Cyber Security Engineer
Job Title: Cyber Security EngineerLocation: Elkhart, IN - RemoteDuration: Long termMostly remote position but monthly once a week attend the office in Elkhart, INResponsibilities:Working with MSP to apply certs to switches, firewalls, WAPWorking on SOC/MDR service implementation and onboarding – procedures for service etc.Testing of segmentation security controlsCyber Security Evaluation and Implementation Support for VMWare replacement projectAD project Cyber Security Implementation SupportNAC implementation and support Scope of Work:Monitoring & Detection (Blumira) - For each technical requirement, the workflow is: Audit - Filter - Alert· RC4/Weak Encryption Monitoring: - This is for requirement SecOps shall monitor for TGS requests using weak encryption typesResearch RC4 ticket request signaturesBuild Blumira report filters to identify users/services requesting weak encryptionHand off identified events to SecOps/SysAdmin for remediation· SPN Registration & Modifications: This is for requirement SecOps shall alert on new SPN registrations or modifications Query Blumira for existing SPN eventsAction: If logs are missing, coordinate with SysAdmin to enable AD audit policies for SPNsWork with Blumira to create custom Blumira detection rules for new registrations if not currently present· TGT Anomaly Detection (Event IDs 4768, 4769, 4771): This is for requirement SecOps shall monitor for unusual TGT requests (Event ID 4768, 4769, 4771 anomalies)Build reports to baseline and flag unusual TGT request patterns· Delegation Change Monitoring (Event IDs 4738, 4742): This is for requirement SecOps shall monitor for delegation changes (Event ID 4738, 4742)Implement tracking for sensitive account delegation changesLog Ingestion Validation – this is for requirement - ITRCC SecOps shall validate that Windows Security event logs including Event IDs 4768, 4769, 4771, 4738, and 4742 from all Domain Controllers are actively flowing into Blumira. ITRCC SysAdmin shall remediate any identified log ingestion gaps.Verify that all Domain Controllers (via Blumira agents) are successfully transmitting the five critical Event IDs (4768, 4769, 4771, 4738, 4742)Document any ingestion gaps and coordinate with SysAdmin to ensure 100% visibilityControl Validation & Gap Analysis (New Task)AD Policy Review: Pull current Active Directory Kerberos policies/settingsGap Assessment: Cross-reference AD settings with BlumiraProduce a document detailing:Current security control findingsValidation results from Kerberos event searchesRecommendations for remediating identified gapsNew detection rule suggestionsRole DescriptionThis is a contract, on-site role based in Dallas, TX, for a Cyber Security Engineer. The primary responsibilities include implementing and maintaining application security, cybersecurity, network security, and information security protocols. The engineer will also conduct vulnerability assessments, monitor systems for potential threats, and contribute to creating secure software designs. Collaboration with cross-functional teams to ensure best practices and compliance with security standards is an essential part of this role.QualificationsStrong expertise in Application Security and CybersecurityProficiency in Network Security and Information Security principlesExperience conducting Vulnerability Assessments and identifying security risksStrong analytical skills to evaluate and enhance security protocolsFamiliarity with compliance regulations and industry standards in securityBachelor’s degree in Cybersecurity, Information Technology, or a related fieldRelevant certifications such as CISSP, CEH, or CISM are a plusAbility to work collaboratively with teams and independently in an on-site environment