EY is a globally connected powerhouse of diverse teams looking to shape the future with confidence. The Cyber Security Engineer will lead and coordinate activities related to multi-functional security technologies for the US Government and Public Sector, ensuring systems are secure, robust, and compliant while supporting the operational state of security technologies.
Responsibilities:
- Supporting the run state of our security technologies
- Bringing operational expertise into efforts which introduce new technologies and upgrade current ones
- Providing technical oversight of Information Security technologies that fall under the team’s responsibilities, confirming they are operating within agreed service levels, compliance specifications and at peak performance
- Managing and coordinating planned maintenance activities as well as incidents for Information Security technologies
- Representing the team in specific project activities, including leading projects and managing the activity of others towards successful completion
- Articulating technology issues/concerns that may emerge at any level of the technical stack, and from any component across the ecosystem, to technology leaders
Requirements:
- Bachelor's degree in computer related field or equivalent work experience
- At least 5 years of experience in managing Information Systems and Security, including demonstratable knowledge of the various platforms and interactions
- Strong English language skills – written and verbal
- Experience in training and coaching staff in technical processes and practices
- Proven experience in configuration of the following Microsoft and Azure security services: Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for O365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender Vulnerability Management, Microsoft Defender for Cloud, Microsoft Entra ID Protection, Microsoft Data Loss Prevention (Purview), App Governance, Microsoft O365 DLP, Microsoft Intune, Azure Monitor Log Analytics, Azure Firewall, Azure WAF, Azure EventHub, Azure Network Watcher
- Eligible to obtain and maintain Top Secret Security Clearance
- Operational experience in an environment of more than 3000 users
- Perform detailed troubleshooting of issues, by using their analytical skills and collaborating with other technical teams, stakeholders and internal and external customers
- Ability to work and solve issues independently, finding solutions to problems
- Strong ability to document processes, procedures and security controls clearly and accurately for distribution to internal teams and customers
- Comfortable working remotely in a large, global virtual environment
- Ability to react appropriately during stressful and ambiguous situations and communicate clearly to senior leadership when the situation requires
- Strong problem solving, decision making and collaboration skills
- Functional and/or technical experience in supporting security technologies including detailed knowledge of many of the following: Cloud Operations especially Azure, O365 Tenants, networking concepts & mechanisms, EDR, DLP, AV/AM, DNS, Encryption, E-Mail technologies including DMARC, DKIM, SMTP, TLS, EVM, SYSLOG, PKI, as well as a myriad of other related security and desktop technologies: Azure networking and platform protection, Azure architectural design, Diagnostic logging & log retention and complex logging solutions with varied vendors and environments, Vulnerability and compliance scanning solutions and policies, Virtual networks and Network Security Groups, Application gateways and load balancing, Traffic Manager and Azure DDoS protection, Host Security and VM Hardening, Serverless Computing (Kubernetes), Subscription security and policies, Azure resource policies and resource locks, Azure information protection, Access control and key management for storage accounts
- Basic Scripting and Automation Skills
- Experience with CI/CD pipelines deployment, DevSecOps and Policy as Code
- Experience with Containers
- Experience with WDAC
- Experience with MS Exchange, O365, Azure, AWS, and GCP
- Advanced skills in troubleshooting cloud environments
- General Knowledge of FedRAMP, NIST SP 800-53, and NIST SP 800-171 and other frameworks
- Federal Government experience, including CMMC Maturity Level 3
- GSEC/CISSP or other security related generalist certification from ISC2 or GIAC
- Experience in incident, problem and change management
- Certifications: AZ-900: Azure Fundamentals, AZ-500: Azure Security Technologies, AZ-303: Azure Architect Technologies, SANS SEC401: Security Essentials - Network, Endpoint, and Cloud, SANS SEC 510, Public Cloud Security: AWS, Azure, and GCP, Sans SEC 540: Cloud Security and DevSecOps Automation