{"schemaVersion":"jobsearcher.job.v1","id":"442cb00a1c67f0b15c4bc8f7","url":"https://jobsearcher.com/jobs/442cb00a1c67f0b15c4bc8f7","canonicalUrl":"https://jobsearcher.com/jobs/442cb00a1c67f0b15c4bc8f7","title":"Cyber Security Engineer","description":"The National Energy Research Scientific Computing Center (NERSC) at Lawrence Berkeley National Laboratory (LBNL) is inviting applications for the position of Cyber Security Engineer.\r\nNERSC's mission is to accelerate scientific discovery through high performance computing and data analysis for the DOE Office of Science programs. NERSC provides critical HPC and data systems and support for NERSC's 10,000 users researching alternative energy sources, climate science, energy efficiency, environmental science and other DOE mission areas.\r\nIn this exciting role, you will be involved in all aspects of cyber security at NERSC, working both independently and collaboratively with the rest of the security team to monitor for malicious and unauthorized activity, perform vulnerability scanning and application security testing, participate or lead responses to security incidents, work with other NERSC staff and end-users to provide security guidance, perform security assessments and reviews, assist in the remediation or mitigation of cyber security issues, and contribute to the NERSC strategy as we move to exascale and beyond.\r\nAt NERSC, you will work in a collaborative, interdisciplinary environment with opportunities to explore emerging technologies, become involved in cross-team projects, and attend NERSC seminars on a wide range of scientific and technical subjects.\r\nYou will\r\nPerform security duties including monitoring for potential threats, proactively examining network traffic and log data, investigating anomalous activity, forensic analysis, and resolution of security incidents.\r\nSupport and/or lead cyber incident response activities, participating in the full incident response lifecycle, from initial detection through resolution and post-incident documentation.\r\nMaintain up-to-date awareness of cybersecurity threats and trends by monitoring a variety of information sources. Assess emerging security issues to determine risk and impact to the center, advise on appropriate response strategies, and coordinate mitigation efforts across teams.\r\nAssist with vulnerability assessment activities,including configuration of scanning tools, assessment of vulnerabilities reported from a variety of sources, prioritization and triage of discovered vulnerabilities, and working closely with NERSC staff and end users to guide remediation efforts.\r\nParticipate in 24/7 on-call rotation, occasionally working outside of scheduled hours as needed.\r\nContribute to the design and development of NERSC's security architecture, identify and address operational gaps in monitoring and detection capabilities, and help evaluate and develop new cyber security tools and technologies.\r\nParticipate or lead efforts to upgrade existing systems to meet evolving needs, including the specification, purchase, installation, configuration, and deployment of new hardware and security services.\r\nPerform system administration tasks, troubleshooting, and hardware maintenance and support as needed. Help maintain and manage existing cybersecurity systems using automation tools.\r\nDevelop comprehensive documentation of the team's technical systems, processes, and procedures.\r\nDevelop and add new signatures to IDS and monitoring infrastructure based on emerging threats and data from past incidents, ensuring detection capabilities align with the latest attack vectors and vulnerabilities. Regularly review and refine existing rules and signatures to enhance accuracy, reducing false positives and negatives.\r\nLead or support the design and implementation of security initiatives, including a Zero Trust strategy, that reduce and mitigate risk while continuing to enable NERSC's open science mission.\r\nPromote a strong security culture through outreach, technical consulting, and security awareness activities.\r\nProvide guidance on security best practices, assist with the implementation of security controls, and effectively communicate security policies and requirements to NERSC staff and users.\r\nCollaborate closely with NERSC system engineers and software developers to integrate cyber security tools and processes throughout the center.\r\nConduct in-depth security reviews and risk assessments, analyzing both technical and non-technical factors to identify weaknesses in existing and proposed deployments. Document review findings in detailed reports, providing actionable recommendations for addressing identified security issues and mitigating risk.\r\nServe as a security subject matter expert on cross-functional projects and initiatives, offering guidance based on security best practices, identifying and communicating security issues, and collaborating with others to ensure security is a key consideration across all phases of the project.\r\nContribute to the development of cybersecurity requirements, translating high-level policy into actionable security controls and guidelines. Assist with maintaining and updating documentation in a central repository.\r\nCreate technical guides, best practices, and other resources to assist NERSC staff and users in understanding.\r\nMay lead technical initiatives or projects focused on advancing security in areas such as containerized environments, secure software practices, Zero Trust Architecture, and secure data movement in HPC and scientific workflows.\r\nWe are looking for\r\nTypically requires a minimum of 8 years of related experience with a Bachelor's degree; or 6 years and a Master's degree; or equivalent experience.\r\nExperience administering Linux/Unix systems or configuring network security devices.\r\nExperience using cybersecurity tools and technologies, such as intrusion detection/prevention systems, firewalls, SIEM platforms, or vulnerability scanners, with demonstrated proficiency in at least one.\r\nExperience designing, implementing, and maintaining network traffic capture and monitoring solutions for complex, high-speed network environments.\r\nExperience performing or supporting incident response activities, including investigation, analysis, containment, and resolution of incidents.\r\nExperience collecting, parsing, and analyzing log and telemetry data from a variety of systems (e.g., servers, network devices, user sessions) to detect and respond to incidents.\r\nExperience leading the implementation or administration of IT infrastructure, leading projects or teams, or providing technical direction for operations or security initiatives.\r\nExperience developing scripts or programs in Python, Shell, C, C++, or similar languages.\r\nKnowledge of common security vulnerabilities and mitigations, attacker TTPs and associated detection methods, and an understanding of core cybersecurity principles.\r\nDemonstrated ability to work in a Linux or UNIX environment, primarily at a Command Line Interface (CLI).\r\nAbility to troubleshoot and resolve complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.\r\nIn-depth knowledge of network security and upper-layer protocols.\r\nAbility to network and collaborate with key contacts beyond one's area of expertise, and to work effectively both independently and within interdisciplinary teams.\r\nAbility to manage multiple tasks and respond to rapidly changing priorities.\r\nExcellent oral and written communication skills.\r\nDesired skills/knowledge:\r\nExperience working in High Performance Computing, higher education, or research environments.\r\nExperience implementing Zero Trust architectures, securing container platforms and workloads, or integrating security into development and deployment processes.\r\nExperience conducting policy compliance activities, such as auditing against cybersecurity frameworks (e.g., NIST, ISO 27001, CIS Controls), and performing vulnerability or risk assessments.\r\nExperience securing large-scale computing or open network environments with broadly accessible infrastructure.\r\nFamiliarity with configuration automation tools such as puppet or ansible.\r\nKnowledge of dual-stack (IPv4/IPv6) and IPv6-only network environments, including common security challenges and strategies.\r\nKnowledge of API security, including secure API design principles and familiarity with OAuth 2.0, JWT, and API key management.\r\nUnderstanding of secure coding practices, with the ability to review source code for vulnerabilities and collaborate with development teams on secure solutions.\r\nKnowledge of data analytics, machine learning, or statistical models and their application to security analysis.\r\nWe're here for the same mission, to bring science solutions to the world. Join our team and YOU will play a supporting role in our goal to address global challenges! Have a high level of impact and work for an organization associated with 17 Nobel Prizes!\r\nWhy join Berkeley Lab?\r\nWe invest in our employees by offering a total rewards package you can count on\r\nExceptional health and retirement benefits, including pension or 401K-style plans\r\nOpportunities to grow in your career - check out our Tuition Assistance Program\r\nA culture where you'll belong - we are invested in our teams!\r\nIn addition to accruing vacation and sick time, we also have a Winter Holiday Shutdown every year.\r\nParental bonding leave (for both mothers and fathers)\r\nPet insurance\r\nAdditional information\r\nAppointment type: This is a full-time, career appointment, exempt (monthly paid) from overtime pay.\r\nSalary range: The expected salary for this position is $156,864 - $191,724, which fits into the full salary of $139,440 - $235,308 depending upon the candidate's skills, knowledge, and abilities. This includes education, certifications, and years of experience.\r\nBackground check: This position is subject to a background check. Any convictions will be evaluated to determine if they directly relate to the responsibilities and requirements of the position. Having a conviction history will not automatically disqualify an applicant from being considered for employment.\r\nWork modality: This position requires substantial on-site presence, but is eligible for a flexible work mode, and hybrid schedules may be considered. Hybrid work is a combination of performing work on-site at Lawrence Berkeley National Lab, 1 Cyclotron Road, Berkeley, CA and some telework. Individuals working a hybrid schedule must reside within 150 miles of Berkeley Lab. Work schedules are dependent on business needs.\r\nWant to learn more about working at Berkeley Lab? Please visit: careers.lbl.gov\r\nEqual Employment Opportunity Employer\r\nThe foundation of Berkeley Lab is our Stewardship Values: Team Science, Service, Trust, Innovation, and Respect; and we strive to build community with these shared values and commitments. Berkeley Lab is an Equal Opportunity Employer. We heartily welcome applications from all who could contribute to the Lab's mission of leading scientific discovery, excellence, and professionalism. In support of our rich global community, all qualified applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected categories under State and Federal law.\r\nBerkeley Lab is a University of California employer. It is the policy of the University of California to undertake affirmative action and anti-discrimination efforts, consistent with its obligations as a Federal and State contractor.\r\nMisconduct Disclosure Requirement: As a condition of employment, the finalist will be required to disclose if they are subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct, are currently being investigated for misconduct, left a position during an investigation for alleged misconduct, or have filed an appeal with a previous employer.\r\nJ-18808-Ljbffr","company":"Isaca","rawCompany":"isaca","city":"Berkeley","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-04-09T15:39:50.391Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541715","title":"Research and Development in the Physical, Engineering, and Life Sciences (except Nanotechnology and Biotechnology)","slug":"research-and-development-in-the-physical-engineering-and-life-sciences-except-nanotechnology-and-biotechnology"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cyber Security Engineer","description":"The National Energy Research Scientific Computing Center (NERSC) at Lawrence Berkeley National Laboratory (LBNL) is inviting applications for the position of Cyber Security Engineer.\r\nNERSC's mission is to accelerate scientific discovery through high performance computing and data analysis for the DOE Office of Science programs. NERSC provides critical HPC and data systems and support for NERSC's 10,000 users researching alternative energy sources, climate science, energy efficiency, environmental science and other DOE mission areas.\r\nIn this exciting role, you will be involved in all aspects of cyber security at NERSC, working both independently and collaboratively with the rest of the security team to monitor for malicious and unauthorized activity, perform vulnerability scanning and application security testing, participate or lead responses to security incidents, work with other NERSC staff and end-users to provide security guidance, perform security assessments and reviews, assist in the remediation or mitigation of cyber security issues, and contribute to the NERSC strategy as we move to exascale and beyond.\r\nAt NERSC, you will work in a collaborative, interdisciplinary environment with opportunities to explore emerging technologies, become involved in cross-team projects, and attend NERSC seminars on a wide range of scientific and technical subjects.\r\nYou will\r\nPerform security duties including monitoring for potential threats, proactively examining network traffic and log data, investigating anomalous activity, forensic analysis, and resolution of security incidents.\r\nSupport and/or lead cyber incident response activities, participating in the full incident response lifecycle, from initial detection through resolution and post-incident documentation.\r\nMaintain up-to-date awareness of cybersecurity threats and trends by monitoring a variety of information sources. Assess emerging security issues to determine risk and impact to the center, advise on appropriate response strategies, and coordinate mitigation efforts across teams.\r\nAssist with vulnerability assessment activities,including configuration of scanning tools, assessment of vulnerabilities reported from a variety of sources, prioritization and triage of discovered vulnerabilities, and working closely with NERSC staff and end users to guide remediation efforts.\r\nParticipate in 24/7 on-call rotation, occasionally working outside of scheduled hours as needed.\r\nContribute to the design and development of NERSC's security architecture, identify and address operational gaps in monitoring and detection capabilities, and help evaluate and develop new cyber security tools and technologies.\r\nParticipate or lead efforts to upgrade existing systems to meet evolving needs, including the specification, purchase, installation, configuration, and deployment of new hardware and security services.\r\nPerform system administration tasks, troubleshooting, and hardware maintenance and support as needed. Help maintain and manage existing cybersecurity systems using automation tools.\r\nDevelop comprehensive documentation of the team's technical systems, processes, and procedures.\r\nDevelop and add new signatures to IDS and monitoring infrastructure based on emerging threats and data from past incidents, ensuring detection capabilities align with the latest attack vectors and vulnerabilities. Regularly review and refine existing rules and signatures to enhance accuracy, reducing false positives and negatives.\r\nLead or support the design and implementation of security initiatives, including a Zero Trust strategy, that reduce and mitigate risk while continuing to enable NERSC's open science mission.\r\nPromote a strong security culture through outreach, technical consulting, and security awareness activities.\r\nProvide guidance on security best practices, assist with the implementation of security controls, and effectively communicate security policies and requirements to NERSC staff and users.\r\nCollaborate closely with NERSC system engineers and software developers to integrate cyber security tools and processes throughout the center.\r\nConduct in-depth security reviews and risk assessments, analyzing both technical and non-technical factors to identify weaknesses in existing and proposed deployments. Document review findings in detailed reports, providing actionable recommendations for addressing identified security issues and mitigating risk.\r\nServe as a security subject matter expert on cross-functional projects and initiatives, offering guidance based on security best practices, identifying and communicating security issues, and collaborating with others to ensure security is a key consideration across all phases of the project.\r\nContribute to the development of cybersecurity requirements, translating high-level policy into actionable security controls and guidelines. Assist with maintaining and updating documentation in a central repository.\r\nCreate technical guides, best practices, and other resources to assist NERSC staff and users in understanding.\r\nMay lead technical initiatives or projects focused on advancing security in areas such as containerized environments, secure software practices, Zero Trust Architecture, and secure data movement in HPC and scientific workflows.\r\nWe are looking for\r\nTypically requires a minimum of 8 years of related experience with a Bachelor's degree; or 6 years and a Master's degree; or equivalent experience.\r\nExperience administering Linux/Unix systems or configuring network security devices.\r\nExperience using cybersecurity tools and technologies, such as intrusion detection/prevention systems, firewalls, SIEM platforms, or vulnerability scanners, with demonstrated proficiency in at least one.\r\nExperience designing, implementing, and maintaining network traffic capture and monitoring solutions for complex, high-speed network environments.\r\nExperience performing or supporting incident response activities, including investigation, analysis, containment, and resolution of incidents.\r\nExperience collecting, parsing, and analyzing log and telemetry data from a variety of systems (e.g., servers, network devices, user sessions) to detect and respond to incidents.\r\nExperience leading the implementation or administration of IT infrastructure, leading projects or teams, or providing technical direction for operations or security initiatives.\r\nExperience developing scripts or programs in Python, Shell, C, C++, or similar languages.\r\nKnowledge of common security vulnerabilities and mitigations, attacker TTPs and associated detection methods, and an understanding of core cybersecurity principles.\r\nDemonstrated ability to work in a Linux or UNIX environment, primarily at a Command Line Interface (CLI).\r\nAbility to troubleshoot and resolve complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.\r\nIn-depth knowledge of network security and upper-layer protocols.\r\nAbility to network and collaborate with key contacts beyond one's area of expertise, and to work effectively both independently and within interdisciplinary teams.\r\nAbility to manage multiple tasks and respond to rapidly changing priorities.\r\nExcellent oral and written communication skills.\r\nDesired skills/knowledge:\r\nExperience working in High Performance Computing, higher education, or research environments.\r\nExperience implementing Zero Trust architectures, securing container platforms and workloads, or integrating security into development and deployment processes.\r\nExperience conducting policy compliance activities, such as auditing against cybersecurity frameworks (e.g., NIST, ISO 27001, CIS Controls), and performing vulnerability or risk assessments.\r\nExperience securing large-scale computing or open network environments with broadly accessible infrastructure.\r\nFamiliarity with configuration automation tools such as puppet or ansible.\r\nKnowledge of dual-stack (IPv4/IPv6) and IPv6-only network environments, including common security challenges and strategies.\r\nKnowledge of API security, including secure API design principles and familiarity with OAuth 2.0, JWT, and API key management.\r\nUnderstanding of secure coding practices, with the ability to review source code for vulnerabilities and collaborate with development teams on secure solutions.\r\nKnowledge of data analytics, machine learning, or statistical models and their application to security analysis.\r\nWe're here for the same mission, to bring science solutions to the world. Join our team and YOU will play a supporting role in our goal to address global challenges! Have a high level of impact and work for an organization associated with 17 Nobel Prizes!\r\nWhy join Berkeley Lab?\r\nWe invest in our employees by offering a total rewards package you can count on\r\nExceptional health and retirement benefits, including pension or 401K-style plans\r\nOpportunities to grow in your career - check out our Tuition Assistance Program\r\nA culture where you'll belong - we are invested in our teams!\r\nIn addition to accruing vacation and sick time, we also have a Winter Holiday Shutdown every year.\r\nParental bonding leave (for both mothers and fathers)\r\nPet insurance\r\nAdditional information\r\nAppointment type: This is a full-time, career appointment, exempt (monthly paid) from overtime pay.\r\nSalary range: The expected salary for this position is $156,864 - $191,724, which fits into the full salary of $139,440 - $235,308 depending upon the candidate's skills, knowledge, and abilities. This includes education, certifications, and years of experience.\r\nBackground check: This position is subject to a background check. Any convictions will be evaluated to determine if they directly relate to the responsibilities and requirements of the position. Having a conviction history will not automatically disqualify an applicant from being considered for employment.\r\nWork modality: This position requires substantial on-site presence, but is eligible for a flexible work mode, and hybrid schedules may be considered. Hybrid work is a combination of performing work on-site at Lawrence Berkeley National Lab, 1 Cyclotron Road, Berkeley, CA and some telework. Individuals working a hybrid schedule must reside within 150 miles of Berkeley Lab. Work schedules are dependent on business needs.\r\nWant to learn more about working at Berkeley Lab? Please visit: careers.lbl.gov\r\nEqual Employment Opportunity Employer\r\nThe foundation of Berkeley Lab is our Stewardship Values: Team Science, Service, Trust, Innovation, and Respect; and we strive to build community with these shared values and commitments. Berkeley Lab is an Equal Opportunity Employer. We heartily welcome applications from all who could contribute to the Lab's mission of leading scientific discovery, excellence, and professionalism. In support of our rich global community, all qualified applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected categories under State and Federal law.\r\nBerkeley Lab is a University of California employer. It is the policy of the University of California to undertake affirmative action and anti-discrimination efforts, consistent with its obligations as a Federal and State contractor.\r\nMisconduct Disclosure Requirement: As a condition of employment, the finalist will be required to disclose if they are subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct, are currently being investigated for misconduct, left a position during an investigation for alleged misconduct, or have filed an appeal with a previous employer.\r\nJ-18808-Ljbffr","datePosted":"2026-04-09T15:39:50.391Z","dateModified":"2026-04-09T15:39:50.391Z","hiringOrganization":{"@type":"Organization","name":"Isaca","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Berkeley","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"442cb00a1c67f0b15c4bc8f7"},"url":"https://jobsearcher.com/jobs/442cb00a1c67f0b15c4bc8f7"}}