Ability to obtain a government clearance if needed.
Responsibilities
Architect, engineer, deploy, and sustain secure, resilient, and cost-effective cloud and on-premise applications and systems, including supporting existing and transitional cloud environments and reviewing and approving architectural designs for secure implementation of cloud, hybrid-cloud, and on-premise resources across the enterprise.
Develop, deploy, and maintain secure baselines for cloud and on-premise systems, ensuring adherence to federal mandates, organizational policies, and industry best practices, and implement and maintain administrative, technical, and physical controls and safeguards.
Create and maintain documentation, including Standard Operating Procedures, policies, architectural diagrams, code documentation, security baselines, system controls, and supporting system documentation.
Ensure comprehensive collection of performance and security logs for resources and applications to support monitoring, analysis, and compliance with federal policies, regulations, mandates, and industry best practices.
Review and improve logging and monitoring methodologies and capabilities to reduce noise and improve performance, security, and compliance.
Develop, implement, and maintain continuous monitoring in accordance with federal regulations and organizational policies, covering system availability, performance, security, reporting, and response.
Monitor cloud expenditures and provide federal leadership with actionable recommendations to minimize cloud costs while maintaining operational effectiveness.
Administer, operate, maintain, configure, tune, and secure hybrid-cloud monitoring technologies and other relevant tools, devices, application systems, servers, and sensors to mitigate Plans of Action and Milestones and reduce risk.
Maintain optimal coverage and performance of the cybersecurity network, applications, and systems, ensuring continuous security and operational efficiency.
Conduct market research to identify and evaluate or develop new security solutions, applications, and hardware to prevent obsolescence, enhance productivity, and improve the enterprise security posture.
Report cybersecurity incidents in accordance with federal regulations and organizational policies.
Maintain data retention and security in accordance with federal policy, regulations, mandates, industry guidelines, and best practices.
Ensure continuous compliance with federal regulations and organizational policies, and support audits of applications, systems, and services.
Gritter Francona is looking for a Junior Cloud Security Engineer to provide comprehensive security engineering and sustainment support for U.S. Customs and Border Protections' cloud environments, ensuring optimal coverage, performance, and adherence to security standards and best practices.
Secure Architecture, Engineering, and Sustainment: Architect, engineer, deploy, and sustain secure, resilient, and cost-effective cloud and on-premise applications and systems. This includes, but is not limited to providing support for existing and transitional cloud environments, and reviewing/approving architectural designs to ensure secure implementation of cloud, hybrid-cloud, and on-premise resources across the enterprise.
Secure Baseline Management: Develop, deploy, and maintain secure baselines for all CSD cloud and on-premise systems, ensuring adherence to federal mandates, organizational policies, and industry best practices. This includes the development, implementation, and maintenance of administrative, technical, and physical controls and safeguards that adhere to federal regulations, organizational policies, and industry best practices.
Documentation and Standards Development: Create and maintain comprehensive documentation including, but not limited to, Standard Operating Procedures (SOPs), policies, architectural diagrams, code documentation, security baselines, system controls, and other supporting system documentation.
Log Management and Monitoring: Ensure the comprehensive collection of all pertinent performance and security logs for all resources and applications to support monitoring, analysis, and compliance with the following, but not limited to, federal policies, regulations, mandates, and industry best practices.
Log Management and Monitoring Optimization: Continually review and improve logging and monitoring mythologies and capabilities to reduce noise and improve performance, security, and compliance.
Continuous Monitoring & Availability: Develop, implement, and maintain a robust continuous monitoring capability within accordance to federal regulations and organizational policies. The continuous monitoring activities shall encompass, at a minimum, system availability, performance, security, reporting, and response.
Cost Optimization: Monitor cloud expenditures and provide federal leadership with actionable recommendations to minimize cloud costs while maintaining operational effectiveness.
Hybrid-Cloud Tool Suite Administration and Security: Administer, operate, maintain, configure, tune, and secure the CSD's hybrid-cloud monitoring technologies and other relevant CSD tools, devices, application systems, servers, and sensors to mitigate Plans of Action and Milestones (POA&Ms) and reduce risk.
Cybersecurity Services Optimization: Maintain optimal coverage and performance of the cybersecurity network, applications, and systems, including but not limited to ensuring continuous security and operational efficiency.
Market Research and Innovation: Conduct market research to identify and evaluate or develop new security solutions, applications, and hardware to prevent obsolescence, enhance productivity, and improve the overall security posture within CBP's enterprise.
Cyber Incident Reporting: Report all cybersecurity incidents within accordance to federal regulations and organizational policies.
Data Management: Maintain data retention and security within accordance to federal policy, regulation, mandates, including industry guidelines and best practices.
Audit Support and Maintenance: Ensure continuous compliance with all federal regulations and organizational policies, and provide comprehensive support for audits of applications, systems, and services to guarantee successful outcomes.
AWS Certified Cloud Practitioner
AWS Certified Security – Specialty
5 years related experience
Ability to obtain a government clearance if needed