The primary role of this person is to administer, maintain and perform analysis for Cisco 8120 IDS/IPS traffic, interpret the results and implement signature tunings/reporting as the administrator. This role will be responsible for integrating the IPS with the Firewalls to implement shunning as triggered or required. This role will coordinate IDS/IPS issues with the Security Operations Center to include incident investigation and escalation.
This person will also serve as the Cisco Firewalls backup administrator.
Duties will include but are not limited to:
Security device management, auditing and monitoring
Maintenance of IDS/IPS rules and configuration
Review of security logs
Preparation of security reports and documentation for compliance and incident response
Troubleshoot and respond to system failures and alerts
Scripting for automation of repetitive processes
Requirements:
5+ years of applicable experience
Security+ or CISSP security certification highly desired
CCNA or CCNP Security highly desired
Cisco ASA series appliance knowledge
Cisco 8120 series IDS/IPS working knowledge
Network architecture domain knowledge
Experience with configuration and operation of network analysis tools
Excellent written and verbal communication skills
Ability to operate in a multi-tasking environment and effectively prioritize competing tasks
Create, update and schedule Service Desk Tickets and Change Orders
Experience with vulnerability scanning systems such as Nessus a plus
Experience with Splunk for reporting a plus
Bachelors degree in Computer Science, Engineering, Business, or related field or equivalent work experience.