S2i2 is a growing company with a supportive and inclusive culture and many opportunities for professional development and growth. We have created a supportive, family-like work environment where contributions are recognized. Regular company updates and open lines of communication with leadership fosters collaboration within the company.
Cybersecurity Engineer
Location
United States
Posted
29 days ago
Salary
$140K - $180K / year
Seniority
Mid Level
Job Description
Cybersecurity Engineer
S2i2 Inc
Role Description We are seeking a Cybersecurity Engineer to provide engineering and operational support for the agency's enterprise Data Loss Prevention (DLP) and File Content Analysis (FCA) program. This role will support the continued enhancement and sustainment of the agency's Microsoft 365 Purview implementation and the parallel deployment of Forcepoint DLP technologies for endpoint and network data protection outside the M365 environment. The engineer will be responsible for: - DLP policy development - Data classification and monitoring - FCA integration - Incident analysis - Tuning and optimization of detection capabilities - Ensuring compliance with federal cybersecurity and data protection requirements across enterprise systems and cloud environments Qualifications - 7+ years of relevant IT experience - Experience implementing modern security solutions in enterprise environments - Microsoft Purview enterprise DLP deployment experience: policy authoring, sensitive information type design, DLP rule tuning across M365, OneDrive, SharePoint Online, and Teams. Microsoft SC-400 (Information Protection Administrator) certification preferred. - Forcepoint DLP enterprise deployment experience: endpoint DLP, network DLP, fingerprinting, incident workflow. - Prior DLA, DISA, or other DoD enterprise IT experience - Experience operating in M365 GCC High and/or Azure IL4+ environments - RMF / ATO documentation experience for DLP solutions, particularly cloud-based with DoD reciprocity - Tier 3 enterprise support experience (24x7x365 on-call rotation) - Demonstrated record of DLP rule tuning that reduced false positive rates - Experience with DISA STIGs as applied to DLP infrastructure - PowerShell / Microsoft Graph API automation for DLP policy management Requirements - DoD 8570.01 IAT Level II baseline certification (Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, SSCP, or CND) - CNDSP-IS certification (CEH, CFR, CCNA-Cyber Ops, CHFI, CySA+, GCIA, GCIH, or SCYBER) - Forcepoint Certified DLP Administrator (FCDA) certification preferred or "DLP Administrator" certification Benefits - Support to achieve professional certifications and degrees - Leadership that is accessible to all employees - Regular company updates - Client networking social engagements - Monthly team-building activities (past examples: Top Golf) - Supporting our community - including veterans
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Build and mature a detection and response program • Detect and respond to security incidents and participate in an incident on-call rotation • Develop innovative ways to detect security incidents. • Design and build the security for the future of our infrastructure. • Partner with the infrastructure team, engineering team, compliance team and within security teams to maintain and further improve our cloud security posture. • Create solutions and processes to identify, resolve and mitigate security vulnerabilities and risks. • Research threats and attack vectors that impact WW applications and infrastructure. • Devise and bolster defense-in-depth through secure-by-default frameworks, architectures and processes. • Mentor and share security standards and processes with all parts of the organization.
• As a Security Engineer at Offchain Labs, you will play a key role in defining and improving our cloud security posture and collaborate across teams to ensure that our operations are secure, compliant, and aligned with regulatory and industry best practices - such as SOC2. • Leverage your extensive experience in Cloud Security to design, implement, and improve secure cloud-native architectures and CI/CD pipelines. • Apply deep expertise in cloud infrastructure security to proactively identify risks, enforce best practices, and harden systems across the entire technology stack. • Automate security controls and educate developers for future-proofing against vulnerabilities. • Play an active part in designing and evolving the company’s overall information security governance and compliance program through: policies, standards, procedures, awareness. • Work closely with engineering, infrastructure, and product teams to make sure controls fit both business objectives and technical realities.
• Assess the current cloud and infrastructure security posture across AWS environments, Kubernetes platforms, and supporting services • Identify critical gaps and define a prioritized roadmap for improving security maturity across identity, runtime, network, and platform layers • Define and implement enterprise security controls across IAM governance, workload/runtime posture, and DNS security • Embed security guardrails, standards, and policies into the Platform Engineering and Cloud Center of Excellence (CoE) frameworks from the beginning of the transformation • Partner with platform teams to design secure-by-default self-service infrastructure patterns, templates, and workflows • Establish identity and access governance models including account strategy, role design, least-privilege policies, and federated access • Design and implement security standards for Kubernetes and containerized workloads, including supply chain security, workload isolation, and runtime protection • Define DNS and network security practices, including private networking, segmentation, service discovery, and threat protection • Collaborate with DevSecOps teams to integrate automated security testing, policy enforcement, and compliance checks into CI/CD pipelines • Support the creation of security observability, monitoring, incident response, and threat detection capabilities across the platform • Provide security leadership and mentoring to engineering teams to promote security ownership and best practices • Support organizational change management and stakeholder alignment to ensure security adoption across teams • Continuously evolve the security framework as the platform and operating model mature
• Assess the current cloud and infrastructure security posture across AWS environments, Kubernetes platforms, and supporting services • Identify critical gaps and define a prioritized roadmap for improving security maturity across identity, runtime, network, and platform layers • Define and implement enterprise security controls across IAM governance, workload/runtime posture, and DNS security • Embed security guardrails, standards, and policies into the Platform Engineering and Cloud Center of Excellence (CoE) frameworks from the beginning of the transformation • Partner with platform teams to design secure-by-default self-service infrastructure patterns, templates, and workflows • Establish identity and access governance models including account strategy, role design, least-privilege policies, and federated access • Design and implement security standards for Kubernetes and containerized workloads, including supply chain security, workload isolation, and runtime protection • Define DNS and network security practices, including private networking, segmentation, service discovery, and threat protection • Collaborate with DevSecOps teams to integrate automated security testing, policy enforcement, and compliance checks into CI/CD pipelines • Support the creation of security observability, monitoring, incident response, and threat detection capabilities across the platform • Provide security leadership and mentoring to engineering teams to promote security ownership and best practices • Support organizational change management and stakeholder alignment to ensure security adoption across teams • Continuously evolve the security framework as the platform and operating model mature


