Join the HJF Team! HJF is seeking a Cyber Security Analyst responsible for safeguarding an organization's cloud computing environment by proactively identifying, assessing, and mitigating security risks across cloud-based systems, applications, and data, utilizing specialized tools and expertise to ensure the confidentiality, integrity, and availability of sensitive information within the cloud infrastructure. This position develops and recommends security designs and frameworks for technology systems by defining processes, writing rules and outlining architecture for creating secure networks and implementing intrusion-detection systems. This position will be in support of The Office of the Chief Information Officer (OCIO), at Uniformed Services University in Bethesda, Maryland. The Henry M. Jackson Foundation for the Advancement of Military Medicine (HJF) is a nonprofit organization dedicated to advancing military medicine. We serve military, medical, academic and government clients by administering, managing and supporting preeminent scientific programs that benefit members of the armed forces and civilians alike.Since its founding in 1983, HJF has served as a vital link between the military medical community and its federal and private partners. HJF's support and administrative capabilities allow military medical researchers and clinicians to maintain their scientific focus and accomplish their research goals.
- Proactively search for and respond to security events and incidents from SIEM, Firewall (FW), Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Antivirus (AV), Network Access Control (NAC) and other client data sources. Investigate security events forwarded from stakeholders for security risk.
- Develop and adjust SIEM rules and analyst response procedures.
- Ensure adherence to relevant cloud security compliance standards and regulations (e.g., NIST SP 800-53, DoDI 8500.01, Cloud SRG, etc.) by performing regular audits and implementing necessary controls.
Provide a proactive and anticipatory threat detection capability to prepare for, prevent and mitigate future attacks. - Participates on projects and recommends secure solutions based on policies, standards and best practices. Collaborate with cloud architects to design and implement secure cloud architectures, including network segmentation, data encryption, and security best practices.
- When necessary, and with the Security Managers approval, devise and document new procedures. Ability to articulate security-related concepts to a broad range of technical and non-technical staff.
- May perform other duties and responsibilities as assigned or directed by the supervisor. This may include attendance of and participation in required training for the role.
Education and Experience
- Bachelor's Degree required, preferably in Engineering, Cybersecurity or Information Systems. Master's Degree preferred.
- Minimum of 6-8 years of experience required.
Required Knowledge, Skills and Abilities
- Deep understanding of cloud computing platforms (GCP, AWS, Azure), network security concepts, security protocols, and encryption techniques.
- Familiarity with scripting languages (e.g., Python, PowerShell) to automate security tasks and streamline operations.
- Strong analytical skills to identify patterns, investigate incidents, and effectively troubleshoot security issues.
- Hands-on experience building and managing network security systems involving components such as monitoring SIEM, firewalls, intrusion detection/prevention, content filtering, DLP, anti-malware, host and application vulnerability assessment and network monitoring tools.
- Well-developed knowledge of security principals, adversary tactics, techniques, and procedures (TTPs).
- Background in at least 2 of the following domains: security products and technologies, security engineering, networking protocols or security analysis.
- Network and host security, experience working with cyber tools and software such as GCP Security products (e.g., Command Center, Shielded VMs, Virus Total, Google Security Operations), Splunk, SourceFire, Carbon Black, Active Directory or relevant cybersecurity assets.
- Excellent written and oral communication skills.
- The ability to obtain and/or maintain a T3 Secret Clearance.
Desired Knowledge, Skills and Abilities
- Use of Terraform to securely, efficiently, and quickly change and update software infrastructure.
- Experience supporting the US Government and / or Department of Defense, particularly familiarity with the Risk Management Framework, NIST 800-53, and / or DoDI 8500.01 and related security requirements.
- Experience managing and securing cloud systems and applications.
- Experience with application and database security.
- Experience applying externally driven security and compliance baselines to workloads.
Licenses and Certifications One or more of the following certifications: CompTIA Security+, CEH, CISM, CISSP, GSEC, Google Cloud Certified Professional - Security Engineer, AWS Certified Security Specialty, Azure Security Engineer Associate, preferred. Physical Capabilities
- Ability to stand or sit at a computer for prolonged periods.
Work Environment
- This position will take place primarily in an office setting.
Compensation
- The annual salary range for this position is $88,600-$100,000. Actual salary will be determined based on experience, education, etc.
Benefits
- HJF offers a comprehensive suite of benefits focused on your health and well-being, from medical, dental, and vision coverage to health savings and retirement plans, and more.
Employment with HJF is contingent upon successful completion of a background check, which may include, but is not limited to, contacting your professional references, verification of previous employment, education and credentials, a criminal background check, and a department of motor vehicle (DMV) check if applicable. Any qualifications to be considered as equivalents, in lieu of stated minimums, require the prior approval of the Chief Human Resources Officer. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c) Any qualifications to be considered as equivalents, in lieu of stated minimums, require the prior approval of the Chief Human Resources Officer.
|