Job Description: Leidos has a current job opportunity for a Palo Alto Security Engineer. This position is located at Scott AFB in O'Fallon, IL. Primary Responsibilities o Serve as the subject matter expert for network security components such as firewalls, VPN, IPS/IDS. o Provide analytic & countermeasure support for Palo Alto security solutions. o Work with Security Information and Event Management (SIEM), Threat and Vulnerability Management, Web Application Firewalls (WAF), Intrusion Detection/Prevention Systems, Big Data Platforms, and Cloud Security solutions. o Recommend enhancements to network security that will improve the security of the network. o Creates and maintains documentation of networks and network systems. o Follows project methodologies to complete assigned tasks. o Provides technical network expertise to others as necessary. o Configures new network equipment and connections. o Handle day-to-day security related tickets. Basic Qualifications o Active Secret clearance (TS/SCI preferred). o Experience developing and tuning Palo Alto IDS/IPS signatures and rules. o Associates Degree and 2+ years of experience (experience working directly with Palo Alto can substitute in lieu of degree) o DoD 8570 IAT II (Sec+, CCNA Security, GSEC, CySA+) prior to starting and CSSP-A Certification (CEH, CySA+, GCIA, GCIH, SCYBER) within 180 days of hire. o Extensive familiarity with intrusion detection/prevention methodology. o Demonstrated understanding of TCP/IP, common networking ports and protocols. o Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs). o Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements. Preferred Qualifications. o Palo Alto certifications (ACE, PCNSE). o Advanced certifications such as SANS GIAC/GCIA/GCIH, CISSP or CASP and/or SIEM-specific training and certification. o CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization or Security Operations Center. o Demonstrated commitment to training, self-study and maintaining proficiency in the technical cyber security domain o Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings. o Familiarity or experience in Intelligence Driven Defense and/or Cyber Kill Chain methodology. o Demonstrated hands-on experience analyzing high volumes of logs, network data (e.g. Netflow, FPC), and other attack artifacts in support of incident investigations. o In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. Nitro/McAfee Enterprise Security Manager, ArcSight, QRadar, LogLogic, Splunk). o Experience and proficiency with any of the following: Anti-Virus, HIPS, ID/PS, Full Packet Capture, Host-Based Forensics, Network Forensics. o Experience with malware analysis concepts and methods. o Unix/Linux command line experience. o Scripting and programming experience. Job #: TR-661702
