Senior Cybersecurity Engineer

Devens, MA
Corporate Operations – IT /
Full-time /
Hybrid
The Senior Cybersecurity Engineer reports to the Director of Cybersecurity and is responsible for cybersecurity operations at CFS as part of a team of cybersecurity engineers. The role includes strong collaboration with internal IT teams, as well as a focus on promoting cybersecurity awareness and training. The Sr Cybersecurity Engineer provides systems administration for day-to-day cybersecurity operations and security advice to advance the cybersecurity program. They will implement and administer systems needed to ensure that operations are properly executed, ranging from firewalls to SIEM, DLP, Network Security, threat intelligence, vulnerability management, DevSecOps, OT, and EDR. The role also assesses new systems and applications before they are implemented using appropriate/applicable testing and evaluation techniques.

This team member will:

    • Monitor and advance the operations of systems and services to ensure organizational confidentiality, integrity, and availability
    • Assist in vulnerability management and threat intelligence, tracking and mitigating threats as necessary
    • Lead cloud and network security efforts (SaaS, AWS, CNAPP, WAF), along with the tools that enable auditing/reporting
    • Be responsible for the administration of cybersecurity tools needed to achieve the cybersecurity mandate (SIEM, DLP, IAM, PAM, EPP/EDR, MDM, etc.)
    • Analyze and recommend security controls and procedures in the acquisition, development, and change management lifecycle of information systems, and provides oversight to ensure compliance
    • Maintain current knowledge of new products and industry trends, and recommends enhancements and purchases that allow CFS to maintain a healthy and functional environment
    • Provide technical consulting to management, business users, and technical associates to ensure that applications and platforms are secure
    • Architect, design, implement, maintain and operate information system security controls and countermeasures; document the operation, use, and expected outputs of these systems
    • Analyze and recommend security controls and procedures in business processes related to use of information systems and assets, and provides oversight to ensure compliance and alignment with security standards/frameworks (NIST 800-53)
    • Help promote a culture of cybersecurity awareness via outreach and training

The ideal candidate will have most, if not all, of these requirements:

    • Bachelor degree in Cybersecurity, Computer Science or equivalent experience
    • Relevant certification in the Cybersecurity field (CISSP preferred)
    • 5 years experience in a hands-on security focused role
    • Demonstrated ability to apply fundamental cybersecurity and IT concepts to tasks and projects
    • Hands-on experience managing enterprise security technologies (SIEM, firewall, IDS/IPS, EPP/EDR, IAM, DLP, etc.)
    • Experience securing IaaS (e.g. AWS)
    • Familiarity with regulatory, compliance, and security frameworks (NIST, ISO, SOC 2)
    • Ability to work in a fast-paced environment and prioritize tasks/projects
    • Experience securing cloud applications (IaaS and SaaS)
    • Automation of security tasks
    • Excellent analytical and problem solving skills, and attention to detail
    • Computer forensics
    • Evidence of personal focus on continuous learning

Additional experience and/or qualifications:

    • AWS Security certification
    • Ability to type, stand, and sit for extended periods of time
    • Willingness to occasionally travel or work required nights/weekends/on-call
    • Work in a facility that contains industrial hazards including heat, cold, noise, fumes, strong magnets, lead (Pb), high voltage, high current, pressure systems, and cryogenics
    • #LI-Hybrid