Job opening: Senior IT Specialist (Data Loss Prevention Security Engineer)
Salary: $117 962 - 181 216 per year
Published at: Oct 25 2024
Employment Type: Full-time
This is a full-time position with the Office of Information Technology at the Supreme Court of the United States in Washington, D.C.
Closing Date: Monday, 11/11/2024, 11:59 PM EDT
Please note that this vacancy has a limit of 200 applicants. The job opportunity announcement will automatically close if that limit is reached prior to the closing date.
Duties
This position is a full-time position in the Office of Information Technology at the Supreme Court of the United States, in Washington, D.C. Under the guidance of the Court Information Security Officer, the incumbent will perform the full range of tasks and activities involved in developing, coordinating, implementing and maintaining standards, procedures and technical solutions to protect the confidentiality, integrity and availability of information systems and data.
The Data Loss Prevention (DLP) Security Engineer will have overall responsibility for the DLP program at the Court. The role requires working with all departments at the Court to identify sensitive data types, implementing technology to restrict access only to the business processes and roles which require them. The DLP Engineer serves a critical role in support of investigations and escalations of DLP alerts/breaches. As a Security Engineer within the Court Information Assurance Group, this role performs additional security engineering duties as assigned.
The incumbent will be responsible for the following duties:
- Manage and evolve the DLP program over time according to business priorities.
- Evaluate current and emerging DLP technologies and risks.
- Install, configure, and maintain DLP software.
- Develop and deliver data profiles for systems across the enterprise.
- Enhance and tune standards-based rulesets and apply them to DLP Tools.
- Implement DLP controls according to the Information Security Policy and the needs of Court offices.
- Create and refine DLP tagging of sensitive information types.
- Define and update DLP rules associated with tags.
- Develop Incident Response playbooks for responding to DLP alerts.
- Support the design and implementation of manual and automated response to DLP incidents.
- Participate in On-Call rotation (approximately one week every two months)
- Train cybersecurity personnel in daily DLP program operation.
- Coordinate and conduct DLP training exercises with relevant stakeholders.
Requirements
- Meet Experience Requirements (see Qualifications)
- Employment is subject to successful completion of a security background check.
- If you are a male applicant born after December 31, 1959, you must certify that you have registered with the Selective Service System, or are exempt from having to do so under the Selective Service Law. See: www.sss.gov
Qualifications
Candidate must possess the following knowledge, skills and abilities:
- At least 2 years of experience of management of enterprise DLP tools.
-Able to demonstrate the skill level needed to lead and build out a DLP program.
-Ability to work with stakeholders to determine information types, patterns, and boundaries, then translating those into enforcement and/or actionable alerts for the Incident Response team.
-Demonstrate the technical skills to deploy and maintain on-prem DLP components, to include server OS administrative skills, agent deployment, or troubleshooting various issues as the result of a DLP deployment.
- Ability to optimize systems to meet enterprise performance requirements
- Ability to work with engineers/vendors to improve capabilities, resolve issues, and increase performance of security operation devices and configurations.
- Knowledge of operating system (Windows, Linux/Unix) command-line tools.
- Knowledge of endpoint security events and how they relate to possible attacks/intrusions.
- Ability to balance business needs with security policies.
- Organizational skills with the ability to multitask, take direction, prioritize, and manage multiple activities/tasks to achieve objectives.
- Ability to work in a fast-paced, technically challenging area; ability to anticipate and manage changes or problems; assess impacts and make sound recommendations.
- Proficiency in tailoring and/or recommending detection rules based on newly discovered IOCs and threats against government networks.
- CISSP, GCIA, GCIH, CASP, and other security certifications desired, but not required.
Education
Candidate must have:
- Two years of demonstrated cyber security related experience and a college degree (computer related).
or
- Five years of demonstrated cyber security experience.
Contacts
- Address Supreme Court of the United States
1 First Street NE
Washington, DC 20543
US
- Name: Human Resources Office
- Phone: (202) 479-3404
- Email: [email protected]
Map