Lincoln Laboratory

Security Analyst

Lincoln Laboratory$95K — $126K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • CompTIA CYSA+ Certification or equivalent
  • Experience with security tools including SIEM and SOAR
  • Strong knowledge of Cyber Security in Cloud / DevSecOps and scripting (preferably Python)
  • Understanding of TCP/IP and application layer protocols (HTTP, SMTP, DNS)
  • Ability to analyze log data for signs of malicious activity and create alerts
  • Familiarity with Windows, Mac, Linux operating systems and their event logging
  • Strong technical documentation skills, including SOPs and incident reports
  • Exceptional customer service and communication skills

Responsibilities

  • Administer and maintain cyber protection tools and SOPs
  • Perform rapid threat analysis on suspicious messages and links
  • Investigate sensor detections to assess severity of threats
  • Coordinate mitigation efforts among analysts to prevent duplication
  • Supervise data/system scans for malicious content
  • Develop technical project plans and documentation for security initiatives
  • Proactively research current cyber threats and vulnerabilities

Benefits

  • Comprehensive health, dental, and vision plans
  • MIT-funded pension
  • Matching 401K
  • Paid leave (including vacation, sick, parental, military, etc.)
  • Tuition reimbursement and continuing education programs
  • Mentorship programs
  • Flexible work-life balance options
  • Additional voluntary benefits, discounts, and perks
Full Job Description
Position Description

The Security Analyst III is responsible for performing operational support for network defenses, risk analysis on cyberthreats, security alerts, systems of interest, and other suspicious system or network activity. The Security Analyst III is part of the ISD Cyber Security Operations team. The Cyber Security Operations team is actively involved with health and configuration management of security tools and works closely with the other teams within ISD Cyber Security from the start to closure of an incident. Through knowledge of network defenses data analysis, the Security Analyst identifies methods to mitigate future risk to networked systems. Also as part of the Cyber Security Team, the Security Analyst assists in the evaluation and testing of security tools and devices.

Primary Duties

Cyber Security Operations

  • Build and Administer Cyber protection tools to include creating and maintaining standard operating procedures (SOPs)
  • Expand expertise in Cyber protection tools to become subject matter expert
  • Ensure the Cyber protection tools are used to their fullest extent to protect the laboratory


Cyber Threat Analysis & Assessment

Rapid assessment and determination of active threats

  • Perform threat analysis on suspicious messages to determine if spam, phishing and or a targeted email.
  • Analyze attachments and URL links for malicious content
  • Investigate sensor detections and alerts to determine severity of threat or false positive.
  • Through log and data analysis determine scope or extent at which other systems were exposed to the same threat.
  • Coordinate efforts among analyst to enhance mitigation efforts and avoid duplication of efforts.
  • Coordinate with Security Services Department on threat impact, nature and potential scope.
  • Identify, implement or request solutions (e.g. blocks) to mitigate future risk to the Laboratory.
  • Perform Data and System of Interest AV scans


Knowledge and Experience with Cyber Security in Cloud (AWS, Azure, etc.) and DevSecOps

  • Infrastructure as code
  • Scripting
  • External Awareness
  • Research current malicious cyber activity at large.
  • Research how vulnerabilities are being exploited and software affected.
  • Proactively identify opportunities to mitigate potential threats based on research.
  • Proactively identify any patterns within device and server logs based on research to potentially identify systems of interest through log analysis.
  • Security Projects
  • Evaluate potential security software, tools or devices
  • Test new network security systems and changes to existing network security devices.
  • Develop technical project plans, requirement documentation, test plans, change requests, and communications to users.


This position is under general supervision of the Operations Team Lead.

This position does not have any financial responsibility. However technical expertise may be required for assisting with product selection and annual product support renewals. This position will maintain frequent contact with internal department and/or Laboratory user community as well as external vendors to maintain communications related to problem resolution, systems upgrades, services and product research. This position interacts frequently with the Security Services Department to maintain communication related to data recovery for forensics analysis based on request, and identification of policy violations, systems of interest putting the network at risk, threats of interest or messages of interest.

Minimum Qualifications

  • CompTIA CYSA+ Certification or equivalent
  • Working knowledge of security tools and devices including SIEM and SOAR tools
  • Working knowledge Cyber Security in Cloud / DevSecOps including scripting (Python preferred)
  • An understanding of TCP/IP network protocols and application layer protocols (e.g., HTTP, SMTP, DNS, etc.)
  • Analyze log data for signs of malicious activity and create detections and/or alerts
  • Good understanding of Windows, Mac and Linux Operating Systems and Event logging
  • Ability to work independently toward delivery of goals as well as collaborate in team efforts
  • Skill in interviewing users to determine source of potential malware or suspicious activity
  • Strong technical documentation skills, including development of SOPs, incident reports, and knowledge base articles
  • Advanced knowledge of Endpoint Detection and Response (EDR) technologies and alert triage
  • Working knowledge of firewall technologies, rule management, and network traffic analysis
  • Excellent customer service skills
  • Excellent verbal and written communication skills


Preferred Qualifications

  • Bachelor's Degree in Computer Science, Information Technologies, Engineering or equivalent experience
  • SANS GCIH (GAIC Certified Incident Handler) or equivalent, which would include solid working knowledge of incident handling
  • Skill in organizing and managing projects
  • Skill in building consensus among stakeholders and colleagues


Experience:

  • 4+ years' experience in various cyber security/SOC roles


Additional Information

Ability to obtain and maintain a government security clearance.

Occasional off-hour/on-call support is necessary. A certain degree of flexibility of schedule is required as some work (planned/unplanned) must be done outside of major production hours during pre-scheduled maintenance windows.

This position requires and individual with excellent communication (both oral and written) and organizational skills. The individual must be able to work in a fast-paced environment at times with minimal supervision and execute operations, project and administrative tasks with a high degree of quality, while following existing processes and establishing new operational procedures and best practices where necessary. Additionally, the position requires the ability to work with members of other teams and staff to accomplish department and organizational goals.

Hiring Range: $95,700 - $126,700

Disclaimer: MIT Lincoln Laboratory provides a typical hiring range as a good faith estimate of what we reasonably expect to offer for this position at the time of posting. The final salary offered to a selected candidate will depend on various factors, including-but not limited to-the scope and responsibilities of the role, the candidate's experience, skills and education/training, internal equity considerations and applicable legal requirements. This range reflects base salary only and does not include additional forms of compensation or benefits.

At MIT Lincoln Laboratory, our exceptional career opportunities include many outstanding benefits to help you stay healthy, feel supported, and enjoy a fulfilling work-life balance. Benefits offered to employees include:

  • Comprehensive health, dental, and vision plans
  • MIT-funded pension
  • Matching 401K
  • Paid leave (including vacation, sick, parental, military, etc.)
  • Tuition reimbursement and continuing education programs
  • Mentorship programs
  • A range of work-life balance options
  • ... and much more!


Please visit our Benefits page for more information. As an employee of MIT, you can also take advantage of other voluntary benefits, discounts and perks.

Selected candidate will be subject to a pre-employment background investigation and must be able to obtain and maintain a Secret level DoD security clearance.

Requisition ID: 42932

About Lincoln Laboratory

Lincoln Laboratory is a federally funded research and development center that conducts research and development in technology areas relevant to national security. The laboratory is operated by the Massachusetts Institute of Technology (MIT) and is located in Lexington, Massachusetts. Lincoln Laboratory's research areas include air and missile defense, cyber security, intelligence, surveillance, and reconnaissance, communications and information technology, and advanced electronics. The laboratory was founded in 1951 and has been responsible for many technological innovations, including the development of the first air traffic control system and the first satellite navigation system. The laboratory has a staff of over 3,000 employees, including scientists, engineers, and support staff.
Learn more about Lincoln Laboratory
Size
3,000 employees
Industry

Similar Jobs

More Jobs at Lincoln Laboratory

More Information Technology Jobs

Find similar Security Analyst jobs: