CSOC Tier 2 Analyst
at CSEngineering
Rockville, MD 20857, USA -
Start Date | Expiry Date | Salary | Posted On | Experience | Skills | Telecommute | Sponsor Visa |
---|---|---|---|---|---|---|---|
Immediate | 31 Jan, 2025 | USD 90000 Annual | 01 Nov, 2024 | 5 year(s) or above | Encase,Information Technology,Security+,Azure,Bigfix,Computer Science,Tenable,Enterprise Security,Fireeye,Power User | No | No |
Required Visa Status:
Citizen | GC |
US Citizen | Student Visa |
H1B | CPT |
OPT | H4 Spouse of H1B |
GC Green Card |
Employment Type:
Full Time | Part Time |
Permanent | Independent - 1099 |
Contract – W2 | C2H Independent |
C2H W2 | Contract – Corp 2 Corp |
Contract to Hire – Corp 2 Corp |
Description:
REQUIRED CERTIFICATIONS AND QUALIFICATIONS
- Bachelors in information technology, Computer Science, or a related field; or relevant, commensurate work experience.
- 5+ years of experience within a Level Tier 2 cybersecurity environment; experience in a leadership role is preferred.
- Robust Certification Portfolio including Security+, Network+, CEH, Azure or Cloud Certification, and Splunk Core Certified Power User.
- Ability to work a day or night shift rotational schedule.
- Vulnerability/cyber incident management framework.
- Experience with advanced technologies such as: Splunk SaaS, Splunk Enterprise Security, Splunk SaaS UBA, Crowdstrike, Tenable, Forescout, zScaler, Bigfix, MaaS-360 (IBM MaaS-360), and Encase for forensic investigations, Fireeye, Cortex XSOAR, Cortex XDR, and Prisma-Access.
- Prior HHS experience a plus.
Responsibilities:
- Respond promptly and effectively to security incidents and threats discovered by CSOC Analyst Level I and carry out effective Level II analysis of incidents.
- Remediation of incidents and escalation when necessary to Tier 3 support
- Initial assessment of the scope of the attack and affected systems
- Accurately document cases during investigations and effectively communicate findings to Level I Analyst or escalation team to ensure complete handover of work streams.
- Continuously improve incident management processes through periodic threat hunting exercises, knowledge optimization effort building, and by comprehensive diagnosis and analysis of incident trends.
- Follow the issue tracking, escalation policies and work effectively across all CSOC tiers as the technical competence requires.
- Dedicated monitoring and analysis of cyber security events by use of SOC tools
- Incident Response generation and reporting IAW established procedures.
- Provide Level II technical support in CSOC operations and activities.
- Provide daily/weekly updates on CSOC operations and developments.
- Conduct Forensic analysis and respond to data call activities.
- Generate quality technical reports containing methodologies, findings, and recommendations.
- Work with external stakeholders to understand operational needs and develop effective processes.
- Maintain a current understanding of industry trends, emerging cyber threats, and new solutions which may impact CSOC activities.
- Collaborate with CSOC SME to ensure optimal performance using CSOC technology.
- Identify, reverse engineering and de-obfuscating digital content related to an incident.
REQUIREMENT SUMMARY
Min:5.0Max:10.0 year(s)
Information Technology/IT
IT Software - Network Administration / Security
Other
Graduate
Proficient
1
Rockville, MD 20857, USA