- You must possess an active Secret security clearance. You must also be able to obtain TSA suitability.
- High school diploma
- One or more vendor specific certifications (CYSA+, CEH, or equivalent)
- The Sr Security Analyst will monitor and analyze security events and alerts reported by the TSA SIEM on a 24x7 basis to identify and investigate suspicious or malicious activity, or other cyber events which violate TSA policy.
- The analyst will be responsible for analyzing logs and events from any other device types which may send logs or events to the TSA SOC in the future. Non-traditional device feeds will deliver data to the SIEM architecture (e.g., Human Resources (HR) data, badging information, and physical security devices, etc.).
- The analyst will provide documentation detailing any additional information collected and maintained for each security investigation.
- The analyst will record all artifacts (i.e. emails, logs, documents, Uniform Resource Locators (URLs), screenshots, etc.) associated with all security events and incident investigations within the TSA SOC incident and tracking application.
- At least five years of experience working in a Security Operations Center (SOC) or Network Operations Center (NOC) environment performing security event monitoring and analysis
- Working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks.
- Must possess a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.)
- Must be capable of analyzing security logs and events from the following types of devices such as, but not limited to: Firewalls (FWs), Intrusion Detection Sensors/Intrusion Prevention Sensors (IDS/IPS), Host-based Intrusion Detection System/ Host-based Intrusion Prevention System (HIDS/HIPS), proxy/web filter, vulnerability scans, routers, router Internet Protocol (IP) accounting systems (i.e., Cisco NetFlow), Virtual Private Network (VPN) gateways/concentrators, server event logs, e-mail and host anti-virus, desktop security monitoring agents, anti-virus servers, IP services (i.e. Domain Name System (DNS) Services, Dynamic Host Configuration Protocol (DHCP), network address translation devices, MDM (e.g. cellphones), Public Key Infrastructure (PKI), and cloud security infrastructure (e.g. Amazon Web Services (AWS), Azure, Oracle, Salesforce, etc.)
- Advanced knowledge of common adversarial tactics, techniques, and procedures (TTPs)
- Ability and prior experience with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes the identification of malicious code present within a computer system as well identification of malicious activities that are present within a computer system and/or enterprise network.
- Experience with Splunk query language.
- Experience with IDS/IPS/firewall/security configurations and signature development.
- Experience with PCAP analysis.
- Experience with Tanium threat response.
- Experience working with a ticket management system to collect, document and maintain information pertinent to security investigations and incidents.
- Excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings.
- Experience in monitoring the operational status of monitoring components and escalating and reporting outages of the components.
- Conceptual understanding of Windows Active Directory is also desired.
- Experience working with various event logging systems and must be proficient in the review of security event log analysis. Previous experience with SIEM platforms that perform log collection, analysis, correlation, and alerting is also preferred.
- Experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment.
- Experience in collecting and maintaining information pertinent to security; investigations and incidents in a format that supports analysis, situational awareness reporting, and law enforcement investigation efforts.
-
Tier Iii Analyst
6 days ago
Peraton Washington, United States**About Peraton** · **Responsibilities** · We are seeking a **Tier III Analyst** to join our Peraton team who will lead and actively participate in the investigation, analysis, and resolution of Tier 3 and escalated cybersecurity incidents. · **What you'll do**: · The **Tier III ...
-
Tier 3 Analyst
1 week ago
Fusion Technology Chantilly, United StatesTier 3 Analyst (Senior Security Analyst) · Who is Fusion Technology? · Fusion Technology is a performance-driven HUBZone Small Business concern residing in the heart of the beautiful mountainsides of West Virginia, steps away from the Federal Bureau of Investigation's Criminal ...
-
Tier 3 Analyst
2 weeks ago
Fusion Technology LLC Chantilly, United StatesJob Description · Job DescriptionTier 3 Analyst (Senior Security Analyst) · Who is Fusion Technology? · Fusion Technology is a performance-driven HUBZone Small Business concern residing in the heart of the beautiful mountainsides of West Virginia, steps away from the Federal Bure ...
-
Csoc Tier 2 Analyst
6 days ago
CSEngineering Rockville, United States**CSOC Tier 2 Analyst** · ***Immediate Requirement** · ***Onsite** · CSEngineering is looking to add a CSOC Tier 2 Analyst to our growing team As the Cyber Security Operations Center (CSOC) Tier 2 Team Lead, you are responsible for overseeing and managing the activities of the Ti ...
-
Csoc Tier 1 Analyst
6 days ago
CSEngineering Rockville, United States**CSOC Tier 1 Analyst** · **Immediate Requirement** · **Onsite** · CSEngineering is looking to add a CSOC Tier 1 Analyst to our growing team As the Cyber Security Operations Center (CSOC) Tier 1 Analyst, you are responsible for the initial assessment of alerts and notification to ...
-
Tier 1 Service Desk Analyst
1 week ago
Smksoft Vienna, United StatesJob Summary: · **Responsibilities**: · - Responsibilities · - Respond to inbound calls daily to provide technical support/troubleshooting · - Leverage resources to resolve technical issues timely · - Escalate requests outside of your scope when necessary · - Attend weekly staff/m ...
-
Tier 1 Service Desk Analyst
2 weeks ago
Smksoft Vienna, United StatesJob Summary: · **Responsibilities**: · - Responsibilities · - Respond to inbound calls daily to provide technical support/troubleshooting · - Leverage resources to resolve technical issues timely · - Escalate requests outside of your scope when necessary · - Attend weekly staff/m ...
-
IT Service Desk Analyst Tier 2
1 week ago
RIVA Solutions Inc. Bethesda, United StatesTitle**:IT Service Desk Tier 2 Analyst** · Location: Bethesda, MD and/or Rockville, MD · Terms: Full-time · Clearance: Public Trust · Travel: 0-20% · Education: BA/BS degree and 5 years of experience · **_ RESULTS. INNOVATION. VALUES. ACCOUNTABILITY._** · That's RIVA. Our employe ...
-
IT Service Desk Analyst Tier 1
1 week ago
RIVA Solutions Inc. Bethesda, United StatesTitle**:IT Service Desk Tier 1 Analyst** · Location: Bethesda, MD and/or Rockville, MD · Terms: Full-time · Clearance: Public Trust · Travel: 0-20% · Education: BA/BS degree and 3+ years of experience · **_ RESULTS. INNOVATION. VALUES. ACCOUNTABILITY._** · That's RIVA. Our employ ...
-
Tier Ii Help Desk Analyst
1 week ago
KeenLogic Alexandria, United StatesKeenLogic is seeking a self-motivated and driven **Tier II Help Desk Analyst **with the ability to work in a challenging, consultative, and collaborative team environment in Alexandria, VA. This position is onsite and full-time, Monday through Friday. · **Description**: · **Quali ...
-
Tier 1 Help Desk Analyst
6 days ago
SecuriGence LLC Arlington, United States**Job Title**:Tier 1 Help Desk Analyst · **Location**: Arlington, Virginia · **Clearance Level**: Secret Clearance. Top Secret Preferred. · **Summary** · We deliver essential technology services to our customers in support of their missions to sustain the national security and pr ...
-
Tier 1-2 IT Support Analyst
6 days ago
Next Step Systems Centreville, United StatesTier 1-2 IT Support Analyst, Centreville, VA · We are seeking a Tier 1-2 Support Analyst with 2 to 4 years of Helpdesk Technician experience. You should enjoy interacting with clients to solve their IT problems and issues and working with a team of energetic people who enjoy "gam ...
-
Tier 1-2 IT Support Analyst
6 days ago
Next Step Systems Centreville, United StatesTier 1-2 IT Support Analyst, Centreville, VA · We are seeking a qualified Tier 1-2 IT Support Analyst professional with 1-3 years of Helpdesk Technician experience. You will be interacting with clients to solve their IT problems and issues and work with a team of energetic people ...
-
Tier 3 SOC Analyst
2 days ago
Demo - Maximus Herndon, United States#techjob#clearanceJob Summary · Who We Seek: · •Passion Seekers. You genuinely care about the work that you do and its impact on society. · •Self-Starters. You're a go-getter who isn't afraid to step up and disrupt the status quo. · •Entrepreneurs. You bring fresh ideas to the t ...
-
Tier 3 NOSC Analyst
2 weeks ago
ManTech Herndon, United States Full timeSecure our Nation, Ignite your Future · Become an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech International, you'll help protect our national security while working on innovative projects that offer ...
-
Tier 1/ Tier 2 Analyst
2 weeks ago
Resource Management Concepts, Inc. Quantico, United StatesResource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the Un ...
-
Tier 1/ Tier 2 Analyst
2 weeks ago
Resource Management Concepts, Inc. Quantico, United StatesJob Description · Job DescriptionResource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the ...
-
Weekend Days- Incident Response Analyst, Tier 2
2 weeks ago
MindPoint Group Washington, United StatesText code IRAWD to to apply · MindPoint Group delivers industry-leading cybersecurity solutions, services, and products. We are trusted cybersecurity advisors to key government and commercial decision-makers and support security operations for some of the most security-conscious ...
-
Tier 2-3 Help Desk Analyst
6 days ago
Next Step Systems Centreville, United StatesTier 2-3 Help Desk Analyst, Centreville, VA · We are looking for a Tier 2-3 Help Desk Analyst for the Helpdesk. We are looking for candidates with 4-5 years of experience that are comfortable with going on-site to clients. The Help desk does not typically go on-site; however, we ...
-
Tier 1 Helpdesk Analyst
3 weeks ago
Leidos Reston, United StatesDescription · This role provides customer service representative support for customer Service Desk operations. This role requires an individual that is technical, customer oriented and familiar with using desktop software applications such as web browsing and client software, an ...
Tier 3 Analyst - Chantilly, United States - Fusion Technology
Description
Tier 3 Analyst (Senior Security Analyst)
Who are you?
What you'll do:
Functional Description –
Required Skills –
Preferred Skills –