Senior Cyber Security Engineer
CurrentPerform IT Security Assessments for U.S. Court units throughout the Federal Judiciary. Identify all technical, management, and operational vulnerabilities in a court unit environment and its supporting IT infrastructure. The assessments include a review of all physical and logical resources, policies, operations, and personnel.Key responsibilities include:- Conduct vulnerability assessments to identify security gaps, vulnerabilities and weak configurations that exist on the court unit networks.- Perform risk analysis and security assessment of the underlying network.- Closely work with court IT support teams to explain vulnerabilities and to provide guidance on potential exploits and impacts to existing systems and applications.- Develop remediation plans (POA&M), communicate and explain them to stakeholders and support teams.- Develop repeatable methodologies and standard operating procedures for the performance of assessments.- Develop and provide guidance in implementation of system checklists, automated tools policies, trends and create and deliver key observation presentations.- Conduct assessment kick-off entrance and close-out exit briefings and run meetings with court staff to respond to questions, explain assessment findings and plan of remediation actions.- Review system documentation and system hardware configuration, including: Security Plans, Incident Response Plans, Network Diagrams (logical and physical), Patch Management Plans, Contingency Plans, and Incident Logs.- Leverage other assessment methods, such as inquiry, observation, and testing to gain an understanding of the court infrastructure, its architecture, and its associated safeguards.