• Crownsville, MD
    1 day ago

    Job Description

    Job Title: SOC Analyst
    Location: US-MD-Crownsville (100% Onsite)

    There are 3 openings currently- , 2nd shift (1 opening)  and night shift (2 openings) Please  clearly specify which shift works when submitting resume

    -2nd Shift:   3pm to 11:30pm
    -Night Shift:  11:00pm to 7:30am

    Required certification:  CompTIA CySA+ certification / or a CompTIA Security+ (or other relevant IAT Level II/III Certification) plus one other certification as stated below

    Must Be a US Citizen

    Successful completion of a Fingerprint background investigation required.


    Client is seeking a Security Operations Center (SOC) Analyst with hands-on experience monitoring, detecting, and analyzing threats and cybersecurity events to identify and defend against validated intrusion events. Daily work includes monitoring network and system security events, conducting threat hunting through event data and activity logs, developing alarms for suspicious or malicious activity, escalating alerts to clients, and preparing reports to summarize detected activities.
     
    The SOC Analyst executes and helps to create operational processes for consistent monitoring of client environments and should be familiar with a variety of security tools and technologies. The SOC Analyst additionally works to support the Incident Response Team by conducting monitoring and analysis during incident management engagements.
     
    Duties and Responsibilities:
    • The shift requirements are 2nd shift and night shift.
    • Monitor, protect, and defend the enterprise perimeter against malicious network traffic.
    • Monitor, protect, and defend internal networks and hosts against ongoing and emerging threats.
    • Enrich monitoring logs with contextual operation data from functional areas correlate events and identify security issues, threats, and vulnerabilities
    • Conduct security event analysis and validation, triage validated incidents, perform initial containment where feasible, research incident and enrich incident case documentation, and escalate the incident for further analysis, containment, and eradication.
    • Review and analyze threat intelligence information and proactively search application, system, network logs to hunt for and thwart relevant threats identified threats.
    • Prepare and perform shift handover briefing to communicate completed and pending activities, and relay situational awareness information.
    • Contribute to the development and maintenance of SOC Standard Operating Procedures (SOPs) and Concept of Operations (CONOPS) to establish and continuously improve organization's operating knowledge base.
    • Participate in post-incident activities and contribute to lessons learned to improve security operations.
    • Provide support in preparation of management threat reports and briefings, and recommendations.
    • Provide sound technical recommendations that enable remediation of security issues.
    • Partner with security engineering to develop and refine SIEM correlation rules.
    • Utilize advanced threat models, SIEM use cases, and incident response playbooks.
     
    Qualifications:
     
    Education and Years of Experience: 
    • Bachelor’s degree from an accredited college or university with a major in computer science, information systems, engineering, business, or a related scientific or technical disciplines. Master's Degree is preferred.
    • CompTIA CySA+ certification/ or a CompTIA Security+ (or other relevant IAT Level II/III Certification) along with one of the following:
    • o CEH
    • o CFR
    • o CCNA Cyber Ops
    • o CCNA-Security
    • o GCIA
    • o GCIH
    • o GICSP
    • o Cloud+
    • o SCYBER
    • o PenTest+
    • Experience analyzing intrusion events such phishing emails, malware, privileges misuse, traffic indicating potential malicious activities such DoS/DDoS, brute force, data loss through exfiltration/ inadvertent disclosure.
    • Applied experience of threat analysis model/frameworks such Cyber Kill Chain, MITRE ATT&CK, Diamond Model, Pyramid of Pain etc.
    • Working knowledge of advanced threat Tactics, Techniques and Procedures (TTPs).
    • Applied experience with network traffic analysis with tools like Wireshark
    • Applied experience with a variety of Opensource threat research tools/platforms such as Virus Total
    • Working knowledge of network and security architecture principles such as defense-in-depth
    • Experience with proprietary security protection/detections tools such as Firewall, Host and Network IDS/IPS, Anti-Virus, EDR, URL Filtering Gateways, Email Filtering Gateways, DLP tools, and SIEM tools such as Splunk etc.
    • Capable of working independently, establishing priorities and managing task completion within set SLAs
    • Able to communicate effectively through writing, speaking, and presenting to client technical representatives.
    • Team player capable of productively contributing to the client mission by supporting fellow teammates in a dynamic growing and changing environment.

    Desired Skills and Qualifications:
    • Experience with mid-to-advance level malware analysis
    • Experience creating detailed queries and scripts, such as regular expressions, for log, event and correlation analysis.
    • Experience scripting in Python, PowerShell, VBScript

    Numbers & Facts

    LocationCrownsville, MD

    Skills

    • Analysis Skillsunmatched
    • Antivirusunmatched
    • Background Investigationunmatched
    • CCNA - Cisco Certified Network Associateunmatched
    • Cloud Computingunmatched
    • Code of Federal Regulationsunmatched
    • Communication Skillsunmatched
    • CompTIA - Computing Technology Industry Associationunmatched
    • CompTIA Security+unmatched
    • Computer Hackingunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Concept of Operations (CONOPS)unmatched
    • Continuous Improvementunmatched
    • Customer Escalationsunmatched
    • Defense in Depthunmatched
    • Denial of Service (DoS)unmatched
    • Documentationunmatched
    • Environmental Monitoringunmatched
    • Establish Prioritiesunmatched
    • Event Correlationunmatched
    • Firewallsunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • Huntingunmatched
    • Identify Issuesunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Intelligence Analysisunmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Knowledge Baseunmatched
    • Malwareunmatched
    • Malware Analysisunmatched
    • Microsoft VBScript (Visual Basic Script) Scripting Languageunmatched
    • Network Architecture/Engineeringunmatched
    • Network Monitoringunmatched
    • Network Securityunmatched
    • Network Traffic Analysisunmatched
    • Open Sourceunmatched
    • Operational Improvementunmatched
    • Operations Processesunmatched
    • Organizational Development/Managementunmatched
    • Phishingunmatched
    • Presentation/Verbal Skillsunmatched
    • Process Developmentunmatched
    • Python Programming/Scripting Languageunmatched
    • Regular Expressionsunmatched
    • Reporting Skillsunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Service Level Agreement (SLA)unmatched
    • Splunkunmatched
    • Standard Operating Procedures (SOP)unmatched
    • Systems Engineeringunmatched
    • Team Playerunmatched
    • Technical Presentationunmatched
    • Threat Modelingunmatched
    • United States Citizenunmatched
    • Use Casesunmatched
    • Virusesunmatched
    • Windows PowerShellunmatched
    • Wireshark (Ethereal)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder