JOB TITLE: SR SOC ANALYST
JOB LOCATION: WASHINGTON, DC (HYBRID 1 DAY IN OFFICE)
WAGE RANGE*: 80.00-85.00 PER HOUR
JOB NUMBER: SAIJP00038690
REQUIRED EXPERIENCE:
Ability to obtain a Public Trust clearance.
A minimum of seven (7) years of professional experience with a solid understanding of incident response, insider threat investigations, forensics, cyber threats and information security.
A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host-based and network-based security monitoring, identifying and analyzing anomalous activities with familiarity in host-based tools, intrusion detection systems, intrusion analysis functions, security information event management (SIEM) platforms, endpoint threat detection tools, and ticket management in a SOC Operations environment.
One or more of the following certifications: GCIA, GCIH, GCFA, GCED, or other Information Assurance Technician (IAT) Level III certification (CASP+ CE, CCNP Security, CISA, CCSP), as well as an active CISSP, or the ability to obtain one within six (6 months) of hire.
JOB DESCRIPTION
The Senior Analyst will provide expert technical support in the areas of Incident Response (IR), Network Defense, and SIEM content creation. Additionally, the ideal candidate will be an expert in cyber threats and information security in the domains of TTP's, Threat Actors, Campaigns, and Observables.
Demonstrated understanding of incident response, insider threats, forensics, cyber threats and information security.
Prior experience with a Splunk as Security Information and Event monitoring (SIEM) platform and log management system.
Experience creating custom content such as rules, filters, signatures, countermeasures and operationally relevant scripts to support analysis and detection efforts. Strong SPL knowledge is preferred.
Experience collecting data and reporting results; handling and escalating security issues or emergency situations appropriately; providing incident response capabilities to contain and mitigate threats to maintain the confidentiality, integrity, and availability of protected data.
Ability and experience extracting and managing complex large data sets.
Strong documentation and written communication skills with technical report writing experience.
Experience with ad-hoc training to junior, mid, or senior members of a cyber work force.
Existing Subject Matter Expertise (SME) of Advanced Persistent Threat (APT) or emerging threats.
Proficiency in utilizing various packet capture (PCAP) applications/engines and in analysis of PCAP and NetFlow data.
Experience with static and dynamic malware analysis, including reverse engineering of binaries.
Familiarity with coding, scripting languages (BASH, PowerShell, Python, etc.), or with software development frameworks such as .NET.
Desired Qualifications:
Experience mentoring and/or leading a technical team.
Experience in Cyber Hunt activities.
Advanced troubleshooting skills.
Metadata extraction and analysis.
Malware Reverse Engineering (MA/RE).
Equal opportunity employer as to all protected groups, including protected veterans and individuals with disabilities
* While an hourly range is posted for this position, an eventual hourly rate is determined by a comprehensive salary analysis which considers multiple factors including but not limited to: job-related knowledge, skills and qualifications, education and experience as compared to others in the organization doing substantially similar work, if applicable, and market and business considerations. Benefits offered include medical, dental and vision benefits; dependent care flexible spending account; 401(k) plan; voluntary life/short term disability/whole life/term life/accident and critical illness coverage; employee assistance program; sick leave in accordance with regulation. Benefits may be subject to generally applicable eligibility, waiting period, contribution, and other requirements and conditions. Benefits offered are in accordance with applicable federal, state, and local laws and subject to change at TCM's discretion.
#Dice
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: cxtcml
- Position Id: 26-00571
- Posted 3 hours ago