Position is 100% Onsite in Blythewood, SC.Candidate location: Candidate must be a CURRENT SC resident. No relocation allowed.
Availability for Saturday and Sunday Evening shifts are required as they will be part of the selected resource’s schedule after training. This is mandatory. Candidate must be willing to sign an NDA if they are selected to interview.
Interview Process: 1-2 Rounds of Virtual or Onsite Interviews. Candidates are expected to be available for onsite interviews.
Working Schedule: Saturday and Sunday evening coverage likely to be 8:00PM-8:00AM (2 12-Hour Shifts) with dayshifts Wednesday and Thursday (8:30 AM - 2:45 PM)
The selected resource will need to successfully complete the following screenings once in onboarding:
- 7 Year Standard Background Check & Credit History Check
- 7-Year Certified Driving Record (MVR)
- 5-Panel Drug Screening
- Fingerprinting - this MUST be done in South Carolina at least 5 business days before the resource starts
Scope of the project:
Enhance the security posture of the Agency to protect sensitive citizen data and ensure the integrity of motor vehicle licensing and titling systems.
Availability for Saturday and Sunday Evening shifts are required as they will be part of the selected resource’s schedule after training. This is mandatory.
Daily Duties / Responsibilities:
The Agency Security Team is looking for candidates to fill an entry level security position. The Agency will train the selected candidate to perform the tasks listed below. At a minimum We are looking for basic server or network administration skills that we can build upon.
1. Threat Intelligence Research
- Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
- Document findings, such as new attack methods or vulnerabilities, and share with the team.
- Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.
2. Threat Hunting and Detection Rule Creation
- Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
- Utilize threat feeds, investigate suspicious activity, and stay current on cyber threats.
- Collaborate with senior analysts to refine and test detection rules (e.g., SIEM queries or Defender for Endpoint rules).
- Document hunting methodologies and findings to support continuous improvement.
3. Log Analysis
- Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
- Escalate findings, such as anomalous IP addresses or unauthorized access attempts, to senior analysts.
- Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.
4. Incident Response
- Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
- Identify and escalate potential security threats.
- Gather and analyze relevant evidence, such as logs or alert data, to determine the scope and severity of incidents.
- Document findings during incidents and contribute to containment and remediation efforts.
5. Documentation, Reporting, and Communication
- Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
- Deliver reports on the security posture and propose mitigation strategies.
- Draft training materials or guides to help improve organizational awareness and readiness.
- Regularly update and organize documentation to ensure accuracy and accessibility for team use.
6. Vulnerability Management
- Analyze reports, prioritize patching, and understand NIST best practices.
7. Security Awareness Training
- Develop and deliver training and assess employee awareness through simulations.
8. Security Automation and Scripting
- Leverage SCCM, GPO, and PowerShell for patch deployment.
- Automate tasks beyond SCCM, GPO, and PowerShell to increase efficiency.
9. Endpoint and Network Security
- Configure policies, analyze alerts, and manage endpoint protection.
- Understand network protocols and firewalls to strengthen the overall security posture.
10. Digital Forensics and Cloud Security
- Investigate security incidents and collect evidence for deeper analysis.
- Develop knowledge of cloud-specific security solutions as cloud adoption grows.
Required Skills (rank in order of Importance):
- Understanding of security concepts and processes
- Understanding of basic computer and network concepts
Preferred Skills:
- 1+ Year of Experience in an IT Security Focused Role
- Experience with SIEM and Endpoint Security Tools
- Experience with PowerShell, Group Policy, and Endpoint Management
- Knowledge of Vulnerability Management and Cloud Security
- Bachelor’s Degree in Information Technology, Computer Science, Cybersecurity, or a related field
- 1+ Years of Experience in Server or Network Administration
Additional Skills
- Problem-Solving: Analyze data, identify anomalies, and recommend solutions.
- Attention to Detail: Ensure accurate analysis and configuration for effective security measures.
- Ability to communicate and work effectively with a mid-size team
Required Education and Experience:
- A High School Diploma is required at minimum.
Certifications:
Not required, however we prioritize applicants who have:
- GIAC Security Essentials (GSEC)
- Security+ (CompTIA)
- Network+ (CompTIA)
- GIAC Incident Handler (GCIH)