ASRC

T2021 - Information Security Engineer

ASRC$115K — $135K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science or related field
  • U.S. Citizenship with active Secret Clearance
  • Active DoD 8570 IAT Level II certification or greater
  • 3+ years in Cybersecurity Incident Response/SOC duties
  • Knowledge of Incident Response Handling Procedures (NIST SP 800-61)
  • Familiarity with cyber adversary tactics and frameworks (e.g., ATT&CK)
  • Knowledge of cybersecurity tools: Trellix/ESS, Tanium, Microsoft Defender Endpoint, BeyondTrust, Splunk

Responsibilities

  • Monitor security tools for alerts, anomalies, and suspicious activity
  • Conduct threat intelligence analysis for indicators of compromise (IOCs)
  • Collaborate with vulnerability management teams on security scans
  • Collect and analyze security-related logs from various sources
  • Create and maintain Incident Response and SOC SOPs
  • Perform technical incident response investigations
  • Track incident response and report on findings

Benefits

  • Hybrid work option (onsite 4 days per week)
  • Opportunity to work on high-priority investigations
  • Contributing to the improvement of cybersecurity capabilities
  • Engaging with a variety of cybersecurity tools and methodologies
  • Involvement in a critical DoD cybersecurity contract
Full Job Description
ASRC Federal NetCentric Technology seeks a Cybersecurity SOC-IRAnalyst to support one of our Cybersecurity Support Services contracts. This is an hybrid position located at Seaside, California responsible for containing, responding to, and eradicating threats and other malicious activity. This position will help maintain and improve cybersecurity incident response capabilities as well as coordinate or participate in high-priority investigations, identifying incident response improvements, and preparing reports for management. Work location is hybrid and onsite 4 days per week in Seaside California.

Key Responsibilities:
  • Monitor security tools for security alerts, anomalies, and suspicious activity, and triage those alerts to distinguish between false positives and potential threats
  • Conduct routine threat intelligence driven analysis for indicators of compromise (IOCs) and advanced persistent threats across the enterprise network and endpoints using threat intelligence and various detection methodologies
  • Collaborate with vulnerability management teams by analyzing security scan results and prioritizing vulnerabilities for remediation based on active threats and exploitability
  • Collect, normalize, and analyze security-related logs from various sources (endpoints, network devices, applications) to establish baselines, detect deviations, and support ongoing investigations
  • Create and maintain Incident Response (IR) and Security Operations Center (SOC) SOP in accordance with CJCSM 6510.01B, NIST SP 800-61R2, DoD regulations, and industry best practices
  • Perform technical incident response investigations into cybersecurity related events and incidents
  • Determine the nature, scope, and cause of incidents including root cause analysis
  • Identify corrective actions and aid in the containment, eradication, and recovery of a given event and incident
  • Track incident response, corrective measures taken, recommendations, and remediation activities; complete incident reports for investigations as needed; provide or contribute to weekly report of events and incidents
  • Respond to and investigate cyber events should an incident occur after regular business hours

Required Skills:
  • Knowledge of Incident Response Handling Procedures (NIST SP 800-61)
  • Familiarity with cyber adversary tactics and frameworks (such as ATT&CK and D3FEND)
  • Knowledge of one or more of the following cybersecurity tools:
    • Trellix/ESS
    • Tanium
    • Microsoft Defender Endpoint
    • BeyondTrust
    • Splunk

Required Qualifications:
  • Bachelor's degree in computer scienceor related field
  • U.S. Citizenshipand an activeSecret Clearance (required) with the ability to obtain and maintain a Top-Secret Clearance.
  • Active DoD 8570 IAT Level II certification or greater, including at least one of the following certifications in good standing: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
  • Active DoD 8570 CSSP Incident Responder certification a plus, including at least one of the following certifications in good standing: CEH, CFR, CCNA Cyber Ops, CHFI, CySA+, GCFA, GCIH, SCYBER, or PenTest+
  • 3+ yearsin performing Cybersecurity Incident Response and Security Operations Center (SOC) duties
  • Required to work onsite daily at our DoD customer office location in Seaside, California.


California Residents: This position offers a pay range of $115,000.00 - $135,000.00 depending on experience, seniority, geographic locations, and other factors permitted by law.

pplicable field, or an equivalent combination of education and experience.

About ASRC

Arctic Slope Regional Corporation (ASRC) is an Alaska Native corporation that was established in 1972 under the Alaska Native Claims Settlement Act (ANCSA). The company is owned by approximately 13,000 Iñupiat shareholders who live primarily in eight villages on Alaska's North Slope. ASRC is a diversified company with subsidiaries involved in oil and gas exploration and production, government services, construction, and resource development. The company has a strong commitment to sustainability and environmental stewardship, and has implemented a number of initiatives to reduce its environmental impact.
Learn more about ASRC
Size
3,500 employees
Industry
Founded
2003

Similar Jobs

More Jobs at ASRC

More Information Technology Jobs

Find similar T2021 - Information Security Engineer jobs: