Atlanta, GA, USA
1 day ago
IT Security Engineer -Associate Principal

Job Family:

IT Cyber Security


Travel Required:

Up to 10%


Clearance Required:

None

What You Will Do:
This role plays a pivotal role within the Information Security Operations team and is dedicated to Security Operations and Incident Management/Response processes, SIEM engineering, Threat Hunting, Automation, Cyber Architecture, and Threat Intelligence.This position is responsible for enhancing SIEM and tool monitoring, tuning, detection, and alerting across multiple domains, to support cyber incident response capabilities and tooling, with the goal of identifying, analyzing, and mitigating security threats across the Guidehouse environment to protecting Guidehouse and Client data within systems, networks, and cloud environments.You will be mentoring and working with SOC analysts to increase knowledge and skill with detection techniques and other SecOps technologies. You may also participate on IT Security projects to enhance IT Security capabilities, improve monitoring coverage, drive detection and threat hunting efforts, leading to an overall improvement of enterprise cybersecurity posture.
The successful candidate applies technical knowledge and experience to drive innovation and performance improvement while demonstrating critical thinking, problem solving, and sound logic when assessing problems and opportunities in generating solutions. This position reports into the Director of IT Security Operations.Job Function:Solid understanding of platform, network, application, and cloud security fundamentals, threats, attack techniques, and mitigationsExperience interpreting vulnerability scan data and CVEs, assessing and responding to vulnerabilities, including a foundational understanding of risk managementKnowledge of cybersecurity concepts, and network/web protocolsDemonstrated knowledge of adversary TTPs (Tactics, Techniques and Procedures)Designs and configures monitoring and alerts using SIEM, Azure Purview, Defender, CSPM, etc.Experience with one or more of SIEMs, SOAR technologies, building/maintaining IR tools and processes, programming/scripting, threat hunting, SIEM detection engineering/tuning.Assists in conducting risk assessments and security audits to identify vulnerabilities and recommending mitigations to enhance security postureDemonstrates effective written and verbal communication skills; delivered in a professional, respectful, and timely mannerProduces high quality work product leveraging existing templates, tools, and methodologies that align to applicable professional standards and best practicesClearly and concisely conveys more complex messages to IT Security Operations team; effectively presenting facts and recommendationsIdentifies risk issues (e.g., technical, client service, engagement, team, internal and external) and escalate them to IT Security supervisors and senior leadersHelps with issue resolution, risk mitigation and contingency planning in alignment with IT Security risk mitigation plansUses critical thinking, analysis, expertise, and collaboration to develop technical solutions and solve problemsWorks in unstructured or unclear circumstancesMentor, train, and guide IT Security technical staff across the organization, fostering a culture of technical excellence, continuous learning, and security-first principles.Promotes the development of new technical knowledge and skills within IT Security Operations teamTakes ownership of tasks, resolving issues and escalating as appropriatePresents themselves and the company in a manner that always promotes a positive lasting impression of high quality, promptness, and professional serviceDraws from experience to propose solutions to meet needs, focusing the team accordinglyBuilds a high level of trust with stakeholders by meeting and anticipating needs and expectationsStays current on Azure and AWS events, trends, and issues in the news relevant to IT SecurityEnsures prescribed IT Security policies, procedures, and standards are followed while identifying opportunities for system and process enhancementsWorks independently on mid to large or complex projects and assignments, with minimal guidance and to influence parties within and outside the job function at an operational level regarding policies, best practices, and proceduresAdvanced understanding and ability to apply standards, principles, theories, and technical concepts obtained through advanced education combined with experience
What You Will Need:
 Bachelor’s degree plus 8 years of experience OR 12 years of experience in lieu of degreeUnited States CitizenshipMust be able to work East Coast US business hoursExperience working with Executive LeadershipExperience supporting Microsoft Windows operating systemsExperience supporting Microsoft Azure and M365 cloud environmentsWorking knowledge of NIST SP 800-171, NIST 800-61, and NIST SP 800-53Working knowledge of the MITRE ATT&CK frameworkExperience working with Security Operation Centers, physically or virtuallyExperience executing processes and procedures in compliance with required NIST and IT standardsExperience using a SIEM, such as Splunk or Sentinel, to do analysis of security anomalies and eventsExperience creating writing queries with Search Processing Language (SPL) or Kusto Query Language (KQL)Ability to work on many concurrent, and changing prioritiesAction-oriented and able to manage and meet aggressive timelines and deadlines.Must have excellent organizational and time management skills
What Would Be Nice To Have:US Government (DOD, DHS, DOE, etc.) security clearanceDeep experience with AWS and/or Azure cloud servicesDegree in computer-related or cyber fieldExperience in one or more of application security, security architecture, security code reviews, security/pentesting, cloud security, cyber threat intelligence, incident response, or security infrastructureOne or more of the following certifications:(ISC)2 Certified Information Security Professional (CISSP)SANs GIAC certification (e.g., GCIH, GCFA, etc.)Offensive-Security Certified Professional (OSCP)EC-Council Certified Ethical Hacker (CEH)CompTIA Security+AWS and/or Azure CloudMicrosoft Security (Operations Analyst/Engineer/Administrator) AssociateExperience working with firewalls/web application firewalls, implementing changes, and monitoring statusExperience conducting Incident Response and Security InvestigationsWorking knowledge of Active Directory, Exchange, SharePoint, and TeamsDemonstrated ability to learn and document new technologies/solutionsExperience with ServiceNow is a plusExperience working in an ITIL environmentPreference will be given to candidates who are located within 50 miles of a Guidehouse office.

The annual salary range for this position is $118,000.00-$196,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

Medical, Rx, Dental & Vision Insurance

Personal and Family Sick Time & Company Paid Holidays

Position may be eligible for a discretionary variable incentive bonus

Parental Leave and Adoption Assistance

401(k) Retirement Plan

Basic Life & Supplemental Life

Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

Short-Term & Long-Term Disability

Student Loan PayDown

Tuition Reimbursement, Personal Development & Learning Opportunities

Skills Development & Certifications

Employee Referral Program

Corporate Sponsored Events & Community Outreach

Emergency Back-Up Childcare Program

Mobility Stipend

About Guidehouse

Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com.  Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse.  Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Confirm your E-mail: Send Email