153 354 per year
Published at: Jul 22 2024
Employment Type: Full-time
This is a full-time position with the Office of Information Technology at the Supreme Court of the United States in Washington, D.C. Closing Date: Monday, 08/05/2024, 11:59 PM EDT Please note that this vacancy has a limit of 200 applicants. The job opportunity announcement will automatically close if that limit is reached prior to the closing date.

Duties

This position is a full-time position in the Office of Information Technology at the Supreme Court of the United States, in Washington, D.C. Under the guidance of the Court Information Security Officer, the incumbent will perform the full range of tasks and activities involved in developing, coordinating, implementing and maintaining standards, procedures and technical solutions to protect the confidentiality, integrity and availability of information systems and data. The Security Information and Event Management (SIEM) Security Engineer will have overall responsibility for the SIEM program at the Court. The role requires working with system administrators, engineers, developers, and incident responders to identify relevant system events, implementing the design, normalization, ingest, and alerting of relevant logs. The SIEM Engineer serves a critical role in support of investigations and escalations of SIEM alerts. The SIEM Engineer also administers the SIEM hardware, software, and endpoint agents across the enterprise. As a Security Engineer within the Court's Information Assurance Group, this role performs additional security engineering duties as assigned. The incumbent will be responsible for the following duties: - Manage and evolve the SIEM program over time according to Court priorities - Evaluate current and emerging SIEM technologies and risks - Install, configure, and maintain SIEM software and hardware - Architect, administer, configure, and optimize the SIEM platform to collect and correlate security event data - Implement the NIST 800-53 Audit and Accountability (AU) control family according to the Information Security Policy and the needs of Court offices - Define and update SIEM alerts, reports, and dashboards - Work with the Incident Response Team to develop playbooks for responding to SIEM alerts - Support the design and implementation of manual and automated response to security events (SOAR) - Train personnel in SIEM program operation - Coordinate and conduct SIEM training exercises with relevant stakeholders - Work with Incident Response Team to create detection rules for emerging threats - Participate in On-Call rotation (approximately one week every two months) - Incorporate threat intelligence feeds and indicators of compromise into SIEM alerting and dashboards - Coordinate with department stakeholders when new technologies are implemented to ensure appropriate data ingest

Requirements

  • Meet Experience Requirements (see Qualifications)
  • Employment is subject to successful completion of a security background check.
  • If you are a male applicant born after December 31, 1959, you must certify that you have registered with the Selective Service System, or are exempt from having to do so under the Selective Service Law. See: www.sss.gov

Qualifications

Candidate must possess the following knowledge, skills and abilities: - At least 2 years of experience managing enterprise SIEM tools - Enterprise level experience installing, configuring, and implementing RHEL, Ubuntu or similar Linux platforms - Experienced engineer with expertise in the design, implementation, configuration, and management of SIEM architectures - Experience with solutions such as SOAR, threat intelligence platforms, and/or User Behavior Analysis (UBA) - Knowledge of detection engineering and detection as code practices - Ability to optimize systems to meet enterprise performance requirements - Ability to work with engineers and vendors to improve capabilities, resolve issues, and increase performance of security operation devices and configurations - Knowledge of operating system (Windows, Linux/Unix) command-line tools - Knowledge of endpoint security events and how they relate to possible attacks/intrusions - Ability to balance business needs with security policies - Organizational skills with the ability to multitask, take direction, prioritize, and manage multiple activities/tasks to achieve objectives - Proficiency in tailoring and/or recommending detection rules based on newly discovered IOCs and threats against government networks - Expertise in data search, including indexing, querying, and visualization - Experience with API scripting and programming languages (e.g. Python) for automation and custom tool development - Excellent problem-solving skills and the ability to work under pressure in incident response scenarios - Strong communication skills, both written and verbal, to effectively convey complex security concepts - CISSP, GCIA, GCIH, CASP, and other security certifications desired, but not required

Education

Candidate must have:
- Two years of demonstrated cyber security related experience and a college degree (computer related).
or
- Five years of demonstrated cyber security experience.

Contacts

  • Address Supreme Court of the United States 1 First Street NE Washington, DC 20543 US
  • Name: Human Resources Office
  • Phone: (202) 479-3404
  • Email: [email protected]

Map

Similar vacancies

Deputy Director, Application Platforms and Delivery Branch, EM-2210-00 Jul 15 2024
$275 000 - 310 000

The incumbent serves as principal advisor to the Chief Information Officer (CIO), Chief Privacy Officer and Director of the Division of Information Technology (DIT), and other senior-level FDIC offici...

Deputy Chief Information Office, Technology & Chief Technology Officer, EM-2210-00 Aug 05 2024
$275 000 - 310 000

Supports the CIO in implementing the mission, vision, and priorities for branches, subordinate organizations and their staff to support CIO strategic activities in IT strategic planning, enterprise a...

Chief Information Officer Oct 11 2023
$237 703 - 303 072

EXECUTIVE DESIGNATION: This is a position designated as an FHFA Executive by the Director as based on the incumbent's influence over and accountability for effectively accomplishing the FHFA mission....

Chief Information Officer Oct 11 2023
$237 703 - 303 072

EXECUTIVE DESIGNATION: This is a position designated as an FHFA Executive by the Director as based on the incumbent's influence over and accountability for effectively accomplishing the FHFA mission....

Chief (Cloud Hosting and Networks Office) Nov 14 2023
$206 200 - 229 111

The Department of Technology Services provides a wide range of enterprise-class systems, infrastructure, and data services supporting the operations of the courts. The incumbent is responsible for th...