Job Id: SC-13902
Onsite/Local Security Analyst (weekend shifts/GSEC/Security+/Network+IH) with Server/Network Admin, SIEM/Defender for Endpoint, Threat Hunting/Detection/Intelligence Research, OSINT tools, Log Analysis, Incident Response, NIST/MITRE ATT&CK, Vulnerability Management, SCCM/GPO/PowerShell, Network/Cloud Security, Digital Forensics experience
Location: Blythewood, SC (SCDMV)
Duration: 12 Months
Work Location: Fully Onsite NO flexibility for hybrid or remote work Candidate location: Candidate must be a CURRENT SC resident. No relocation allowed.
Skills:
Required Skills (rank in order of Importance):
Understanding of security concepts and processes
Understanding of basic computer and network concepts
Preferred Skills (rank in order of Importance):
1+ Years of Experience in Server or Network Administration
1+ Year of Experience in an IT Security Focused Role
Experience with SIEM and Endpoint Security Tools
Experience with PowerShell, Group Policy, and Endpoint Management
Knowledge of Vulnerability Management and Cloud Security
Bachelors Degree in Information Technology, Computer Science, Cybersecurity, or a related field
Additional Skills
Problem-Solving: Analyze data, identify anomalies, and recommend solutions.
Attention to Detail: Ensure accurate analysis and configuration for effective security measures.
Ability to communicate and work effectively with a mid-size team
Required Education and experience: A High School Diploma is required at minimum Certifications: Not required, however we prioritize applicants who have:
GIAC Security Essentials (GSEC)
Security+ (CompTIA)
Network+ (CompTIA)
GIAC Incident Handler (GCIH)
Job Decsription:
The DMV Security Team is looking for candidates to fill an entry level security
position. The DMV will train the selected candidate to perform the tasks listed below. At a minimum We are looking for basic server or network administration skills that we can build upon.
- Threat Intelligence Research
o Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
o Document findings, such as new attack methods or vulnerabilities, and share with the team.
o Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.
- Threat Hunting and Detection Rule Creation
o Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
o Utilize threat feeds, investigate suspicious activity, and stay current on cyber threats.
o Collaborate with senior analysts to refine and test detection rules (e.g.,
SIEM queries or Defender for Endpoint rules).
o Document hunting methodologies and findings to support continuous improvement.
- Log Analysis
o Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
o Escalate findings, such as anomalous IP addresses or unauthorized
access attempts, to senior analysts.
o Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.
- Incident Response
o Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
o Identify and escalate potential security threats.
o Gather and analyze relevant evidence, such as logs or alert data, to determine the scope and severity of incidents.
o Document findings during incidents and contribute to containment and remediation efforts.
- Documentation, Reporting, and Communication
o Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
o Deliver reports on the security posture and propose mitigation
- o Draft training materials or guides to help improve organizational awareness and readiness.
o Regularly update and organize documentation to ensure accuracy and
accessibility for team use.
- Vulnerability Management
o Analyze reports, prioritize patching, and understand NIST best practices. - Security Awareness Training
o Develop and deliver training and assess employee awareness through
simulations.
- Security Automation and Scripting
o Leverage SCCM, GPO, and PowerShell for patch deployment.
o Automate tasks beyond SCCM, GPO, and PowerShell to increase efficiency.
- Endpoint and Network Security
o Configure policies, analyze alerts, and manage endpoint protection.
o Understand network protocols and firewalls to strengthen the overall security posture.
- Digital Forensics and Cloud Security
o Investigate security incidents and collect evidence for deeper analysis.
o Develop knowledge of cloud-specific security solutions as cloud adoption grows.