Advance your career while impacting our national security in cyber as a Cybersecurity Analyst Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. MEANINGFUL WORK AND PERSONAL IMPACT As a Cybersecurity Analyst Principal, the work you'll do at GDIT will be impactful to the mission of the US Department of Education's Portfolio of Integrated Value-Oriented Technologies (PIVOT). You will play a crucial role via the following responsibilities: Oversee the daily operations of the SOC and plans shift activities Works closely with Incident Management Team Must be willing to lead major incident management process, supports Agency leadership during the activation of major/escalated incidents Develop, author, and deliver process improvements for the SOC in order to maintain operational readiness for incident response Monitor and report on call volumes, alarm responses, and incident reports to ensure appropriate levels of service are met Partner with IT leadership and teams to support operational issues and prepare for potential incidents Support annual updates of the incident response concept of operations document Support annual incident response tabletop exercises Lead, mentor, and coach SOC I and SOC II staff members Work as part of a 24x7x365 team delivering real time proactive monitoring and maintenance of supported security tools and associated rules and signatures Carry out triage on security events, coordinate incidents with Incident Management Team, IT operations, network engineering, and application teams and support the Incident Management process Identify and respond to incidents, to prevent or limit damage to assets, and report incidents Detect and analyze incidents, coordinate activities with other stakeholders for containing, eradicating, and recovering from incidents Development of advanced analytics and countermeasures to protect critical assets IDS monitoring and analysis, network traffic and log analysis, prioritization and differentiation between potential intrusion attempts, determination of false alarms, insider threat and APT detection, and malware analysis/forensics Supports the production and maintenance standard operational processes and procedures and playbooks for use by all shift personnel Provide enterprise-wide management of security incidents, managed network space, to detect, respond, and report all computer related incidents that includes daily monitoring of information systems, vulnerability remediation, intrusion detection, log reviews, and malware tracking Assess, identify, and remediate of the individuals and/or systems affected Coordinate all information security incidents complied with timeline specifics Coordinate the development of reports from the SIEM, NIDS, and HIDS Remain up to date with current attack methods and characteristics in order to identify threats and advise on prevention, mitigation and remediation Perform other tasks consistent with the goals and objectives of the department/contract Perform other duties as assigned by Senior Program Executive Responsible to fully document assigned tickets to show all work performed in order to pass SLRs Responsible to manage team to fully document assigned tickets to show all work performed in order to pass SLRs
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Industry
Professional, Scientific, and Technical Services
Education Level
No Education Listed
Number of Employees
5,001-10,000 employees