Security Engineer
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, IT Consultant
Cyber Security Engineer
The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a U.S. Government program responsible for preventing, identifying, containing, and eradicating cyber threats to CBP networks through monitoring, intrusion detection, and protective security services to CBP information systems, including LAN/WAN, commercial Internet, public-facing websites, wireless, mobile/cellular, various cloud environments, security devices, servers, and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems and for collecting, investigating, and reporting any suspected and confirmed security violations.
PrimaryResponsibilities
The Cyber Security Engineer will support the full system engineering life‑cycle, including requirements analysis, design, development, test, implementation, maintenance, integration, and documentation of SOC infrastructure and SOC tool suite.
The Security Engineer will install, configure, monitor, and troubleshoot network security solutions and related monitoring tools, including L2/L3 network security devices, IDS/IPS, full packet capture, DLP, Endpoint (AV, DLP, Endpoint Detection & Response), and infrastructure supporting SEIM (Splunk).
The Security Engineer must have an understanding and knowledge of LAN/WAN security solutions, including creating and maintaining LAN/WAN security standards and design documentation.
Knowledge and familiarity with new LAN/WAN security applications and hardware as assigned.
Knowledge and hands‑on experience with securing AWS environments, automating controls, and supporting enterprise security operations.
Ability to script in one or more of the following computer languages:
Python, Bash, Visual Basic, or Power Shell.
Strong written and oral communication skills with the ability to communicate with team members, management, and customers.
Tools & Skills- 2‑4 years’ experience in Systems Engineer/Admin role or an equivalent of 2‑4 years in Cybersecurity.
- Hands‑on experience on AWS – majority of the environment systems are in AWS. These may include EC2, Storage, Lambda, S3, VPC, Storage Gateways.
- Hands‑on experience with Linux – more than half of the systems being managed are Linux, including CentOS, Amazon Linux 2, RHEL, Kali Linux, and Rocky Linux. Knowledge/experience in patching and updating these will be key.
- Knowledge/experience with Windows – need knowledge in setting up and building using images. Someone who knows the ins and outs of where logs and other locations of data are on a Windows system is a plus.
- Hands‑on experience with troubleshooting – mid to high level troubleshooting skills. Have the knowledge and experience on where to look for logs and errors within applications and OS’s.
- Knowledge and understanding of networking and how it all ties together – networking knowledge, VPNs, DNS, DHCP, AWS VPCs, Firewalls.
- Knowledge/experience on applications – automation software such as Ansible, Windows SCCM, or any automation software.
- Understanding of cybersecurity processes and protocols.
- Knowledge and understanding of some antivirus software such as McAfee and Crowd Strike. Any HIPS software and how it works.
- Understanding of SOPs, Playbooks, and experience creating documentation.
- Knowledge with platform hardening.
- Bachelor’s degree in computer science, engineering, software development, information technology, cyber security, or related field and 6 years of related experience. Additional years of experience and cyber certifications may be considered in lieu of a degree.
- Familiar with the management, operational, and technical aspects of IT security in a complex enterprise environment. Additional experience in cyber risk management and assessments will be considered.
- Knowledge and familiarity with in-depth analysis of Zero Trust capabilities, infrastructures, and architecture.
- Ability to learn and support new systems and applications.
- Redhat, Cisco or Microsoft, Security+, Linux+, or Network+ certifications.
- Cisco Hardware and Storage.
- Expertise in networking, Linux, and Windows.
- Source fire (Snort)…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).