SDLC Technologies is seeking a Cybersecurity Analyst to safeguard enterprise systems and data across a global technology environment. The role involves managing privileged access, monitoring vulnerabilities, and driving remediation efforts to strengthen security posture while ensuring compliance with internal policies and regulatory frameworks such as FedRAMP.
Responsibilities:
- Strong proficiency with Delinea's Thycotic Secret Server/BeyondTrust
- Demonstrated knowledge of Active Directory and networking
- Thorough understanding of identity lifecycle management for privileged and user accounts
- Extensive experience with Tenable and Wiz
- Proficient in executing various scans (daily, weekly, ad-hoc, monthly), including PCI Compliance, Web Application Scanning, Vulnerability Management, Attack Surface Management, and Identity Exposure
- Proven ability to coordinate vulnerability remediation efforts with asset owners (identified through Tenable/Wiz/Google Mandiant)
- General understanding of digital certificate concepts
- Familiarity with Google Sheets and Mail Merge, along with a general understanding of Active Directory fields (e.g., nested groups, disabled/expiring accounts, Organizational Units)
- Familiarity with Google Sheets and VLOOKUP commands, and a general understanding of Active Directory fields (e.g., disabled/expiring accounts, Organizational Units)
- Ground level work experience on issues like P1 Issues (Critical): Ransomware infection detected, Domain advertised as a ransomware victim, Malware controller observed or malware infection, Phishing infrastructure, Alleged breach incident, Anonymous open proxy, Products susceptible to ransomware exploits exposed
- P2 Issues (High): DB or RDP services exposed to the Internet, Certificate revoked/expired, SSH software supporting vulnerable protocols or weak ciphers/MACs, SSL/TLS service supporting weak protocols or cipher suites, End-of-Life (EOL) OS/Software, Critical/High-Severity CVSS v3.0 Vulnerabilities, Site not enforcing HTTPS, FTP/Telnet/rsync/VNC/SMB/PPTP services detected, Adware installation, Missing SPF record
- P3 Issues (Medium/Low): Certificate lifetime exceeding best practices or without revocation control, Malformed SPF record or SPF record containing a softfail without DMARC, Medium/Low-Severity CVSS v3.0 Service Vulnerabilities, Missing Content Security Policy (CSP), Insecure HTTPS redirect pattern or redirect chain containing HTTP, Website not implementing HSTS best practices
Requirements:
- FedRamp Certification / FedRamp Implementation experience
- Delinea/Thycotic Secret Server, vulnerability management
- PCI Compliance, Tenable and PAM experience
- Candidate should have worked on a Federal Project
- Detail-oriented with strong organizational abilities
- Foundational understanding of security principles
- Excellent communication skills
- Proficiency in conducting scans, analyzing findings, and collaborating with teams for timely remediation to ensure compliance
- Capable of working both independently and within cross-functional teams
- Strong proficiency with Delinea's Thycotic Secret Server/BeyondTrust
- Demonstrated knowledge of Active Directory and networking
- Thorough understanding of identity lifecycle management for privileged and user accounts
- Extensive experience with Tenable and Wiz
- Proficient in executing various scans (daily, weekly, ad-hoc, monthly), including PCI Compliance, Web Application Scanning, Vulnerability Management, Attack Surface Management, and Identity Exposure
- Proven ability to coordinate vulnerability remediation efforts with asset owners (identified through Tenable/Wiz/Google Mandiant)
- General understanding of digital certificate concepts
- Familiarity with Google Sheets and Mail Merge, along with a general understanding of Active Directory fields (e.g., nested groups, disabled/expiring accounts, Organizational Units)
- Familiarity with Google Sheets and VLOOKUP commands, and a general understanding of Active Directory fields (e.g., disabled/expiring accounts, Organizational Units)
- Ground level work experience on issues like P1 Issues (Critical) and P2 Issues (High) and P3 Issues (Medium/Low) as described in the job description