Senior SOC Analyst
XOR Security is currently seeking a Senior SOC Analyst with advanced skillsets in cyber security, to develop and operate cyber security capabilities for a variety of federal customers. Candidates should have excellent written and oral communication skills, be able to work independently and as part of a team, with demonstrated leadership capabilities. Skills and experience in Operations Management, Security Event Analysis, Incident Response, Cyber Hunt, Forensics, Malware Analysis, and Cyber Threat Intelligence (skills in more than one cyber discipline are preferred) are required for this position. The ideal candidate will have hands-on experience supporting a 24x7x365 SOC environment as an analyst or engineer, experience as a technical team lead within the SOC, and operations management experience. A solid understanding of cyber threats and information security in the domains of TTP’s, Threat Actors, Campaigns, and Observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management.
Corporate duties such as solution/proposal development, corporate culture development, mentoring employees, supporting recruiting efforts, will also be required. In addition, flexibility in work locations within the DC Metro Area and performing varying duties is a must.
Job duties include:
- Manage a SOC to provide cyber defense capabilities to a federal entity provide comprehensive Computer Network Defense support through security event monitoring, advanced analytics and response, and cyber intelligence activities in support of the CND operational mission
- Conduct quality assurance reviews of all SOC activities through reviewing of metrics and case analysis
- Serve as a technical Cyber SME and onsite task lead
- Maintain a 24x7 schedule and minimum-manning requirements
- Lead efforts Planning, organization, scheduling and progress reporting of various projects
- Construct and optimize operational workflows for 24x7 teams across multiple shifts
- Develop, collect, analyze security operational metrics to optimize SOC performance and minimize organizational risk
- Research, evaluate, recommend, and design new security technologies and supporting infrastructure
- Develop technical cyber security solutions in response to customer requests or in support of proposal solution development
- Provide technical writing support in support of corporate response to RFPs/RFQs from various customers
- Support new XOR engagements as transitional program or operations lead
- Support documentation of all business and workflow processes in this area
- Provides technical consultation in cyber security capability development
- Maintains current knowledge of relevant cyber security and related technologies as assigned
- Serves as liaison with various customers (internal and external)
- Acts as a subject-matter expert to multiple tasks and/or programs
Candidate must have the required Qualifications:
- At least 3 years of experience in a cyber network defense environment performing analysis and engineer functions and 2 years of experience as a team lead or operations management
- Bachelor’s Degree in Information Technology, Cyber Security, Computer Science, Computer Engineering, or Electrical Engineering.
- Active Secret Clearance.
- Strong analytical and technical skills in computer network defense operations, triage, investigation, and incident response efforts
- Previous hands-on experience with a Security Information and Event Monitoring (SIEM) platforms and log management systems that perform log collection, analysis, correlation, and alerting (preferably within Splunk or ArcSight).
- Prior experience and ability to with analyzing information technology security events to discern events that qualify as a legitimate security incident as opposed to non-incidents. This includes security event triage, incident investigation, implementing countermeasures, and conducting incident response.
- Existing Subject Matter Expertise of Advanced Persistent Threat or Emerging Threats.
- Strong proficiency in report writing and briefing senior management
- Excellent organizational and attention to details in tracking activities within various Security Operation workflows.
- A working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks, a conceptual understanding of Windows Active Directory is also required, and a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.).
- Experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment.
- Ability to work on-call during critical incidents or to support coverage requirements (including weekends and holidays when required).
- Secret Clearance
- Experience in mentoring and training junior, mid-level, and senior analysts.
- Proficiency in utilizing various packet capture (PCAP) applications/engines and in the analysis of PCAP data.
- Ability to develop rules, filters, views, signatures, countermeasures and operationally relevant applications and scripts to support analysis and detection efforts.
- One or more certifications for CND Analysts: GCIA, GCFA, GCFE, GREM, GISF, GMON, GXPN, CHFI, GNFA, CCFP, LPT, CHFI, CSA.
- One or more certifications for a manager: CISSP, PMP, CISM, ITILv3
XOR Security offers a very competitive benefits package including health insurance coverage from the first day of employment, 401k with a vested company match, vacation and supplemental insurance benefits.
XOR Security is an Equal Opportunity Employer (EOE). M/F/D/V.
Citizenship Clearance Requirement - Applicants selected must meet background investigation eligibility requirements - US CITIZENSHIP and a Secret clearance.
More Information Security position highlights
- Explore open Information Security Architect Jobs
- Explore open SOC Analyst Jobs
- Explore open Threat Intelligence Response Analyst Jobs
- Explore open Senior Penetration Tester Jobs
- Explore open Staff Security Engineer Jobs
- Explore open Information Security Officer Jobs
- Explore open Vulnerability Analyst Jobs
- Explore open Software Security Engineer Jobs
- Explore open Threat Intelligence Analyst Jobs
- Explore open Infrastructure Security Engineer Jobs
- Explore open Computer Network Defense & Incident Response Analyst - Mid to Senior Level Jobs
- Explore open DevOps Security Engineer Jobs
- Explore open Senior Information Security Engineer Jobs
- Explore open Chief Information Security Officer Jobs
- Explore open IAM Engineer Jobs
- Explore open Computer Forensic Software Engineer Jobs
- Explore open Staff Engineer, Cloud Security Jobs
- Explore open Manager, Cybersecurity and Trust Jobs
- Explore open Sr. Software Engineer - Detection Engineering Jobs
- Explore open Cybersecurity Analyst Jobs
- Explore open Cybersecurity Engineer Jobs
- Explore open Personnel Security Officer Jobs
- Explore open Engineering Manager - Information Security, Bangalore Jobs
- Explore open Senior Information Security Analyst Jobs
- Explore open Cyber Threat Analyst Jobs
- Explore open Clearance-related jobs
- Explore open CEH-related jobs
- Explore open Audits-related jobs
- Explore open Open Source-related jobs
- Explore open Forensics-related jobs
- Explore open PCI-related jobs
- Explore open Risk management-related jobs
- Explore open IDS-related jobs
- Explore open NIST-related jobs
- Explore open Ruby-related jobs
- Explore open OSCP-related jobs
- Explore open Machine Learning-related jobs
- Explore open Splunk-related jobs
- Explore open AI-related jobs
- Explore open Google-related jobs
- Explore open IPS-related jobs
- Explore open Security assessments-related jobs
- Explore open Threat detection-related jobs
- Explore open Encryption-related jobs
- Explore open Unix-related jobs
- Explore open Docker-related jobs
- Explore open DNS-related jobs
- Explore open PowerShell-related jobs
- Explore open TCP/IP-related jobs