Security Operation Center (SOC) Analyst II Job at Targeted Solutions, LLC, Colorado Springs, CO

bkhFOHNBR2E4Yk1SSEEvbmdwODFDR01LWGc9PQ==
  • Targeted Solutions, LLC
  • Colorado Springs, CO

Job Description

Job Description

Job Description

Salary: $56.81/Hrly

Security Operation Center (SOC) Analyst II

REQ: 25-J-0265

SOC Analysts primary function is to provide comprehensive Computer Network Defense and Response support through 247365 monitoring and analysis of potential threat activity targeting the enterprise. This position will conduct security event monitoring, advanced analytics and response activities in support of the governments mission. This position requires a solid understanding of cyber threats and information security in the domains of TTP's, Threat Actors, Campaigns, and Observables. Additionally, this candidate must be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management. This position will support activities within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide day-to-day support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.

Performance shall include:

  • Must have strong analytical and technical skills in computer network defense operations, ability to lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management) and Malware Analysis
  • Experience and ability to with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes security event triage, incident investigation, implementing countermeasures, and conducting incident response.
  • Must be knowledgeable and have hands-on experience with a Security Information and Event
  • Monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting
  • Strong logical/critical thinking abilities, especially analyzing security events (windows event logs, network traffic, IDS events for malicious intent)
  • Excellent organizational and attention to details in tracking activities within various Security Operation workflows
  • A working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks, a conceptual understanding of Windows Active Directory is also required, and a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, etc.)
  • Experience with the identification and implementation of countermeasures or mitigating controls for deployment and implementation in the enterprise network environment
  • Experience with one or more of the following technologies Network Threat Hunting, Big Data
    Analytics, Endpoint Threat Detection and Response, SIEM, workflow and ticketing, and Intrusion
    Detection System

Experience:
5 - 7 years of directly related experience
Prior performance in roles such as ISSO or ISSM (must be articulated on resume)


Education :
Bachelors degree in a related area or equivalent experience (minimum 4 years)


Certifications:
Must meet position and certification requirements outlined in DoD Directive 8570.01-M for
Information Assurance Technician Level 2 or Information Assurance Manager Level 2 or CND Auditor
or Incident Responder certification within 6 months of the date of hire


Security Clearance:

Top-Secret clearance
Current clearance as defined in the Task Order
Eligibility for access to Special Access Program Information
Willingness to submit to a Counterintelligence polygraph


Other Requirements:
Ability to develop rules, filters, views, signatures, countermeasures and operationally relevant

applications and scripts to support analysis and detection efforts.
An understanding in researching Emerging Threats and recommending monitoring content within
security tools.
Experience in analyzing NetFlow data and packet capture (PCAP).
Robust knowledge of common attack methodologies, tactics and protocols
Knowledge of the TCP and IP protocol suite, security architecture, DNS and remote access security
techniques and products.
Technical experience in the information security field utilizing a mix of security technology such as: Intrusion
Detection & Prevention Systems (IDS/IPS), Firewalls & Log Analysis. SIEM, Network Behavior Analysis tools,
Antivirus, and Network Packet Analyzers, Digital Forensics tools in an Enterprise environment, Cyber
Incident Response activities in an Enterprise environment.

BENEFITS:

We offer a competitive compensation package including a generous PTO and Flexible holiday package, tax-free healthcare cost reimbursement, and an immediate vesting 401K with 4% matching.

Job Tags

Holiday work, Immediate start, Flexible hours,

Similar Jobs

The John Hopkins Health System

PRN LACTATION CONSULTANT Job at The John Hopkins Health System

You Belong Here. Join our Sibley Nursing Team as a Lactation Consultant and become part of world-renowned Johns Hopkins Health System! What nurses love about Sibley:Free Onsite parking!Emphasis on RN growth and developmentFree employee gym, employee vegetable gardens... 

Lensa

Remote Sr. Healthcare Data Analyst Job at Lensa

 ...Insight Global, is seeking professionals. Apply via Lensa today! Job Description Insight Global is looking for a remote healthcare data analyst for a large healthcare company. This candidate will be helping with the implementation of the population health platform,... 

McDonald's Corporation

Cybersecurity Engineer III Job at McDonald's Corporation

 ...all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our...  ...Delivery, Digital and Drive Thru). McDonalds will accelerate technology innovation so 65M+ customers a day will experience a fast, easy... 

Selby Jennings

Full Stack Java/React Developer Job at Selby Jennings

 ...Full Stack Java/React Developer - Post Trade Technology We're seeking a Full Stack Java/React Developer to join our dynamic Post Trade Technology team. In this fast-paced and collaborative role, you'll partner with Operations, Treasury, and Compliance to build innovative... 

PepsiCo

Maintenance Planner Job at PepsiCo

 ...globally and act locally, constantly innovating to sustain our planet, our people, our communities and our business practices. We are a think tank, bringing our ideas into action and are determined to find ways to drive efficiencies, improve processes and achieve the highest...