Title: Lead, Information Security Systems Engineer
Greenville, TX, US, 75402
Job Title: Lead, Information Security Systems Engineer
Job Code: 44627
Job Location: Greenville, TX
Schedule: 9/80 - Employees work 9 out of every 14 days – totaling 80 hours worked – and have every other Friday off
Job Description:
The Lead Incident Response and Security Operations Engineer establish, operates, and continuously improves the Enterprise Product and Services’ incident response and security operations capability across a government-owned, contractor-operated hybrid environment that includes Amazon Web Services (AWS), multiple data centers, and a corporate location.
The role leads monitoring, investigation, detection engineering, incident coordination, and risk escalation to strengthen the availability, integrity, and confidentiality of GSS services.
Infrastructure, system, and application owners retain responsibility for technical remediation, patching, and platform repair.
Essential Functions:
- 15% travel based on business needs (CONUS or OCONUS).
- Ability to work a flexible schedule includes off-shift work, weekends, occasional overtime, and on-call duties.
- Establish and maintain security information and event management operations, including Wazuh health, log ingestion, data-quality validation, alert rules, dashboards, and detection tuning.
- Monitor, triage, investigate, document, and coordinate response to security events across AWS, datacenter, network, endpoint, and corporate environments.
- Create and manage security-incident tickets; preserve investigation evidence; document findings and actions; and validate closure with responsible technical owners.
- Develop and maintain incident-response plans, escalation paths, severity criteria, playbooks, runbooks, and after-action reports.
- Coordinate remediation tracking for vulnerabilities, security findings, and incident corrective actions, escalating overdue or material risk.
- Conduct AWS security-alert and exposure reviews, including identity and access management, privileged access, logging, and cloud-security findings within assigned authority.
- Onboard and maintain log sources and integrations needed to support monitoring, detection, incident investigation, and compliance evidence.
- Conduct periodic reviews of privileged access, security-tool access, and operational logging coverage; support disaster-recovery and incident-response exercises.
- Produce security-operations metrics, risk reports, and stakeholder briefings, and maintain documentation supporting the Risk Management Framework, audit readiness, and continuous monitoring.
Qualifications:
- Active US Secret security clearance or higher.
- Bachelor’s Degree and minimum 9 years of prior relevant experience.
- Graduate Degree and a minimum of 7 years of prior related experience.
- In lieu of a degree, a minimum of 13 years of prior related experience.
- Current in at least one of the following; Certified Information Security Manager, Certified Information Systems Auditor, Certified Cloud Security Professional, Certificate of Cloud Security Knowledge, or comparable Department of Defense 8140 certification.
- Minimum 8 years of security operations, incident response, or security engineering experience.
- Demonstrated experience operating or engineering a security information and event management platform, developing detection rules, validating log ingestion, and tuning alerts.
- Demonstrated experience with incident triage, investigation, evidence handling, ticket management, stakeholder communications, and closure documentation.
- Demonstrated experience supporting hybrid-cloud environments, including AWS and on-premises data-center infrastructure.
Preferred Additional Skills
- Knowledge of Windows, Linux, networking, identity and access management, security logging, and vulnerability-management processes.
- Experience with SIEM, Logging and Monitoring infrastructure design, operation management
- Splunk, Wazuh, SysAid, AWS security services, or comparable security information and event management, information technology service management, and cloud-security platforms.
- Experience with MITRE ATT&CK, detection engineering, threat hunting, and alert use-case development.
- Experience developing or maintaining incident-response and disaster-recovery plans, playbooks, tabletop exercises, or technical exercises.
- Experience with plans of action and milestones, audit evidence, security assessments, and government compliance environments.
- CISSP, CISM, CCSP, GCIH, GCIA, CySA+, Security+, AWS Certified Security - Specialty, or comparable certification.
- Experience supporting government-owned, contractor-operated systems and multi-site operations.
- Experience with Risk Management Framework assessment and authorization activities, National Institute of Standards and Technology Special Publication 800-53 controls, or Platform Information Technology environments.
#LI-AM2
Nearest Major Market: Dallas
Nearest Secondary Market: Fort Worth