Specific Responsibilities:
• Design, implement, and maintain the organization's security infrastructure, including firewalls, intrusion detection/prevention systems (IDS/IPS), data loss prevention (DLP), and security information and event management (SIEM) systems.
• Conduct and automate security assessments and penetration testing to identify vulnerabilities and develop mitigation strategies.
• Develop and maintain security policies, procedures, and standards in compliance with industry best practices and regulatory requirements.
• Develop and track Plan of Action and Milestones (POA&Ms) to address identified security vulnerabilities and compliance gaps.
• Support DevSecOps initiatives by developing and implementing test-driven security within a CI/CD pipeline.
• Work and support Authorization to Operate (ATOs, cATOs)
• Conduct research on emerging threats, vulnerabilities, and technologies to stay updated on the evolving security landscape.
• Participate in incident response activities, including forensic analysis, evidence gathering, and reporting.