Jobs

    Cybersecurity Threat Detection Developer - Washington, United States - Capgemini Government Solutions LLC

    Capgemini Government Solutions LLC
    Capgemini Government Solutions LLC Washington, United States

    1 week ago

    Default job background
    Description

    Capgemini Government Solutions (CGS) is seeking a highly motivated Cyber Security Content Developer/ Cyber Threat Detection Developer (Threat Detection Developer) for User Activity Monitoring (UAM) to join our team to support our government clients. This role requires a Content Developer to provide support for onsite Insider Threat support services providing immediate investigation and resolution. Any qualified Cyber Threat Detection Developer will need to have an active Top-Secret clearance with SCI eligibility.

    This role is an opportunity to apply and grow your skillset in development work with a motivated and rapidly growing company, working with a wide range of technology-forward clients, and building CGS' capabilities.

    Job Responsibilities:

    • Self-directed team member who develops, implements, maintains, and supports SIEM dashboards, reports, alerts, and knowledge objects
    • Create baselines, queries, dashboards, and visualization to support customer requirements shared with the SecOps and operational teams to identify trends, etc.
    • Manages and administers the tuning of rules, triggers, policies, signatures, and custom content for specialized CND applications and systems
    • Apply knowledge of regular expressions to create extractions and apply working knowledge of Power Shell or other scripting language(s)
    • Utilize knowledge of latest cyber threats and attack vectors to develop and or maintain custom correlation rules from all indexed sources to support continuous event monitoring and alerting
    • Participate in discussions to make recommendations on improving SOC cyber visibility, process improvements, and reducing the incident remediation period
    • Review all existing network event collections to determine if relevant data is present and make technical recommendations to develop or enhance alerting actions
    • Enhance customer's ability to accomplish mission initiatives by delivering forward-thinking solutions that are not defined by requirements
    • Author reports and/or interface with customers for ad-hoc requests
    • Provide expert guidance and mentorship to junior analysts

    Required Qualifications:

    • US Citizen. Must have an active Top-Secret clearance (SCI eligible)
    • Bachelor's degree in computer science, Information Technology, or a related field, or equivalent work experience
    • Five years of experience in developing, implementing, and managing SIEM correlation rules and content (such as Splunk, ArcSight, Kibana, LogRhythm)
    • Experience with writing audit log parsers for SIEM data structures such as ArcSight's CEF or Splunk's SPL
    • Advanced knowledge of TCP/IP (Transport protocols geared to Network Engineering - Maybe change to encryption methods e.g. SSL/TLS and PKI) protocols, experience configuring and implementing various technical security solutions, extensive experience providing analysis and trending of security log data from security devices
    • Must have demonstrated the ability to tune the SIEM event correlation rules and logic to filter out security events associated with known and well-established network behavior, known false positives, and/or known errors
    • Experience developing advanced correlation rules utilizing stats and data models for cyber threat detection
    • Experience with Network Monitoring Tools such as proxy, load balancing, IDS/IPS, and packet capturing tools
    • Experience in a scripting language (e.g. Bash, Powershell, etc) and automating SOC processes/workflow
    • Experience implementing security methodologies and SOC processes
    • Ability to effectively work independently and as a team member
    • Work experience with Security Operations Center (SOC) or Industry Red Team
    • Facilitate excellent problem-solving, critical thinking, and analytical skills with the ability to de-construct problems
    • Work experience with the Intelligence Community
    • Critical thinking skills
    • Must possess strong written and verbal communication skills and must be capable of understanding, documenting, communicating, and presenting technical issues in a non-technical manner to audiences with varying degrees of technical expertise

    Preferred qualifications:

    • Highly Preferred to have an Active SCI
    • Splunk Enterprise Security Admin, Splunk Certified Developer certification
    • Extensive experience with User activity monitoring (UAM) ,User Entity Behavior Analytics (UEBA) and DLP tools
    • Expertise in developing Insider Threat trigger policies
    • Investigate and analyze events of interest within the SIEM, document workflows, and identify process improvements in the handling and remediation of cybersecurity events
    • requirements?
    • Identifies and remediates visibility gaps of cyber defense systems
    • Experience with Installing and administering COTS applications on RHEL Linux and/or Windows
    • Hands-on experience with one of the enterprise cybersecurity toolsets: HBSS/ESS , Trellix and ePolicy Orchestrator
    • Hands-on experience running Tenable or vulnerability tracking/scanning systems
    • Other highly desired certifications: CEH , CYSA+ , GICSP, SSCP, CND

    Life at Capgemini

    Capgemini supports all aspects of your well-being throughout the changing stages of your life and career. For eligible employees, we offer:

    • Flexible work
    • Healthcare including dental, vision, mental health, and well-being programs
    • Financial well-being programs such as 401(k) and Employee Share Ownership Plan
    • Paid time off and paid holidays
    • Paid parental leave
    • Family building benefits like adoption assistance, surrogacy, and cryopreservation
    • Social well-being benefits like subsidized backup child/elder care and tutoring
    • Mentoring, coaching, and learning programs
    • Employee Resource Groups
    • Disaster Relief

    About Capgemini

    Capgemini is a global leader in partnering with companies to transform and manage their business by harnessing the power of technology. The Group is guided every day by its purpose of unleashing human energy through technology for an inclusive and sustainable future. It is a responsible and diverse organization of over 360,000 team members in more than 50 countries. With its strong 55-year heritage and deep industry expertise, Capgemini is trusted by its clients to address the entire breadth of their business needs, from strategy and design to operations, fueled by the fast-evolving and innovative world of cloud, data, AI, connectivity, software, digital engineering and platforms. The Group reported in 2022 global revenues of €22 billion.

    Get The Future You Want |

    Disclaimer

    Capgemini is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.

    This is a general description of the Duties, Responsibilities and Qualifications required for this position. Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodations do not pose an undue hardship.

    Capgemini is committed to providing reasonable accommodations during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.

    Click the following link for more information on your rights as an Applicant

    Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.

    Applicants for employment in the US must have valid work authorization that does not now and/or will not in the future require sponsorship of a visa for employment authorization in the US by Capgemini.

    Capgemini discloses salary range information in compliance with state and local pay transparency obligations. The disclosed range represents the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting, although we may ultimately pay more or less than the disclosed range, and the range may be modified in the future. The disclosed range takes into account the wide range of factors that are considered in making compensation decisions including, but not limited to, geographic location, relevant education, qualifications, certifications, experience, skills, seniority, performance, sales or revenue-based metrics, and business or organizational needs. At Capgemini, it is not typical for an individual to be hired at or near the top of the range for their role. The base salary range for the tagged location is [$120K- $135K].

    This role may be eligible for other compensation including variable compensation, bonus, or commission. Full-time regular employees are eligible for paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.

    Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that is allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company's sole discretion, consistent with the law.



  • Capgemini Government Solutions LLC Washington, United States

    Capgemini Government Solutions (CGS) is seeking a highly motivated Cyber Security Content Developer/ Cyber Threat Detection Developer (Threat Detection Developer) for User Activity Monitoring (UAM) to join our team to support our government clients. This role requires a Content D ...


  • ECS Limited Washington, United States

    ECS is seeking a Cybersecurity Operations Specialist - Tier 3 to work in our Washington, DC office.Job Description: Cloud Security: Plan, implement, upgrade, or monitor security measures for the protection of House assets and information hosted on cloud platforms. Understand and ...


  • ECS Limited Washington, United States

    ECS is seeking a Cybersecurity Operations Specialist - Tier 3 to work in our Washington, DC office. · Job Description: · Cloud Security: Plan, implement, upgrade, or monitor security measures for the protection of House assets and information hosted on cloud platforms. Understan ...


  • Program for Appropriate Technology in Health Washington, United States

    PATH current employees - please log in and apply Here · PATH is a global nonprofit dedicated to achieving health equity. With more than 40 years of experience forging multisector partnerships and with expertise in science, economics, technology, advocacy, and dozens of other spe ...

  • NetWitness

    Senior Consultant

    5 days ago


    NetWitness Washington, United States

    Company Job Description: NetWitness Senior Consultant · As one of the most established cybersecurity companies in the world, we at NetWitness are hard at work every day helping our customers and partners better protect their organizations from cyberattacks. Our products and incid ...


  • Cybernetic Washington, United States

    Role Description · Ot he behalf of our client, we are seeking a full-time onsite Red Team Operations Operator for a project with a governmental entity based in Washington DC. The role entails executing red team exercises, conducting penetration tests, physical security assessment ...

  • Foxhole Technology

    SOC Analyst III

    2 days ago


    Foxhole Technology Washington, United States

    Title: SOC ANALYST III · Location: Washington, DC (Onsite) · Salary: Based on experience, education and certification · Clearance: Public Trust (6C) · Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recogn ...


  • Knewin Washington, United States

    Be visionary · Teledyne Technologies Incorporated provides enabling technologies for industrial growth markets that require advanced technology and high reliability. These markets include aerospace and defense, factory automation, air and water quality environmental monitoring, e ...


  • Maveris Washington, United States

    Washington, District of Columbia, United States - Remote · Maveris · Maveris is an IT and cybersecurity company committed to helping organizations create secure digital solutions to accelerate their mission. We are Veteran-owned and proud to serve customers across the Federal G ...


  • RIT Solutions, Inc. Washington, United States

    Computer Vision Data Scientist · Remote Computer vision experience · Masters degree with 3 year working experience or PhD · Remote working · Contract to at least 1/31/2025 · We're looking for an incredible Senior Computer Vision Data Scientist to create computer vision mode ...


  • DCS Services Washington, United States

    DCS is looking for an experienced software engineer to support modeling, simulation, and analysis of IRCM (Infrared Countermeasure) and MWR (Missile Warning Receiver) systems along with the development of requirement and techniques working at customer facility in Washington, DC. ...


  • Teledyne Technologies Washington, United States

    Be visionary · Teledyne Technologies Incorporated provides enabling technologies for industrial growth markets that require advanced technology and high reliability. These markets include aerospace and defense, factory automation, air and water quality environmental monitoring, ...


  • Quadrant Washington, United States

    Cyber Security Analyst III · Washington, DC Hybrid · MUST: · Experienced Cyber Security Analyst III · 8+ years of Cyber Security Analyst experience supporting a federal/government project · Experience conducting Security Assessments on various size information systems to include ...


  • AHU Technologies Recruitment Washington, United States

    Job Description: · Short Description : The contractor is responsible for the organization's security program including but not limited to daily operations of the IT security program. · Complete Description: · The Security Lead will support the Clients under the Technical Progr ...


  • Reality Defender Washington, United States

    About Reality Defender · Reality Defender is a groundbreaking security platform offering comprehensive deepfake detection. A Y Combinator graduate, Comcast NBCUniversal LIFT Labs alumni, and backed by DCVC, Reality Defender's proactive deepfake and AI-generated content detection ...


  • Cybernetic Search Washington, United States

    On he behalf of our consulting client, we are seeking a full-time onsite Senior Red Team Operator for a project with a governmental entity based in Washington DC. The role entails executing red team exercises, conducting penetration tests, physical security assessments, and innov ...


  • Quadrant Inc Washington, United States

    Job ID: · Cyber Security Analyst III · Washington, DC Hybrid · MUST: · Experienced Cyber Security Analyst III · 8+ years of Cyber Security Analyst experience supporting a federal/government project · Experience conducting Security Assessments on various size information systems ...


  • vTech Solution Washington, United States

    Job Details: · Job Title : SOC Cyber Security Engineer · Job Location : Washington, DC · Job Duration : 12 Months + possibility of an extension · Job Description: · The client is looking for a skilled Cyber Security Engineer with expertise in cloud Security Operations Center ...


  • International Foundation for Electoral Systems Washington, United States

    · About International Foundation for Electoral Systems (IFES): IFES advances democracy for a better future. We collaborate with civil society, public institutions, and the private sector to build resilient democracies that deliver for all. Our technical assistance and applied re ...

  • XOR Security

    SOC Analyst Lead

    1 week ago


    XOR Security Washington, United States

    Job Title: SOC Analyst Lead · Location: st St NW Washington, District of Columbia Onsite twice a week · Clearance Level: Public Trust · Required Certification(s): An industry technical certification such as GCIH, MS-SC200 or other MS cloud certifications · SUMMARYXOR Securit ...