Experience configuring and administering security tools and products
Experience supporting security products for local governments or public sector
Hands-on experience with EDR and Vulnerability Management Systems (VMS)
Relevant cybersecurity certifications (e.g., Security+, CCFA, Tenable Certified) or equivalent
Requirements:
Administer and maintain EDR tools, including tuning detection rules, keeping asset inventory up to date, updating agents, reviewing security policies, conducting health checks, and troubleshooting unexpected agent behavior
Administer and maintain Vulnerability Management System (VMS), including tuning scan policies, updating agents, ensuring asset inventory accuracy, configuring scans, performing health checks, and troubleshooting integrations
Provide general support by responding to tickets, updating the Remote Monitoring and Management (RMM) platform, documenting troubleshooting steps and resolutions, and ensuring SLAs are met through ticket queue management and follow-ups
Coordinate and troubleshoot integrations between security tools and systems to ensure seamless operation
Job description
Ideal Candidate Profile: Seeking an experienced Cybersecurity Engineer to support Security Products for Local Governments. The ideal candidate will possess in-depth knowledge of configuring and administering Security Tools and Products.
Job Duties & Responsibilities Administer and Maintain EDR Tools
Tune detection rules to reduce false positives and improve threat visibility for each covered locality.
Ensure asset inventory is accurate and up to date for each covered locality.
Regularly update the EDR platform and agents to the latest versions.
Review and adjust security policies.
Conduct health checks to ensure the EDR system is functioning properly.
Investigate and remediate unexcepted agent behavior
Ensure that Integrations are working as required and troubleshoot when issues are identified
Administer and Maintain Vulnerability Management System
Maintain and update the vulnerability management platform and agents
Conduct health checks to ensure the VMS system is functioning properly.
Tune scan policies to reduce false positives and improve accuracy for each covered locality
Ensure asset inventory is accurate and up to date for each covered locality
Configure and schedule scans for each covered locality.
Investigate and remediate unexpected agent behavior
Ensure that integrations are working as required and troubleshoot when issues are identified
General Support
Respond to and resolve customer inquiries and issues submitted through the ticketing system and SOC
Maintain and update the Remote Monitoring and Management platform and agents
Accurately document customer interactions, troubleshooting steps, and resolutions
Escalate complex or unresolved issues as needed
Monitor ticket queues to ensure service level agreements (SLAs) are met and follow up with customers as needed