Cyber Security System Engineer
Focus on vulnerability remediation and prioritization in a secure systems environment.
Overview
Focus on vulnerability remediation and prioritization in a secure systems environment.
You have:
- Bachelor's or Master’s Degrees are preferred in IT field.
- 5+ years of Cyber Security System experience.
- Proficiency in Server 2019 and Windows 10 environments.
- Strong troubleshooting skills and experience in resolving technical issues.
- Hands-on experience with Microsoft Systems Configuration Manager (SCCM and MECM), MDT, and OSD deployment methods.
- Excellent verbal and written communication skills to interact with end users, colleagues, and management effectively.
- Ability to explain technical concepts to non-technical individuals.
- Familiarity with Service Now and remote access/application delivery technologies.
- Understanding of the accreditation process and ability to upload artifacts to A&A systems.
- Experience with VMWare technologies such as Core VCF, NSX, AVI, Horizon Operations, and Automation is preferred.
- Knowledge of Azure, Linux administration/troubleshooting, and PowerShell scripting is preferred.
- Proficiency in Microsoft SQL Server and Active Directory administration is preferred.
Job Description
The Resettlement Support Center Asia (RSC Asia), funded by the US State Department Bureau of Population, Refugees, and Migration (PRM), assists persons throughout Asia seeking permanent resettlement in the United States. Responsible for a portfolio of 37 countries, RSC Asia: prepares refugee applications for the United States Refugee Admissions Program (USRAP) using START (a State Department–managed data system that supports the arrival and resettlement of refugees through technology); provides information to resettlement agencies about arriving refugees and offers cultural orientation training to refugees bound for the United States. RSC Asia is based in Bangkok, Thailand, with sub-offices in Mae Sot-Thailand, Kuala Lumpur-Malaysia and Cox’s Bazar-Bangladesh.
Job Overview/Summary:
The Cyber Security System Engineer will focus on Vulnerability Remediation and Prioritization, playing a key role in identifying and addressing security vulnerabilities across our systems. The primary responsibilities involve coordinating remediation efforts, tracking progress, and ensuring compliance with established policies, standards, and guidelines. The position will be responsible for a range of duties related to remediation efforts, configuration settings, system security scans, troubleshooting, and providing tier 3 and tier 4 technical support in a Windows-based environment.
Key Responsibilities:
• Collect, review, and consolidate vulnerability and compliance findings from various systems and platforms.
• Identify remediation actions, prioritize tasks, and establish schedules based on customer guidelines.
• Execute required actions to remediate identified vulnerabilities and track progress using workflow/tracking tools.
• Utilize automated security tools (e.g., ACAS, Active Directory GPO, SCCM, ServiceNow) to identify and address vulnerabilities.
• Coordinate and collaborate with internal teams and external stakeholders as necessary.
• Conduct self-test activities and respond to Cyber Task Orders issued by relevant agencies.
• Support Assessment & Authorization and Continuous Monitoring activities, ensuring compliance with NIST Risk Management Framework (RMF) requirements.
• Assist in developing and maintaining required documentation, including Body of Evidence (BoE).
• Ensure timely execution of Continuous Monitoring activities and update tracking tools accordingly.
• Configure and validate additional security tools and applications as needed (e.g., HBSS, Splunk, UAM)
• Support cyber vulnerabilities by conducting comprehensive assessments of information systems policies, technical/non-technical security components, and documentation.
• Perform system security scans and act as a point of contact for monitoring, troubleshooting, and problem resolution.
• Independently manage tasks with a proactive approach to achieving objectives efficiently.
• Ensure the provision of high-quality, secure, and resilient infrastructure that aligns with customer business needs.
• Conducted script verification checks, reviewed event logs, maintained documentation, and provided technical training.
• Provide tier 3 and tier 4 technical support and leadership in a complex, mission-critical Windows environment.
Key Working Relationships:
Position Reports to: Technology Information Security Coordinator
Position directly supervises: N/A Indirect reporting: N/A Other Internal and/or external contacts:
Internal: All RSC Asia SMT, RSC Asia IT Support teams, IRC HQ/Regional IT System Network
Engineering, Regional IT, and relevant global IT Teams
External:, PRM/RPC and Auditor Teams as required
Job Requirements
Education and Technical Skills:
• Bachelor’s or Master’s Degrees are preferred in IT field.
• 5+ years of Cyber Security System.
• Proficiency in Server 2019 and Windows 10 environments.
• Ability to self-learn, take initiative, and thrive in a dynamic environment.
• Strong troubleshooting skills and experience in resolving technical issues.
• Knowledgeable in multiple technology areas, including operating systems, networking, and systems integration.
• Hands-on experience with Microsoft Systems Configuration Manager (SCCM and MECM), MDT, and OSD deployment methods.
• Familiarity with Service Now and remote access/application delivery technologies.
• Understanding of the accreditation process and ability to upload artifacts to A&A systems.
Preferred Skills:
• Experience with VMWare technologies such as Core VCF, NSX, AVI, Horizon Operations, and Automation.
• Knowledge of Azure, Linux administration/troubleshooting, and PowerShell scripting.
• Familiarity with deploying and managing thin clients, WSUS, and inventory management.
• Proficiency in Microsoft SQL Server and Active Directory administration.
Communication and Collaboration:
• Excellent verbal and written communication skills to interact with end users, colleagues, and management effectively.
• Ability to explain technical concepts to non-technical individuals.
Working Environment:
The position is national staff who can be based in any of our RSC Asia offices located in Thailand, Bangladesh, or Malaysia. Successful candidates will be assigned to the office with available workstations.
This position may involve both domestic and international travel to support NIST 800-53 remediation efforts across the RSC Asia region. Candidates must possess a valid passport and the ability to obtain US and other necessary visas.
Qualifications
Potential interview questions
Can you explain a situation where you successfully remediated a security vulnerability? | This question assesses your hands-on experience with vulnerability management. | Describe the situation with specifics on the actions taken and the outcome achieved. |
How do you prioritize tasks when managing multiple security vulnerabilities? | The interviewer wants to understand your project management and time management skills. | Pro members can see the explanation. |
What automated tools have you used for vulnerability scanning and how effective have they been? | Pro members can see the explanation. | Pro members can see the explanation. |
Describe a time when you had to explain a complex technical concept to a non-technical audience. | Pro members can see the explanation. | Pro members can see the explanation. |
How do you stay current with the latest threats and vulnerabilities in cyber security? | Pro members can see the explanation. | Pro members can see the explanation. |