*Role : Security Admin with Arcsight Experience. *
*Location : Atlanta, GA*
*Duration : 1 Year*


*Profiles with below skills will be ideal. Not looking for an expert in
Arcsight Admin.*
1.       Security Operation Center  ( Working as L3 with focus on Security
Incident Response)
2.       Experience with ArcSight ( Monitoring/responding to security
events, developing new content)

*Job Description:*
Develop content for enterprise SIEM application, combining big data
security information collection, management, and analytics capabilities
with full network and log-based visibility and automated threat
intelligence from commercial vendor and other government agencies.
Develop and upgrade dashboards, channels, filters, rules, and reports, as
needed. Integrate threat intelligence. Maintain and upgrade application to
current supported version. Patch and update application software as needed.
Maintain version control and document all changes.
Develop processes for application use by all ArcSight users.
Provide support for Information Security requests: Review security policy
clarifications and exception requests; lead Security projects; triage
general security questions from other internal teams.
Tune, monitor and analyze network traffic and respond to IDS alerts
Analyze network and host-based security logs to identify potential security
threats. Participate in incident response and triage
Participate in an on call rotation including after hours and weekends to
support critical security issues. Drive down mean time to resolution for
all Security work. Continuously create and review documentation for
Security Operations procedures.
Work with the GRC team to develop the policies, standards and procedures
related to Security Management.
Recommend steps and plans to improve EPA’s security posture via security
device placement, optimization of existing architecture, and evaluation and
implementation of new technologies.
Assess new and emerging security threats to identify security risks and
impacts to WAN and data center operations.
Provide technical guidance for and participate in the installation,
configuration, and management of enterprise security infrastructure,
including IPS, firewalls, VPN, and vulnerability scanners.
Review IPS system and SIEM tool logs, report potentially malicious
findings, and assist with incident response activities.
Assist firewall team with development, review, implementation, and audit of
firewall rules.
Oversee the hardening, monitoring, and maintenance of security components
to provide protection against malicious external threats to EPA’s intranet,
public access, and DMZ networks.
Provide weekly and monthly status, performance, and compliance reports as
required by client.
Participate in a 24x7 on-call support rotation to resolve issues with
security infrastructure devices.
Assist system administrators with interpretation of vulnerability scan
results and remediation efforts as needed.
Review general support systems (GSS) and application security plans for
compliance with NIST guidelines, and help document the implementation and
successful operation of technical security controls.
Support and participate in external oversight audits as needed. Document
audit findings in a Plan of Action and Milestones (POAM), and track
mitigation progress.
Maintain and update Standard Operating Procedures and Standard
Configuration Documents for security infrastructure components.
Closely coordinate with and assist other task orders and teams as required,
especially the Network Operations team, Internet and managed service
providers, and Enterprise Computer Security Incident Management (ECSIM).


*Mazhar Khan*
*||Tel: 703-962-7227 X 427 || Fax: 703-439-2550 || *
*Email: maz...@gsquire.com <maz...@gsquire.com>*
*Gsquire Business Solutions Inc || www.gsquire.com <http://www.gsquire.com>
|| 4229 Lafayette Center Dr , Suite #1625, Chantilly, VA 20151Women Owned
Small Business / MBE / SWAM Certified*

-- 
You received this message because you are subscribed to the Google Groups "SAP 
Resource Center" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to sap-resource-center+unsubscr...@googlegroups.com.
To post to this group, send email to sap-resource-center@googlegroups.com.
Visit this group at https://groups.google.com/group/sap-resource-center.
For more options, visit https://groups.google.com/d/optout.

Reply via email to