Cybersecurity Research Assistant
Early-career cybersecurity professional implementing and monitoring security controls across Linux, Kubernetes, database, and AI infrastructure. Requires 1–3 years of hands-on technical experience, Linux and scripting skills, and interest in federal authorization and security engineering.
About the job
Responsibilities
- Implement security controls across Kubernetes, Linux, database, and model-serving environments.
- Build and operate monitoring and detection coverage, including metrics, dashboards, log aggregation, and alert routing.
- Run vulnerability scans across container images, hosts, and application dependencies; track findings to closure and maintain plans of action and milestones.
- Write and maintain Ansible and Python automation for hardening baselines and drift detection.
- Contribute to secrets management, network policy, and role-based access control.
- Build deterministic collectors for security-control evidence and normalize timestamped outputs.
- Help develop internal AI tooling for control-catalog retrieval, evidence drafting, and scanner-output triage.
- Keep security documentation aligned with deployed configurations and prepare materials for security reviews and continuous-monitoring reports.
- Test controls, policies, alerts, backups, and implemented changes.
Requirements
- 1–3 years of professional experience in IT, systems administration, help desk, network operations, or a comparable hands-on technical role.
- Associate’s or bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field; equivalent experience or technical certification may substitute.
- Comfort with the Linux command line and working knowledge of Linux system administration, preferably RHEL-based systems and Ubuntu.
- Scripting ability in Bash and Python.
- Basic understanding of TCP/IP, DNS, TLS, firewalls, and request flows.
- Basic familiarity with containers and interest in learning Kubernetes.
- Familiarity with version control and shared Git repositories.
- Ability to obtain and maintain a Public Trust security clearance.
- Clear written communication, careful documentation, independent task execution, and willingness to ask questions.
- Interest in NIST security controls, continuous monitoring, and federal security authorization.
Nice-to-haves
- CompTIA Security+, Network+, Linux+, Kubernetes, or cloud certification.
- Cybersecurity or information-assurance coursework or concentration.
- Exposure to NIST standards, security frameworks, or compliance work.
- Home lab, capture-the-flag participation, open-source contributions, or a personal security project.
- Experience with Ansible, Terraform, Prometheus, Grafana, Elastic, or similar monitoring and configuration-management tools.
- Curiosity about large language models and AI tooling.
- Experience with NIH, federal agencies, or federal IT environments.
Compensation and Benefits
- Annual salary: $85,000–$110,000 USD.
- 100% employee medical, dental, and vision coverage.
- Paid time off and holidays.
- 401(k) match up to 5%.
- Educational benefits, flexible spending accounts, and certification exam and study-material sponsorship.
Skills
Linux, Bash, Python, Kubernetes, Ansible, Terraform, Git, TCP/IP, DNS, Tls, Firewalls, Prometheus, Grafana, Elastic, Nist
Similar jobs
Security Engineering jobsBuild security into embedded vehicle platforms through security assessments, secure boot implementation, and HSM integration. This new-grad role requires a relevant computer or electrical engineering degree, foundational cryptography knowledge, and proficiency in C, C++, or Python.
Corporate Security Engineer responsible for identity, endpoint, SaaS, and security automation controls across the company. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.
Own and operate Vertex Synapse, integrating and modeling threat intelligence while delivering it to detections, blocklists, data pipelines, and security workflows. Requires at least two years of production threat-intelligence platform or security data-pipeline experience and software development skills in Python, Go, or Storm.
Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.
Build and operate foundational security services spanning identity, access, secrets, privileged access, and secure AI-agent infrastructure. The role requires at least two years of production software engineering experience, cloud expertise, and experience translating security requirements into reliable automated systems.