An Average Day:
As the Cybersecurity Engineer II, you will be responsible for designing, implementing, and maintaining secure information systems that support mission-critical operations. You will utilize technical expertise in endpoint security, vulnerability management, security monitoring, and compliance within Windows and Linux enterprise environments. You will also serve as a key technical contributor, supporting both defensive cyber operations and Risk Management Framework (RMF) activities. Additionally, in this position you will:
- Design, implement, and maintain cybersecurity controls to protect enterprise systems and networks.
- Administer and optimize Trellix ePO (formerly McAfee ePO) for endpoint protection, policy enforcement, threat detection, and incident response across Windows and Linux systems.
- Operate and maintain ACAS/Nessus vulnerability scanning solutions; analyze findings and support remediation efforts.
- Develop, maintain, and enhance Splunk dashboards, alerts, and correlation rules for security monitoring, log analysis, and threat detection.
- Perform technical security assessments, vulnerability assessments, and configuration compliance reviews.
- Support RMF activities including SSP development, POA&M management, control implementation, and continuous monitoring.
- Apply STIGs and SCAP benchmarks to Windows and Linux systems; validate compliance and document results.
- Analyze security events, logs, and alerts to identify indicators of compromise and support incident response actions.
- Collaborate with system administrators, network engineers, and cybersecurity leadership to implement risk mitigations.
- Provide technical recommendations to improve overall cybersecurity posture based on emerging threats and trends.
- Develop technical documentation including SOPs, security procedures, and assessment reports.