Cyber Security Operations Specialist

General DynamicsSpringfield, VA
349d$91,811 - $112,700

About The Position

GDIT is seeking a motivated, career and customer-oriented Cybersecurity Operations Specialist to perform on our Cybersecurity Data Analysis Services team in the Springfield, VA area. The team member shall provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) capability (i.e. Enterprise Audit), long-term analytics platform, log aggregation platform, and the cyber threat intelligence capability, signature development and deployment, and reputation management services. This includes the onboarding of all new and existing IT resources, and ensuring the correct routing of all audit events to mission partners in accordance with Intelligence Community Standards (ICS) 500-27.

Requirements

  • 6+ years of related experience.
  • Active TS/SCI Clearance.
  • DoD 8570.01-M IAT Level II and CSSP Infrastructure Support certifications.
  • SIEM experience with one of the following: ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA).
  • Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules.
  • Create SIEM playbooks.
  • Linux (RHEL) Expert (administration and engineering).
  • Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives.
  • Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events.
  • Creation of ArcSight rules based on use cases of malicious events.
  • Tuning and aggregation of queries and filters.
  • Skilled in troubleshooting event flow through Enterprise Audit infrastructure.
  • Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools.

Nice To Haves

  • Kibana
  • Data Analytics

Responsibilities

  • Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability.
  • Maintain system availability and reliability with a threshold of 99.99%.
  • Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation.
  • Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes.
  • Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution.
  • Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions.
  • Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.
  • Retain documentation regarding loss of event logs.
  • Configure all assets assigned to this service within the Government Furnished Information - Software Tools list.
  • Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets.
  • Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions.
  • Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed.

Benefits

  • Medical plan options, some with Health Savings Accounts.
  • Dental plan options.
  • Vision plan.
  • 401(k) plan with company match.
  • Full flex work weeks where possible.
  • Paid time off plans including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • Short and long-term disability benefits.
  • Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Industry

Professional, Scientific, and Technical Services

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service