Summary
This job involves managing and fixing security weaknesses in computer networks for South Carolina state government, including scheduling updates, testing them safely, and working with teams to keep everything running smoothly.
It's a hands-on role focused on using specific tools to monitor and protect networks from threats.
A good fit would be someone with experience in network security who enjoys coordinating with others and solving technical problems in a team setting.
Full Job Description
Network Services Vulnerability Engineer
The Department of Administration's (Admin) Office of Technology and Information Services (OTIS) is the state’s central provider of IT services to state government agencies. Our Network Services team is maturing and growing. If you are customer service oriented, and thrive in leading IT Professionals focused on the efficiency technology brings to an organization, this position is for you! In this role you will assist the Department of Technology Operations (DTO) Network Services team in implementing industry security best practices and statewide security programs established by Division of Information Security (DIS) including vulnerability management and configuration management.
This position is onsite in beautiful Columbia, South Carolina.
Responsibilities of the Network Services Vulnerability Engineer:- Manage vulnerability remediation and patch windows schedule. Schedule patches within Catalyst Center & Meraki Dashboard.
Submit all change requests relating to patching of devices and work with customers to coordinate patching. Work with the DTO Vulnerability Manager and DIS for Vulnerability Remediation.
Develop documentation to demonstrate remediation of findings and compliance with state and regulatory requirements.
- Audit and drive remediation of Network Services routers and switches using the statewide vulnerability management platform and other tools as needed for IT Security and of supported agencies.
- Work with DIS staff and agencies to develop Plan of Action & Milestones (POA&M) concerning Shared Services for defining, tracking, and reporting on the progress of remediation actions.
- Monitor network performance and utilization with available tools to ensure that the network remains healthy and fully functional. Utilize test environments, when possible, to evaluate and test new firmware so that firmware patches can be applied with no adverse impact to devices and customers.
- Utilize available network services tools like, Solarwinds Orion (or similar network monitoring tool), ISE and Catalyst center to support network activities.
- Other duties as assigned such as helping Network Integration and Design Engineers when needed.
Requirements
- A bachelor's degree in an information technology or information security related field. Relevant experience may be substituted for the bachelor's degree on a year-for-year basis.
Additional Requirements:- Hands on operational experience with Cisco management tools (e.g. Cisco Catalyst Center, Meraki Dashboard, Cisco Nexus Dashboard) including the ability to deploy, configure, and operate.
- Understanding of various Cisco operating systems including Cisco IOS-XE, Cisco IOS-XR and Cisco Nexus OS.
- Ability to report issues clearly and efficiently communicate vulnerability severity to various stakeholders.
- Strong written and verbal communication skills.
- Ability to examine issues both strategically and analytically.
- Strong understanding of vulnerability management lifecycle and governance.
- Position may require employee to work evenings and weekends.
- Position requires routine driver duties.
- Position may be required to report to work during emergency situations.
Applicants indicating college credit or degree(s) on the application may bring a copy of college transcript to the interview. A copy of the transcript may also be uploaded as an attachment to the application, if required by the hiring department or if desired by the applicant. Please note that some areas of the Department may require an official, certified copy of the transcript prior to hiring or within a specific timeframe required by that area, after hiring. Failure to produce an official, certified transcript may result in not being hired or termination.
Qualifications
- Two (2) years of experience in supporting vulnerability management for large IT environments is preferred.
- Networking certifications such as CompTIA N+ or CCNA is desired.
- Automation/scripting experience using Python or any other scripting languages is desired.
Additional Information
The Department of Administration is committed to providing equal employment opportunities to all applicants and does not discriminate on the basis of race, color, religion, sex (including pregnancy, childbirth, or related medical conditions including, but not limited, to lactation), national origin, age (40 or older), disability or genetic information.
Supplemental questions are considered part of your official application. Any misrepresentation will result in your disqualification from employment.
Please complete the state application to include all current and previous work history and education.
A resume will not be accepted nor reviewed to determine if an applicant has met the qualifications for the position.
The South Carolina Department of Administration offers an exceptional benefits package for full time (FTE) employees:
- Health, dental, vision, long-term disability, and life insurance for employees, spouse, and children. Click here
for additional information.
- 15 days annual (vacation) leave per year
- 15 days sick leave per year
- 13 paid holidays
- Paid Parental Leave
- S.C. Deferred Compensation Program available (S.C. Deferred Compensation)
- Retirement benefit choices *
*Enrollment in one of the listed plans is required for all FTE employees; please refer to the contribution section of hyperlinked retirement sites for the current contribution rate of gross pay.