The Opportunity: Responsible for building/maintaining data-pipelines for associated information used for cybersecurity investigation within the enterprise. In this role you will have the opportunity to contribute to one or more areas including (but not limited to) data ingest, data normalization, SIEM management, Linux/Windows host administration, virtual machine (VM) management, and cloud asset management. To support our team, you will need to be experienced, driven, and have strong Linux, Windows, and/or networking experience. You will be collaborating closely with peers and customers which means you need to be an active listener, detail oriented, and a clear communicator. Responsibilities: • Resolve escalated issues and perform root cause analysis for complex issues • Have ability to communicate with program SMEs as well as other customers with less technical backgrounds • Demonstrate a high attention to detail, examining every aspect of the system • Be able to multi-task, working with several different customers in various stages of onboarding process • Apply Configuration Management disciplines to maintain hardware/software revisions, security patches, hardening, and documentation • Coordinate and conducts event collection, log management, event management, compliance activities, and identity monitoring activities for the customer's system • Works with other Service Providers to support areas of common interest • Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability • Maintain system availability and reliability with a threshold of 99.99% • Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation • Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes • Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management • Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions • Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost) • Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, polices, guidance, procedures etc. • Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed
Number of Employees
5,001-10,000 employees