This position is open to U.S. Citizens and permanent residents. This onsite role requires the selected candidate to work from an HHS office in Austin, Texas. The Cybersecurity Analyst III performs senior-level cybersecurity engineering work with emphasis on security operations engineering, security platform administration, detection engineering, automation, orchestration, and cybersecurity infrastructure integration. The role supports agency on-premises and cloud environments by designing, implementing, maintaining, and enhancing security technologies used to protect agency systems, applications, hosts, networks, cloud services, and data. The Cybersecurity Analyst III also participates in incident response as needed. The Cybersecurity Operations Center (CSOC) Engineer is responsible for engineering and maintaining the technical capabilities that enable enterprise security monitoring, threat detection, incident response, threat hunting, and cybersecurity operations. This position provides senior-level expertise in SIEM engineering, security orchestration and automation, cloud security integrations, endpoint security platforms, security monitoring architecture, and detection development. The CSOC Engineer develops and maintains enterprise security monitoring infrastructure, enhances agency cybersecurity visibility, and implements technical solutions that improve the efficiency and effectiveness of security operations. This position serves as a critical technical resource responsible for ensuring security platforms generate reliable, actionable, and meaningful intelligence for cybersecurity analysts, engineers, and leadership. This position performs highly complex information security and cybersecurity engineering work. The Engineer works under limited supervision with considerable latitude for the use of initiative and independent judgment. The Engineer will research, evaluate, implement, and optimize new security technologies, detection methodologies, automation capabilities, integrations, and operational solutions used to prevent, detect, contain, and respond to cybersecurity threats. The Engineer provides expert guidance regarding cybersecurity technologies, monitoring architectures, logging standards, data onboarding strategies, security automation opportunities, and defensive engineering practices. This role partners closely with Cybersecurity Operations, Threat Hunting, Incident Response, Security Architecture, Infrastructure Services, Cloud Operations, and Application Development teams to strengthen the agency's cybersecurity posture. The Engineer also serves as a member of the Incident Response team.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior