We're currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to support our on-site team in Crystal City (Arlington, VA).Location DetailsThis is a full time on site position with our Coalfire Federal team supporting a government customer.
- Open to local candidates in the DMV reporting to our in person team in Arlington, Virginia.
- Also open to local candidates residing in Denver, Colorado to report to on client site location in CO.
What you'll do- Monitors and analyzes for potential threat activity.
- Provides real-time alerting and monitoring by capturing, indexing, and correlating data in a searchable repository to generate graphs, reports, alerts and visualizations. Provides metrics, diagnoses security problems.
- Provides engineering support, operations, and maintenance of security tools.
- Utilizes Security, Information, and Event Monitoring (SIEM) tools to identify security events and incidents to evaluate the effectiveness of current security measures.
- Maintains Tenable Security Center administrator responsibilities, routine maintenance of the front end including but not limited to user accounts, scan polices, and reports.
- Conducts daily and ad-hoc vulnerability scanning on networks and systems.
- Prepares reports of metrics for vulnerability management that is briefed to senior leadership to convey network security status.
- Participates and contributes to weekly meetings with O&M team to discuss vulnerability patch management status.
- Tracks, maintains, and verifies findings. Promote timely remediation before due date and/or work with stakeholders on extension request.
- Conducts DISA STIG baseline configuration scanning of hardware and network devices and manually reviews CAT I and CAT II items that cannot be checked via automated scan.
- Monitors incoming events and maintain Audit Log Management using Splunk Tool.
- Validates hardware and software inventory for a portfolio of systems.
- Uses advanced analytic tools to determine presence of emerging threat patterns and vulnerabilities.
- Utilizes in-depth operational and technical knowledge of security concepts to provide technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation.
- Provides technical evaluations of customer systems and assists with making security improvements.
- Conducts product evaluations, and recommends products, technologies and upgrades to improve the customer's security posture.
- Conducts testing and audit log reviews.
What you'll bringIn addition to the duties listed above, utilizes the following cyber tools or equivalents:
• Splunk Enterprise Security
• Q-Audit ICS-500-27 Splunk application
• Tenable Nessus Security Center
• Cylance
• Extrahop
• Burp Suite
EducationCompleted Bachelor's degree from an accredited university, preferably in an IT related field.
Clearance / Suitability An active Secret or Top Secret clearance is required.
Certifications One or more of the following: CISSP, CISA, CISM, Security+, CAP
Years of Experience - At least five (5) years of information technology, cybersecurity experience for a consulting organization, including skills and responsibilities relative to the SOC role
Bonus Points- Previous DOJ experience
- Military experience