|Job Title: Cybersecurity SOC Analyst|
Job ID: 1705
Location: Washington, DC
Job Type: Full Time
Date Posted: 01/09/2018
The SOC Analyst is a tier 2 tech resource responsible for monitoring, detecting, analyzing, remediating, and reporting on cyber events and incidents impacting the tech infrastructure of the District of Columbia. Serves as advanced escalation point.
- Provide in-depth cybersecurity analysis, and trending of log, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cybersecurity incidents and make sound recommendations that enable expeditious remediation.
- Conduct security tool/application (for example, mcafee siem) tuning engagements with analysts and engineers to develop/adjust rules and analyst response procedures and reduce false-positives from alerting.
- Utilize advanced background and experience in information technology and incident response handling to scrutinize escalated cybersecurity events from tier 1 analysts—distinguishing these events from benign activities, and escalating confirmed incidents to the incident response lead.
- Recognize, create and ingest indicators of compromise (ioc’s) for attacker tools, tactics, and procedures into network security tools/applications (for example, mcafee siem, palo alto content filter, anomali threatstream) to protect the government of the district of columbia network.
- Provide technical analytical guidance to, and quality-proofing of tier 1 analysts analytical advisories and assessments prior to release from soc.
- Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
- Report common and repeat problems (trend analysis) to soc management and propose process and technical improvements to improve the effectiveness and efficiency of the incident handling process.
- Respond to inbound requests via phone and other electronic means for technical assistance, and resolve problems independently. Coordinate escalations and collaborate with internal technology teams to ensure timely resolution of issues.
- Five years of hands-on operational experience as a cybersecurity analyst/engineer in a security operations center, or equivalent knowledge in areas such as; cybersecurity operations, incident analysis and handling, vulnerability management, log analysis, and intrusion detection.
- In-depth understanding of cybersecurity attack countermeasures for adversarial activities such as network probing and scanning, distributed denial of service (ddos), phishing, malicious code activity such as worms, trojans, viruses, etc.
- In-depth hands-on experience analyzing and responding to security events and incidents with a majority of the following technologies and/or techniques; leading security information and event management (siem) technologies, intrusion detection/prevention systems (ids/ips), network- and host- based firewalls, data leak protection (dlp), database activity monitoring (dam), web content filtering, vulnerability scanning tools, endpoint protection, secure coding, etc.
- Excellent interpersonal, organizational, oral, communication and customer service skills.