Role: Cybersecurity Engineer
Location: Richmond, VA
Long Term Contract
Job Summary:
We are seeking a Cybersecurity Engineer to join our security team. The ideal candidate will have strong expertise in cloud security (AWS, Azure, or GCP), deep knowledge of networking concepts, and hands-on experience with security tools and frameworks. You will be responsible for securing cloud environments, monitoring threats, implementing security controls, and ensuring compliance with security policies.
Key Responsibilities:
- Design, implement, and manage cloud security controls in AWS, Azure, or GCP.
- Monitor and respond to security incidents using SIEM tools (Splunk, QRadar, etc.).
- Perform vulnerability assessments and penetration testing to identify security risks.
- Implement firewalls, IDS/IPS, VPNs, and other network security tools.
- Develop and enforce security policies, standards, and best practices.
- Work closely with DevOps and network teams to secure cloud-based applications and infrastructure.
- Conduct forensic analysis and investigate security breaches.
- Manage identity and access management (IAM) controls.
- Ensure compliance with industry standards such as ISO 27001, NIST, SOC 2, CIS Benchmarks.
Required Qualifications:
- 8 years of experience in cybersecurity or a related field.
- Strong knowledge of cloud security (AWS, Azure, or GCP).
- Expertise in network security, firewalls, IDS/IPS, VPNs, TCP/IP, DNS, and routing protocols.
- Experience with SIEM, EDR, vulnerability scanners, and penetration testing tools.
- Familiarity with zero trust architecture and zero trust network access (ZTNA).
- Strong understanding of encryption, authentication protocols, and identity management.
- Knowledge of scripting or automation using Python, PowerShell, or Bash is a plus.
- Relevant certifications such as CISSP, CEH, CCSP, AWS Security Specialty, or CompTIA Security+ are preferred.
Preferred Skills:
- Experience with cloud-native security tools like AWS GuardDuty, Azure Security Center, or Google Security Command Center.
- Knowledge of container security (Docker, Kubernetes).
- Familiarity with SOC operations and threat intelligence platforms.
- Understanding of regulatory frameworks (GDPR, HIPAA, PCI-DSS).