ASD is a wholly owned subsidiary of CTI
CTI is seeking for IMMEDIATE HIRE a senior, hands-on Cybersecurity Engineer to support day-to-day security operations, log analysis, incident investigation, and remediation across the National Indian Gaming Commission's hybrid IT environment. This role works closely with the IT Operations and Records Management teams to ensure cohesive execution across all three program areas. The ideal candidate is a working engineer, not just a governance or compliance voice — someone who can get into the tools, find the problem, and fix it.
Support SCuBA (Secure Cloud Business Applications) compliance baseline implementation and assessment for Microsoft 365/cloud environments.
Maintain FISMA-aligned security operations, working within NIST-based control frameworks.
Configure and monitor Microsoft Azure security controls, including conditional access, hybrid/Azure Arc integration, and Azure Monitor/Sentinel or Defender for Cloud where applicable.
Apply knowledge and skills of information systems security principles, NIST guidelines, FISMA, CISA, and federal directives, to conduct ongoing security assessments of installed systems and networks with a view to recommend corrective actions.
Perform systems engineering and maintenance activities according to established standards.
Apply knowledge of Networking Technologies including LAN, MS Azure, and Wireless management in security solutions implementation and troubleshooting. d. Develop agency’s security operations capabilities by evaluating current strategies and pursuing alignment with best practices.
Ensure the effective configuration and daily operations of tools that support the agency’s cybersecurity strategy. Such tools include SEIM integration, Syslog, Network Detection and Response (NDR), Endpoint Detection and Response (EDR), Firewalls, M365 Cloud security, Defender for Cloud, and Continuous Diagnostics & Mitigation (CDM) capabilities.
In collaboration with CISO and Privacy Officer develop plans, techniques, and measurable objectives to improve the development of cybersecurity and privacy measures that meet agency’s goals for protecting sensitive information.
Collaborate with other teams on the integration of agency Applications and IT services to consider security implications and ensure that AGENCY security requirements are met.
Maintain threat awareness and monitor agency information systems for exploits and any suspicious activities. Analyze aggregated logs from security tools and perform regular threat hunting activities.
Develop Security Orchestration and Automation capabilities.
Adhere to Continuous Monitoring practices to evaluate the effectiveness of implemented security controls and execute proactive threat hunting activities to ensure confidentiality, integrity, and availability of agency information systems.
Develop detection and response configuration policies to increase automation.
Execute Incident Response activities to include all associated actions according to the agency incident response plan.
Develop Incident handling procedures.
Validate that sufficient and relevant information is captured and retained from security tools to support actionable security awareness and incident investigations.
Collect security operations performance and agency security posture management metrics and prepare agency threat reports to inform risk management decisions.
Develop and maintain accurate security operations documentation including the preparation of standard operating procedures for recurring tasks.
Collaborate cohesively with the IT Systems Engineer and Records Management Specialist to ensure security posture is integrated across infrastructure and records functions.
Communicate findings and remediation status clearly to agency leadership.
Minimum 6 years of experience operating specifically at a senior level — not simply total years in IT or cybersecurity, but demonstrated senior-level ownership and independent execution.
Genuine, hands-on Microsoft Azure experience is required. This means direct, personal configuration and administration experience — not familiarity from a distance. Candidates must be able to speak in specific technical detail about environments supported, actions personally taken, and outcomes achieved.
Hands-on experience with the following tools:
SIEM Tool : 5 years (Required)
Syslog and Log Collection tools: 5 years (Required)
Network Detection & Response (NDR) tools: 5 years (Required)
Endpoint Detection & Response (EDR) tools: 5 years (Required)
Firewalls / Network Security Gateways tools: 5 years (Required)
M365 Cloud Security tools: 3 years (Required)
Continuous Diagnostics & Mitigation (CDM): 5 years (Required)
IT Security: 9 years (Required)
Ability to discuss technical work in depth during a live technical interview — candidates should expect to be asked to walk through specific projects, tools, and decisions, not just list skills.
Active Public Trust clearance strongly preferred; must be able to pass a new background investigation without issue.
Must be a hands-on engineer/analyst ready to absorb existing tools and refine policy with minimal ramp-up — this is not a purely oversight, governance, or management-level role.
Direct experience with FISMA, STIG baselines, and ideally SCuBA compliance baselines.
Experience performing hands-on threat investigation, log analysis, and remediation — not solely policy or audit work.
Relevant certifications such as CISSP, CySA+, CASP+, or equivalent.
Prior experience supporting a federal agency's security operations.
Level of Security Clearance: Public Trust [Required]