Senior Forescout Engineer

New Today

: GDIT is currently seeking a Cybersecurity Engineer (Senior) with a focus area of Forescout Counteract, network access control (NAC) enforcement, and device compliance supporting the Department of Education's (DoED) Office of the Chief Information Officer (OCIO). The role will involve support of ForeScout CounterAct implementation as part of the DHS Continuous Diagnostics and Mitigation (CDM) program and OCIO security operations. The team member in this position should also have an understanding of networking and firewall. Normal tasks will include (but not limited to); maintaining and upgrading Forescout appliances, troubleshooting quarantined VLANs, expanding Forescout capabilities, and security stack integration. Serves as lead and subject matter expert in Forescout and network access control services and enforcement.
Responsiblities include: Maintain and support Forescout appliances on-prem and virtual machines in Azure cloud for an enterprise federal department. Support continuous diagnostics and mitigation (DHS CDM) integration and compliance for HWAM, SWAM, and CMS requirements utilizing Forescout. Troubleshoot various types of issues with the Forescout platforms (authentication, 802.1x, quarantine VLANs, network reachability, logging, etc.). Develop and maintain enforcement policies to comply with the Department's Vulnerability Management Remediation guidelines and CISA Known Exploitable Vulnerability (KEV) mandates (BOD 22-01). Develop and maintain enforcement and compliance dashboards. Prepare and maintain appropriate standard operational procedures (SOPs) and supporting documentation. Submit and respond to tickets using a central ticketing system such as ServiceNow. Submit, present, and implement change requests for regular maintenance and out-of-band emergency tasks. Understanding of router and switch configurations using CLI commands to verify communication with Forescout (i.e., 802.1x). Coordinate third-party maintenance for Foresout equipment and services. Other duties may include, packet capture and analysis support. Maintain and update diagrams for Forescout architecture using Microsoft Visio. Provide reports as needed using the Microsoft Office Suite. Provide outage notifications and update outage reports. Review IP addresses and subnets to identify networks that need to be monitored by Forescout. Perform network traces to analyze traffic issues. Provide specific detailed information for hardware and software selection, implementation techniques, and tools for the most efficient solution to meet business needs, including present and future capacity requirements. Propose solutions to management to ensure all communications requirements based on future needs and current usage, configuring such solutions to optimize cost savings. Provide regular monitoring and network analysis regarding short- and long-range planning.
EDUCATION AND EXPERIENCE: BA/BS or equivalent, 5+ years of experience
The likely salary range for this position is $119,000 - $161,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours: 40
Travel Required: Less than 10%
T elecommuting Options: Hybrid
Work Location: USA DC Home Office (DCHOME)
Location:
Washington