Talent.com
Database Security Specialist
Database Security SpecialistEvolver Federal • USA
Database Security Specialist

Database Security Specialist

Evolver Federal • USA
30+ days ago
Job type
  • Full-time
  • Quick Apply
Job description

Evolver Federal is looking for a Database Security Specialist ­to join our team supporting our government client.

The successful candidate will work with Database Administrators, ISSOs and System Teams to support the client in ensuring the security of its databases across the enterprise. By collaborating with other stakeholders (Federal and Contractor), the candidate will support the ISD Security Tools Team and System DBAs in establishing the initial configuration of database scans using TIO (Tenable Nessus). The candidate will also monitor successful application of security patching for all databases and troubleshoot where necessary, review database-related POA&Ms and provide input into POA&M milestones and associated remediation plans, review artifacts for POA&M closure relating to documented database weaknesses and advise on closure, assist the team in hardening databases throughout the enterprise, and assist DBAs in onboarding database logs to the organization's SIEM tool. The candidate must be a self-starter.

The client environment is diverse and currently contains Oracle, Postgres, SQL Server, and mySQL databases.

Responsibilities

  • Review output of database scans using Tenable io (TIO), work with System DBAs to remediate findings, including vulnerabilities and hardening.
  • Provide input and recommendations into approved security configuration baselines for database types including Oracle, Postgres, SQL Server, and mySQL.
  • Provide input and recommendations into approved database versions based on database type.
  • Work with members of the POA&M Management Support Team to review artifacts submitted as evidence of POA&M closure for database-related weaknesses.
  • Review, validate, and track false positives and known deviations in scan results to provide assurance that IT systems meet established configuration baseline(s) for approved database types.
  • Review documentation submitted in support of requesting a waiver for compliance with specified security requirements per the NIST SP 800-53 and provide recommendations to client for approval and acceptance of associated risk. Specific to security requirements relating to databases and the database layer of a system.
  • Participate in process improvement initiatives to mature the client's internal business processes in areas including, but not limited to, vulnerability remediation, patch remediation efforts, STIG compliance, and approved database instances.
  • Work with Database Administrators, ISSOs, and System Admin Teams to configure database assets to send the appropriate logging data to Splunk / designated SIEM tool.
  • Provide recommendations for database logging standards across the enterprise for each database type within the enterprise to facilitate establishing new and enhancing existing logging standards.
  • Perform other duties as assigned by the Government.
  • Ability to work efficiently and effectively in a dynamic and fast-paced environment.
  • Determine the clearest and most logical way to present information and instructions for greatest reader comprehension and write and edit technical information accordingly.
  • Meet with other Technical SMEs (Federal and Contractor) to ensure specialized topics are appropriately addressed, discussed, and understood.

Basic Qualifications

  • Bachelor's Degree in Information Technology, Computer Science, or related field or 10 years of overall experience.
  • Minimum of 5 years of experience as a Database Administrator for Oracle and / or Postg res databases in the federal government, including configuring databases to comply with Industry-Standard configuration baselines.
  • Database certification such as Oracle Database Administrator Certified Professional, Certified PostgreSQL Database Administrator, or similar.
  • 5 years of experience with Oracle and Postgres.
  • 5 years of experience in troubleshooting complex issues involving database security settings and engaging in complex root causes analysis.
  • 5 years of experience with cloud-based environments and cloud infrastructure.
  • 3 years of experience using Tenable.io, specifically to review scan results, search, and create custom reports.
  • 3 years of experience one or more of the following tools : tenable.io, Nexus IQ Server, Splunk Enterprise v 7.3 and higher, DoJ CSAM, JIRA / Confluence, CloudCheckr, PrismaCloud
  • General awareness of the NIST SP 800-37 Risk Management Framework.
  • Must have previous client-engagement experience.
  • Must be a US Citizen with suitable eligibility for Public Trust position.
  • Preferred Qualifications

  • Experience with other database types including, but not limited to Postgres, SQL Server, or mySQL preferred, but not required.
  • Previous experience supporting Department of Homeland Security federal clients preferred.
  • Working knowledge of secure configuration guidelines for Oracle databases, specifically CIS Benchmarks.
  • General awareness of the NIST SP 800-53, specifically as the controls apply to database security.
  • Ability to work independently and possesses a solid understanding of database and cyber security concepts.
  • Ability to communicate clearly and effectively via written and verbal communication in both formal and informal situations.
  • Ability to clearly articulate database-related weaknesses for the purpose of documenting POA&M descriptions.
  • Ability to clearly articulate remediation strategies and / or compensating controls specific to database weaknesses.
  • Ability to clearly communicate complex technical concepts to Information Technology Project Managers, Database Administrators, Application Developers, and Security Compliance Analysts, as well as non-technical POCs such as Branch Chiefs and Business System Owners.
  • Ability to adapt to frequent changes in priorities, follow project schedules, meet established deadlines, and proactively communicate risks and issues to the Contractor PM and / or Federal Leads.
  • Ability to adapt to an Agile environment and provide quality, professional deliverables in a short timeframe with little to no guidance from the Government.
  • Possess good listening skills and the ability to detect explicit and implicit needs and wants of the client.
  • Demonstrated ability to exercise good judgment, prioritize multiple tasks, and problem solve under pressure of deadlines and resource constraints.
  • Possess strong analytical and critical thinking skills with the ability to apply them to the client / contract workspace.
  • Evolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military / veteran status, or any other factor protected by law.

    Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.

    Job Posted by ApplicantPro

    Create a job alert for this search

    Security Specialist • USA

    Related jobs
    Senior Defense ISSO / ISSM with Cloud experience

    Senior Defense ISSO / ISSM with Cloud experience

    Tetrad Digital Integrity LLC • US
    Permanent
    Quick Apply
    Tetrad Digital Integrity (TDI) is hiring a Senior DoD Information Systems Security Officer or Manager / Cloud Security Engineer to lead RMF for modern, cloud-hosted systems and guide non-security e...Show more
    Last updated: 12 hours ago • New!
    SOC Analyst – Associate – part time, remote

    SOC Analyst – Associate – part time, remote

    Revel IT • Remote, USA
    Remote
    Part-time
    Treat our consultants and clients the way we would like others to treat us!Interested in joining our team? Check out the opportunity below and apply today!. Our client has a part time, remote contra...Show more
    Last updated: 14 hours ago • Promoted • New!
    Consulting Director, Cloud Security, Proactive Services (Unit 42) - Remote

    Consulting Director, Cloud Security, Proactive Services (Unit 42) - Remote

    Palo Alto Networks • United States
    Remote
    Full-time
    At Palo Alto Networks® everything starts and ends with our mission : .Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and m...Show more
    Last updated: 19 days ago • Promoted
    Cyber Intelligence, Security Systems

    Cyber Intelligence, Security Systems

    L3Harris Technologies • US
    Full-time
    Our employees are unified in a shared dedication to our customers’ mission and quest for professional growth.Fundamental to our culture is an unwavering focus on values, dedication to our communiti...Show more
    Last updated: 19 hours ago • Promoted • New!
    Applications Cyber Security Lead Architect

    Applications Cyber Security Lead Architect

    Mastercard • US
    Full-time +1
    Mastercard powers economies and empowers people in 200+ countries and territories worldwide.Together with our customers, we’re helping build a sustainable economy where everyone can prosper.We supp...Show more
    Last updated: 19 hours ago • Promoted • New!
    RACF Specialist - Remote

    RACF Specialist - Remote

    Axxum Technologies • United States
    Remote
    Full-time
    Resource Access Control Facility (RACF) is a security program that serves as a component of the Security Server for the z / OS operating system. It provides tools to help manage access to critical res...Show more
    Last updated: 30+ days ago • Promoted
    Associate or Mid-Level Software Security Engineer

    Associate or Mid-Level Software Security Engineer

    Boeing • US
    Permanent +1
    At Boeing, we innovate and collaborate to make the world a better place.We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportu...Show more
    Last updated: 19 hours ago • Promoted • New!
    Senior Manager Product Security

    Senior Manager Product Security

    Two95 International Inc. • US
    Remote
    Full-time
    Quick Apply
    Title : Senior Manager Product Security.Testing and reviewing web applications / services written in Java, C / C++, and mobile languages. Securing AWS and GCP environments using IaC.Engage in and improve...Show more
    Last updated: 30+ days ago
    Mid-Level Product Security Analyst

    Mid-Level Product Security Analyst

    Boeing • US
    Permanent
    At Boeing, we innovate and collaborate to make the world a better place.We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportu...Show more
    Last updated: 19 hours ago • Promoted • New!
    Remote Cloud Security Engineer

    Remote Cloud Security Engineer

    Insight Global • United States
    Remote
    Full-time
    We’re looking for a seasoned Cloud Security Engineer with deep expertise in digital forensics, cloud infrastructure, and automation. This role blends investigative rigor with modern cloud security p...Show more
    Last updated: 19 hours ago • Promoted • New!
    SOC Analyst - Associate Level

    SOC Analyst - Associate Level

    Northwest Partners • United States
    Part-time
    Quick Apply
    Northwest Partners is engaged in a strategic initiative with a well-established healthcare organization and seeks an experienced Security Operations Center (SOC) Analyst to support weekend monitori...Show more
    Last updated: 20 hours ago • New!
    Database Administrators

    Database Administrators

    Prometheus • NULL, NULL, US
    Remote
    Temporary
    Role Overview • • Mercor is collaborating with a leading AI organization to identify experienced Database Administrators for a high-priority training and evaluation project.Freelancers will be tasked...Show more
    Last updated: 13 days ago • Promoted
    Sr. Network Security Engineer | Remote, USA

    Sr. Network Security Engineer | Remote, USA

    Optiv • United States
    Remote
    Full-time
    This position will be fully remote and can be hired anywhere in the continental U.Additionally this position requires a CJIS Background Check and Fingerprinting as part of the onboarding process.Ne...Show more
    Last updated: 3 days ago • Promoted
    Network Security Engineer - Hybrid

    Network Security Engineer - Hybrid

    Charles Schwab • US
    Full-time
    At Schwab, you are empowered to make an impact on your career.Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry toget...Show more
    Last updated: 3 hours ago • Promoted • New!
    Database Architects (Professional, Scientific, and Technical Services)

    Database Architects (Professional, Scientific, and Technical Services)

    Obsidian • NULL, NULL, US
    Remote
    Full-time
    Mercor is recruiting • •Database Architects who work in the Professional, Scientific, and Technical Services • • as independent contractors working on a research project • •for one of the world’s top A...Show more
    Last updated: 1 day ago • Promoted
    Sales Engineer – Security Integration

    Sales Engineer – Security Integration

    Jobot • US
    Full-time
    Build the machines that build the future — hands-on electrical work, global travel, and innovation await!.This Jobot Job is hosted by : Jamie Beene. Are you a fit? Easy Apply now by clicking the "App...Show more
    Last updated: 23 hours ago • Promoted
    Security Project Manager

    Security Project Manager

    Cloud Security Services • US
    Full-time
    Quick Apply
    Cloud Security Services is seeking a Security Project Manager Consultant to support their Threat Management team and objectives by leading, coordinating, and delivering security project milestones ...Show more
    Last updated: 30+ days ago
    SOC Analyst – Intermediate – remote

    SOC Analyst – Intermediate – remote

    Revel IT • Remote, USA
    Remote
    Full-time
    Treat our consultants and clients the way we would like others to treat us!Interested in joining our team? Check out the opportunity below and apply today!. Client is seeking a SOC Analyst – Interme...Show more
    Last updated: 14 hours ago • Promoted • New!