Cyber Threat Analyst (Threat Intel Team)

Falls Church, VA

GuidePoint Security LLC

View company page

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

Candidates MUST have an active Top Secret/SCI clearance with a CI or FSP Poly for consideration. This position is not remote.

Splunk Security Architects fuel solutions to ensure enterprise security deployments make the deepest impact possible across an organization. They solve organizations’ most challenging problems, including the ones they didn't know existed. They are self-motivated, have an insatiable thirst to learn new technologies and thrive in a fast paced environment. Lastly, they feel comfortable mastering new technologies and come from a variety of business, analytic and technology backgrounds. 


Role and Responsibilities:

  • Implement a dynamic, advanced Risk-Based Alerting (RBA) security framework within Splunk
  • Create and test detections written in advanced Splunk Programming Language (SPL)
  • Perform analysis on hosts running on a variety of platforms and operating systems, to include, but not limited to, Microsoft Windows, UNIX, Linux, as well as embedded systems and mainframes.
  • Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system logs) to identify possible threats to network security.
  • Leverage tools including Splunk, Tanium, FireEye suite as part of duties performing cyber incident response analysis.
  • Act as an observer to Red Team penetration testing exercises and collaborating with Cybersecurity Operations Center (CSOC)
  • Correlate event or incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.
  • Work with a diverse team of analysts in conducting incident triage, incident handling, and remediation.


Position Requirements:

    • 5+ years’ experience with Splunk, MITRE ATT&CK Framework, Endpoint Security Services
    • Experience with host level scripting, eg. Powershell.
    • Experience in working with one or more Cloud Platforms
    • Familiarity with cybersecurity operation center functions
    • Linux Administration and monitoring
    • Windows Administration and monitoring
    • Experience with Security framework and can interpret use cases into actionable monitoring solutions.

Strong working knowledge of:

  • Security Information and Event Management (SIEM) systems.
  • Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS).
  • Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS).
  • Network and Host malware detection and prevention.
  • Network and Host forensic applications.
  • Web/Email gateway security technologies.
  • Sysmon.
  • Log aggregation tools.
  • Demonstrated ability to establish priorities, manage shifting priorities, and handle numerous time-sensitive projects with multiple deadlines
  • Ability to accomplish goals working through formal and informal channels, with diplomacy and tactfulness
  • Demonstrated solid planning and organizational skills
  • Demonstrated experience working independently and as part of a team

We use Greenhouse Software as our applicant tracking system and communicate through their systems. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 750 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 3,000 Enterprise-Level customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • 100% employer-paid medical premiums (employee only $0 deductible and HSA plans) along with 75% employer-paid family contributions
  • 100% employer-paid dental premiums (employee only) along with 75% employer-paid family contributions
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Care plan

 

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Clearance Cloud CSOC Endpoint security Firewalls IDS Incident response Intrusion detection Intrusion prevention IPS Linux Log files Malware MITRE ATT&CK Monitoring Network security Pentesting PowerShell Red team Scripting SIEM Splunk Top Secret TS/SCI UNIX Vulnerabilities Windows

Perks/benefits: Career development Flex hours Flex vacation

Region: North America
Country: United States
Job stats:  24  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.