Associate Cybersecurity Specialist
Job description
About the role
Vulcan Elements is at the forefront of producing rare-earth permanent magnets in the United States, playing a crucial role in fostering a secure and resilient future. Our mission is to bolster national security and promote economic stability by serving essential sectors such as defense, aerospace, and automotive industries. As an Associate Cybersecurity Specialist, you will be instrumental in strengthening the security posture and compliance of our integrated operational technology (OT) and information technology (IT) systems.
Key facts
What you'll do
- Collaborate with our external CMMC compliance partner to support the implementation and enhancement of NIST 800-171 controls within both IT and OT environments. You will assist in managing the Plan of Action and Milestones (POA&M) and help resolve any outstanding compliance issues.
- Contribute to maintaining the System Security Plan (SSP) by ensuring its accuracy and relevance. You will gain hands-on experience in mapping security controls to actual systems, configurations, and personnel while becoming acquainted with the operational environment.
- Identify and document security vulnerabilities present in both IT and OT systems. You will learn to prioritize these risks based on their potential impact on operational safety and production efficiency.
- Assist in the implementation and continuous monitoring of security measures across IT infrastructure and OT systems, which include Manufacturing Execution Systems (MES), historians, and network boundary devices.
- Monitor security incidents across both IT and OT environments. Under supervision, you will investigate alerts, assist in incident response activities, and document your findings for future reference.
- Participate in vulnerability assessments for IT systems and help coordinate safe evaluation methods for OT assets. You will track remediation efforts in collaboration with system owners.
- Aid in delivering security awareness training to ensure that personnel with access to Controlled Unclassified Information (CUI) are well-informed of their responsibilities under CMMC policies.
- Support third-party CMMC assessments and internal audits by gathering and organizing evidence related to control implementations.
Please note that the responsibilities and tasks listed are not exhaustive and may evolve based on the organization's needs.
Requirements
- A minimum of 2 years of experience in an IT, cybersecurity, or related technical role is essential. Relevant internships or lab experience will also be considered. Familiarity with manufacturing or industrial environments is advantageous but not required.
- A foundational understanding of cybersecurity principles, including access control, network security, logging, and incident response, is necessary. This knowledge can come from formal education, self-study, or hands-on lab experience.
- Familiarity with the NIST 800-171 framework or the CMMC is preferred. While direct experience in implementation is not mandatory, a solid understanding of their importance is crucial.
- A keen interest in the integration of OT and IT systems is important. A willingness to learn about Industrial Control Systems (ICS), SCADA concepts, and safety considerations in manufacturing is essential.
- Comfort with Windows environments is required. Knowledge of Active Directory, networking fundamentals, and security tools such as SIEM, endpoint protection, and vulnerability scanners will be beneficial.
- Strong attention to detail is necessary, as maintaining accurate documentation is vital for security compliance.
- Previous experience with the Department of Defense (DoD), federal contracting, or environments that involve CUI is a plus.
- Ability to work in a manufacturing environment, which may include occasional physical tasks in production or server areas.
- CompTIA Security+ certification is required within six months of hire if not already obtained. Support for obtaining the Certified CMMC Professional (CCP) certification is expected within 12-18 months.
Candidates must be U.S. Persons due to the necessity of accessing U.S. export-controlled information or facilities.
Nice to have
- Experience with risk management frameworks or compliance standards beyond NIST and CMMC.
- Familiarity with cloud security principles and practices.
- Knowledge of programming or scripting languages to automate security tasks.
Skills & tools
- Proficiency in cybersecurity tools and technologies, including firewalls, intrusion detection systems, and antivirus solutions.
- Experience with security information and event management (SIEM) systems.
- Familiarity with vulnerability assessment tools and methodologies.
Practical notes
- This position is based in Research Triangle Park, NC, and requires full-time engagement.
- The salary for this role will be competitive and commensurate with experience.
- Candidates should be prepared to undergo background checks and security clearances as necessary.
- Opportunities for professional development and continued education will be provided to support your growth in the cybersecurity field.