Cyber Security Data Analysis-SIEM - Springfield, United States - Abile Group, Inc.

    Abile Group, Inc.
    Abile Group, Inc. Springfield, United States

    Found in: Lensa US 4 C2 - 1 week ago

    Default job background
    Description

    Overview:

    Abile Group has an exciting and challenging opportunity for a Cyber Security Data Analysis on a 10 year contract providing Network and Cybersecurity services supporting an Intelligence Community customer. All the personnel on the team will work together to support transport and cybersecurity information technology (IT) services on multiple networks and security domains, at multiple locations worldwide, inclusive of new facilities and building constructions to support the IC mission.

    The right candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.

    Responsibilities:
    • Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software
    • Maintain system availability and reliability with a threshold of 99.99%
    • Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation
    • Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge
    • management platform
      Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management
    • Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions
    • Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.
    • Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost)
    • Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, polices, guidance, procedures etc.
    • Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN Joint Incident Management System, DoD CIO DoD Scorecard/Get to Green reporting, IC CIO Cybersecurity Performance Evaluation Model reporting, etc.)
    • Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions
    • Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services
    Qualifications:

    Clearance Required: Active or Reinstateable TS/SCI required with ability to pass a CI poly

    Degree and Years of Experience: Bachelors (BA/BS) or equivalent experience and minimum 3 or more years of related work experience

    Required Certifications:

    • DoD M IAT Level II and CSSP Infrastructure Support certifications (must have at least a Security+ CERT to start on program and required to obtain any other required CERT within 4 months)

    Required Skills:

    • SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)
    • Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules
    • Creating SIEM playbooks
    • Linux (RHEL) Expert (administration and engineering)
    • Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives
    • Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events
    • Creation of ArcSight rules based on use cases of malicious events
    • Tuning and aggregation of queries and filters
    • Skilled in troubleshooting event flow through Enterprise Audit infrastructure
    • Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools
    • Experience with SIEM and Development Projects
    • Experience with SIEM support for projects and technical exchange meetings
    • Experience developing and maintaining enterprise audit projects

    Desired Skills:

    • Kibana
    • Data Analytics
    About Abile Group, Inc.:

    Abile Group, Inc. was formed in July 2004 to partner with the Intelligence Community and their Contractors in the areas of Enterprise Analytics & Performance Management, IT & Systems Engineering and Program & Project Management. We have significant experience with the Federal Government and are an EDWOSB dedicated to our employees and clients. We are looking for high performing employees who enjoy providing advice and guidance along with solutions development and implementation support, crafted by combining industry best practices with the clients subject matter experience and Abiles breadth of expertise.

    EEO Statement:

    Abile Group, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Anyone requiring reasonable accommodations should email with requested details. A member of the HR team will respond to your request within 2 business days.

    Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.