SOC Analyst - Tier 3 with Min 11yrs exp (Webcam or in Person interview)(ONSITE_only local to DMV Area)

Advanced American Technologies, Inc
  • 200 I Street SE, DC
  • Instant Apply
3 days ago

Job Description

We are looking for a Tier 3 SOC Analyst (Min 11+ Yrs. Exp) ONSITE (Either Webcam or In Person Interview).
POSITION DESCRIPTION
DIRECT CLIENT Position
Number of positions:1
Length: 12 Months+
Work Address: Washington DC 20003
Immediate interviews Either Webcam or In Person Interview
Please Note this position is ONSITE
Monitoring, detecting, analyzing, remediating, and reporting on Cyber events and incidents impacting the tech infrastructure of the District of Columbia. Serves as advanced escalation point.

The SOC Analyst - Tier 3 is cybersecurity technical resource responsible for providing technical analytical oversight a team of SOC Analysts to monitor, detect, analyze, remediate, and report on cybersecurity events and incidents impacting the technology infrastructure of the Government of the District of Columbia. The ideal candidate will have an advanced technical background with significant experience in an enterprise successfully leading a SOC team or unit responsible for analysis and correlation of cybersecurity event, log, and alert data. The candidate will be skilled in understanding, recognition, and root-cause detection of cybersecurity exploits, vulnerabilities, and intrusions in host and network-based systems.

SPECIFIC TASKS
-Utilize advanced technical background and experience in information technology and incident response handling to scrutinize and provide corrective analysis to escalated cybersecurity events from Tier 2 analysts-distinguishing these events from benign activities, and escalating confirmed incidents to the Incident Response Lead.
-Provide in-depth cybersecurity analysis, and trending/correlation of large data-sets such as logs, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cybersecurity incidents, and make sound technical recommendations that enable expeditious remediation.
-Proactively search through log, network, and system data to find and identify undetected threats.
-Support security tool/application tuning engagements with analysts and engineers to develop/adjust rules and analyze/develop related response procedures, and reduce false-positives from alerting.
-Identify, verify, and ingest indicators of compromise and attack (IOC's, IOA's) (e.g., malicious IPs/URLs, etc.) into network security tools/applications to protect the Government of the District of Columbia network.
-Quality-proof technical advisories and assessments prior to release from SOC.
-Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
-Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements to improve the effectiveness and efficiency of alert notification and incident handling.
-Formulate and coordinate technical best-practice SOPs and Runbooks for SOC Analysts.
-Respond to inbound requests via phone and other electronic means for technical assistance, and resolve problems independently. Coordinate escalations with Incident Response Lead and collaborate with internal technology teams to ensure timely resolution of issues.

MINIMUM QUALIFICATIONS
- Bachelor's Degree in Cyber Security or related area with minimum Five years of demonstrated operational experience as a cybersecurity analyst/engineer handling and coordinating cybersecurity incidents and response in critical environments, and/or equivalent knowledge in areas such as; technical incident handling and analysis, intrusion detection, log analysis, penetration testing, and vulnerability management.
-In-depth understanding of current cybersecurity threats, attacks and countermeasures for adversarial activities such as network probing and scanning, distributed denial of service (DDoS), phishing, ransomware, botnets, command and control (C2) activity, etc.
-In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and/or techniques; leading security information and event management (SIEM) technologies, intrusion detection/prevention systems (IDS/IPS), network- and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, secure coding, etc.
-Strong communication, interpersonal, organizational, oral, and customer service skills.
-Strong knowledge of TCP/IP protocols, services, and networking.
-Knowledge of forensic analysis techniques for common operating systems.
-Adept at proactive search, solicitation, and detailed analysis of threat intelligence (e.g., exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) derived from open-source resources and external entities, to identify cybersecurity threats and derive countermeasures, not previously ingested into network security tools/applications, to apply to protect the Government of the District of Columbia network.
-Excellent ability to multi-task, prioritize, and manage time and tasks effectively.
-Ability to work effectively in stressful situations.
-Strong attention to detail.

PREFERRED EDUCATION/CERTIFICATION REQUIREMENTS
-Undergraduate degree in computer science, information technology, or related field.
-SANS GCIA, GCED, GPEN, GCIH or similar industry certification desired.
job description
Responsibilities:

1. Coordinates it project management, engineering, maintenance, qa, and risk management.
2. Plans, coordinates, and monitors project activities.
3. Develops technical applications to support users.
4. Develops, implements, maintains and enforces documented standards and procedures for the design, development, installation, modification, and documentation of assigned systems.
5. Provides training for system products and procedures.
6. Performs application upgrades.
7. Performs, monitoring, maintenance, or reporting on real- time databases, real-time network and serial data communications, and real-time graphics and logic applications.
8. Troubleshoots problems.
9. Ensures project life-cycle is in compliance with district standards and procedures.

Minimum education/certification requirements:
Bachelor's degree in information technology or related field or equivalent experience
Required/Desired Skills
Candidates must have ALL the "Required" skills in order to be considered for the position. "Desired" or "Highly Desired" skills are a PLUS but may NOT be required.
Skill Matrix
Experience with Business workflow processes
Required / Desired
Amount
of Experience
Years of Experience
Hands-on operational experience as a cybersecurity analyst/engineer in a security operations center, or equivalent knowledge.
Required
5
Years
In-depth understanding of cybersecurity attack countermeasures for adversarial activities such as malicious code, DDOS, and phishing.
Required
5
Years
In-Depth Hands-On Experience Analyzing And Responding To Security Events And Incidents With Security Information And Event Management System (SIEM)
Required
5
Years
Strong knowledge of cybersecurity attack methodology to include tactics and techniques, and associated countermeasures.
Required
5
Years
Strong Knowledge Of Tcp/Ip Protocols, Services, Networking, And Experience Identifying, Analyzing, Containing, And Eradicating Cybersecurity Threat
Required
5
Years
11-15 yrs implementing, administering, and operating IS tech such as firewalls, IDS/IPS, SIEM, Antivirus, net traffic analyzers, and malware analysis
Required
11
Years
11-15 yrs yrs utilizing advanced experience with scripting and tool automation such as Perl, PowerShell, Regex
Required
11
Years
11-15 yrs developing, leading and executing information security incident response plans
Required
11
Years
11-15 yrs yrs developing standard and complex IT solutions & services, driven by business requirements and industry standards
Required
11
Years
BS Degree in IT, Cybersecurity, Engineering or equivalent experience
Highly desired
0

Numbers & Facts

Location200 I Street SE, DC

Skills

  • Analysis Skillsunmatched
  • Antivirusunmatched
  • Applications Securityunmatched
  • Best Practicesunmatched
  • Communication Skillsunmatched
  • Computer Hackingunmatched
  • Computer Networksunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Content Filtering Softwareunmatched
  • Customer Support/Serviceunmatched
  • Data Setsunmatched
  • Denial of Service (DoS)unmatched
  • Detail Orientedunmatched
  • Digital Asset Management Software (DAM)unmatched
  • Documentationunmatched
  • Endpoint Securityunmatched
  • Establish Prioritiesunmatched
  • Event Correlationunmatched
  • Firewallsunmatched
  • Forensic Scienceunmatched
  • GCIA - GIAC Certified Intrusion Analystunmatched
  • GCIH - GIAC Certified Incident Handlerunmatched
  • GPEN - GIAC Penetration Testerunmatched
  • Governmentunmatched
  • Graphics Softwareunmatched
  • Identify Issuesunmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Information Systems/Technology IS/IT Administrationunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Intelligence Analysisunmatched
  • Internet Securityunmatched
  • Internet/Online Serviceunmatched
  • Interpersonal Skillsunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Detection and Prevention (IDP)unmatched
  • Intrusion Prevention Systemsunmatched
  • Inversion of Control (IoC)unmatched
  • Malwareunmatched
  • Malware Analysisunmatched
  • Multitaskingunmatched
  • Network Access Control (NAC)unmatched
  • Network Protocolsunmatched
  • Network Securityunmatched
  • Network Systemsunmatched
  • Open Sourceunmatched
  • Operating Systemsunmatched
  • Penetration Testingunmatched
  • Perl Programming Languageunmatched
  • Phishingunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Procedure Developmentunmatched
  • Process Improvementunmatched
  • Project Engineeringunmatched
  • Project Lifecycleunmatched
  • Project Trackingunmatched
  • Project/Program Managementunmatched
  • Quality Assuranceunmatched
  • Ransomwareunmatched
  • Realtime Communicationsunmatched
  • Regular Expressionsunmatched
  • Regulatory Complianceunmatched
  • Risk Managementunmatched
  • Scripting (Scripting Languages)unmatched
  • Secure Codingunmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Software Developmentunmatched
  • Standard Operating Procedures (SOP)unmatched
  • Standards Developmentunmatched
  • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
  • Team Lead/Managerunmatched
  • Technical Analysisunmatched
  • Technical Leadershipunmatched
  • Technical Supportunmatched
  • Time Managementunmatched
  • Trend Analysisunmatched
  • Vulnerability Scannersunmatched
  • Webcamsunmatched
  • Windows PowerShellunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder