EY is a globally connected powerhouse of diverse teams, seeking to build a better working world. The Cyber Security Engineer will lead and coordinate activities related to multi-functional security technologies for the US Government and Public Sector, ensuring systems are secure and compliant while supporting operational efforts and introducing new technologies.
Responsibilities:
- Supporting the run state of our security technologies
- Bringing operational expertise into efforts which introduce new technologies and upgrade current ones
- Providing technical oversight of Information Security technologies that fall under the team’s responsibilities, confirming they are operating within agreed service levels, compliance specifications and at peak performance
- Managing and coordinating planned maintenance activities as well as incidents for Information Security technologies
- Representing the team in specific project activities, including leading projects and managing the activity of others towards successful completion
- Articulating technology issues/concerns that may emerge at any level of the technical stack, and from any component across the ecosystem, to technology leaders
- The role will likely be 100% remote and require <10% travel
- Occasional weekend and off hours work to support the business. It will also require a rotational on-call schedule
Requirements:
- Bachelor's degree in computer related field or equivalent work experience
- At least 5 years of experience in managing Information Systems and Security, including demonstratable knowledge of the various platforms and interactions
- Strong English language skills – written and verbal
- Experience in training and coaching staff in technical processes and practices
- Proven experience in configuration of the following Microsoft and Azure security services: Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for O365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender Vulnerability Management, Microsoft Defender for Cloud, Microsoft Entra ID Protection, Microsoft Data Loss Prevention (Purview), App Governance, Microsoft O365 DLP, Microsoft Intune, Azure Monitor Log Analytics, Azure Firewall, Azure WAF, Azure EventHub, Azure Network Watcher
- Eligible to obtain and maintain Top Secret Security Clearance
- Experience with MS Exchange, O365, Azure, AWS, and GCP
- Advanced skills in troubleshooting cloud environments
- General Knowledge of FedRAMP, NIST SP 800-53, and NIST SP 800-171 and other frameworks
- Federal Government experience, including CMMC Maturity Level 3
- Strong ability to document processes, procedures and security controls clearly and accurately for distribution to internal teams and customers
- GSEC/CISSP or other security related generalist certification from ISC2 or GIAC
- Experience in incident, problem and change management
- Certifications: AZ-900: Azure Fundamentals, AZ-500: Azure Security Technologies, AZ-303: Azure Architect Technologies, SANS SEC401: Security Essentials - Network, Endpoint, and Cloud, SANS SEC 510, Public Cloud Security: AWS, Azure, and GCP, SANS SEC 540: Cloud Security and DevSecOps Automation