Cyber Security Engineer

4 weeks ago


Washington, United States Kalani Consulting Full time
Cyber Security Engineer

Kalani Consulting Inc recently awarded Best and Brightest Companies to Work for in The Nation for the second year in a row and Washington Post's Top Workplaces of 2023 is looking to add more talent to our team Kalani is a fast-growing small business located in Northern Virginia with an increasing base of government customers. We specialize in Information Technology, and Management Consulting. We offer very competitive salaries and benefits and are an employee-focused company. Join us and experience the Aloha Spirit

Overview:
This individual will serve as the Senior Information Systems Security Engineer and Senior Technical Consultant for the Department of State DevOps team, Solution Architecture team and Application Vulnerability Assessment Program. Responsibilities include developing pipelines. Must be able to configure, implement and administer Fortify Static Code Analyzer, Web Inspect, OWASP and SonaType into the Azure DevOps pipeline and provide hands-on technical subject matter expertise for applications using the application scanning tools.

Responsibilities:
  • Maintain Azure DevOps pool agent servers.
  • Monitor and coordinate security findings.
  • Manage the program testing processes and testing activities of the security program.
  • Manage the resolution of open issues and communicate essential information to stakeholders.
  • Administer applications and users and field troubleshooting questions for users and other stakeholders.
  • Analyze internal security and provide relevant information to internal and external stakeholders.
  • Analyze all platform level system changes and monitor impact and provide appropriate technical solutions to resolve issues efficiently; evaluate and document operating baseline according to required standards.
  • Work with Project teams to review vulnerabilities and manage the resolution of vulnerabilities.
  • Support the creation and maintenance of program documentation including Standard Operating Procedures, Test Plans, Reference Guides, Troubleshooting Guides, Training Guides, etc.
Qualifications:
  • Strong understanding of DevSecOps tools and processes, as well as OWASP top risks and mitigations.
  • Hands-on experience in installing, configuring, operating, and monitoring CI/CD pipeline tools.
  • Previous work writing/developing CI/CD pipelines using YAML, maintaining/configuring build agents, and generating documentation and statements of procedures for these processes.
  • Experience integrating static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and other application security tools (i.e., IaC scanning, container security, etc.) into CI/CD pipelines to automate security testing.
    • Examples include Fortify SCA, Fortify WebInspect, Sonatype, Checkov, Owasp ZAP, Burp Suite, etc.
  • Knowledge of NIST's Secure Software Development Framework and how code scanning tools align.
  • Ability to troubleshoot, via log analysis, both frequent and infrequent technical issues related to CI/CD pipeline run errors.
  • Programming/scripting experience in Python/PowerShell to design and implement automation to streamline processes.
  • Solid understanding of other core programming languages such as C#/.NET, Java, Node.js, PHP, etc. to aid in troubleshooting of customer CI/CD pipelines.
  • Experience reviewing and validating outputs of code scans to assist customers in identify true positives and provide appropriate remediation guidance.
Clearance Requirement:
  • Active DOD Secret Clearance

Kalani Consulting, Inc. is an equal opportunity employer that values the strength diversity brings to the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law.

  • Washington, United States Iron Vine Security Full time

    Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintaining IT security systems to protect digital assets from malicious cyber-attacks. · Experience developing and implementing an annual Incident Response Training and Testing Program · Experience implementing, configuring, and...


  • Washington, United States Latitude, Inc. Full time

    Job DescriptionJob DescriptionWe are seeking a highly motivated and experienced Cyber Security Systems Engineer to join our dynamic team. The Cyber Security Systems Engineer will be responsible for designing, implementing, and maintaining security systems and protocols to protect our organization's infrastructure and assets from cyber threats. The ideal...


  • Washington DC, United States Avid Technology Professionals Full time

    The Sr Cyber Security Engineer designs, develops, documents, analyzes, tests, integrates, debugs, conducts research and/or discovers and analyzes security flaws or vulnerabilities in software, networks, systems, and applications. The Sr Cyber Security Engineer ensures system security needs are established and maintained for various objects/matters. ...


  • Washington, United States INSPYR Solutions Full time

    Title: Cyber Security Engineer Location: Washington, DC Duration: 1 year contract to hire Compensation: 78/hr and 140k on conversion Work Requirements: US Citizen, GC Holders or Authorized to Work in the U.S. Skillset / Experience:Cyber Security Engineer Develops and implements security solutions. Administers security technology systems by architecting and...


  • Washington, United States Base One Technologies Full time

    Our DC metro based client is looking for a Senior Security Engineer. If you are interested in this opening, please forward a copy of your updated resume in word format to Work location: L'Enfant PlazaMust Have One of the Following J3 Certifications:CISSP or one of GCWN, GISF, GSSP, GICSP, CCSP, CSSLP, SSCP, CCSNP, CCIE-Security, ECSP, MCSE-Security Expert,...


  • Washington, United States GuidePoint Security Full time

    GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...


  • Washington, United States GuidePoint Security Full time

    GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...


  • Washington DC, United States Avid Technology Professionals Full time

    The Sr Cyber Security Engineer designs, develops, documents, analyzes, tests, integrates, debugs, conducts research and/or discovers and analyzes security flaws or vulnerabilities in software, networks, systems, and applications. The Sr Cyber Security Engineer ensures system security needs are established and maintained for various objects/matters. ...


  • Washington, United States INSPYR Solutions Full time

    Title: Cyber Security Engineer Location: Washington DC (Hybrid) Duration: 12 Month Contract to Perm Compensation: $80-89/HR W2 Work Requirements: US Citizen, GC Holders or Authorized to Work in the U.S. As a Senior Splunk Engineer within our Security Operations Engineering team, you will play a pivotal role in orchestrating the full spectrum of...


  • Washington, United States Jlha Full time

    If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Cyber Security Specialist Full Time Washington, DC, US 30+ days ago Requisition ID: 1085 At Herren Associates, we’re focused on driving innovation throughout the Federal landscape and in the business...


  • Washington, DC, United States GuidePoint Security Full time

    GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government...


  • Washington, United States Ageatia Global Solutions Full time

    PURPOSE: Develops and implements security solutions. Administers security technology systems by architecting and engineering/developing trusted systems into secure systems. Assists in the development of implementation and deployment plans that are aligned to the organizational strategic plan objectives and security requirements. Advises management in...


  • Washington, United States Ageatia Global Solutions Full time

    PURPOSE: Develops and implements security solutions. Administers security technology systems by architecting and engineering/developing trusted systems into secure systems. Assists in the development of implementation and deployment plans that are aligned to the organizational strategic plan objectives and security requirements. Advises management in...


  • Washington, Washington, D.C., United States BAE Systems Full time

    Job Description BAE Systems, Inc. is currently looking for a Cyber Security Engineer / Information Systems Security Engineer (ISSE) to join an innovative team in Washington, DC. This position supports the development of mission-critical applications for a federal government client focused on national security.The ISSE will be part of a team that supports...


  • Washington, United States Everfox, formerly Forcepoint Federal Full time

    Job Title: Principal Cyber EngineerLocation: Washington DC with 50% travel The Position:We are looking for talented cyber engineers motivated to help customers solve complex and fast-moving cybersecurity challenges supporting the U.S. Government. Focusing on our Cross Domain solutions, you will interface directly with customers and play a key role in...


  • Washington, United States PPT Solutions, Inc. Full time

    **PPT Solutions, Inc**. is seeking a **Cyber Security Analyst** in the **National Capital Region.** The qualified applicant will provide objective expertise for cyber tabletop exercises and specialized skills to supporting projects related to cyber penetration testing, resilience, assessment, and testing efforts. They will collaborate with the test team to...


  • Washington, Washington, D.C., United States Non-Departmental Agency Full time

    Summary Cyber Security Officers identify current threats, mitigate vulnerabilities, and anticipate future cybersecurity challenges, protecting CIA data and systems and managing IT risk. Duties As a Cyber Security Officer (CSO), you will protect Agency data and systems using sophisticated tools, instrumentation, and knowledge of CIA Information Technology...


  • Washington, United States Non-Departmental Agency Full time

    Summary Cyber Security Officers identify current threats, mitigate vulnerabilities, and anticipate future cybersecurity challenges, protecting CIA data and systems and managing IT risk. ...


  • Washington, United States Enlightened Full time

    Job Description Job Description Senior Cyber Security Analyst Are you passionate about Cyber Security and looking to contribute to meaningful projects that impact our Nation and communities? If so, we are ready to Enlightened you! This is an excellent opportunity to use critical thinking to bring together information from multiple sources to determine if a...


  • Washington, United States The Tatitlek Corporation Full time

    Overview RESPONSIBILITIES: * Engineering and implementing Cyber Security program initiatives.* O365 Cloud Security Experience, deployment, maintaining, auditing.* Ensuring data are protected from unauthorized access and disclosure.* Working knowledge of network technologies such as: Windows, Linux Operating Systems; Database security, Active Directory,...