Quick Overview
Job Description
Hi,
Please let me know your interest in the below position
Role: SOC Analyst
Location: Washington, DC
Duration: 12 months
Pay rate: $75/hr on C2C
Job ID: OCTO Tier 3 SOC Analyst - 812392
Client: OCTO, DC govt
100% Onsite role and only locals to DC/VA/MD
In person interview
11 years of experience required
Description:
Monitoring, detecting, analyzing, remediating, and reporting on Cyber events and incidents impacting the tech infrastructure of the District of Columbia. Serves as advanced escalation point.
The SOC Analyst - Tier 3 is cybersecurity technical resource responsible for providing technical analytical oversight a team of SOC Analysts to monitor, detect, analyze, remediate, and report on cybersecurity events and incidents impacting the technology infrastructure of the Government of the District of Columbia. The ideal candidate will have an advanced technical background with significant experience in an enterprise successfully leading a SOC team or unit responsible for analysis and correlation of cybersecurity event, log, and alert data. The candidate will be skilled in understanding, recognition, and root-cause detection of cybersecurity exploits, vulnerabilities, and intrusions in host and network-based systems.
Responsibilities
- Utilize advanced technical background and experience in information technology and incident response handling to scrutinize and provide corrective analysis to escalated cybersecurity events from Tier 2 analysts—distinguishing these events from benign activities, and escalating confirmed incidents to the Incident Response Lead.
- Provide in-depth cybersecurity analysis, and trending/correlation of large data-sets such as logs, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cybersecurity incidents, and make sound technical recommendations that enable expeditious remediation.
- Proactively search through log, network, and system data to find and identify undetected threats.
- Support security tool/application tuning engagements with analysts and engineers to develop/adjust rules and analyze/develop related response procedures, and reduce false-positives from alerting.
- Identify, verify, and ingest indicators of compromise and attack (IOC’s, IOA’s) (e.g., malicious IPs/URLs, etc.) into network security tools/applications to protect the Government of the District of Columbia network.
- Quality-proof technical advisories and assessments prior to release from SOC.
- Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
- Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements to improve the effectiveness and efficiency of alert notification and incident handling.
- Formulate and coordinate technical best-practice SOPs and Runbooks for SOC Analysts.
- Respond to inbound requests via phone and other electronic means for technical assistance, and resolve problems independently. Coordinate escalations with Incident Response Lead and collaborate with internal technology teams to ensure timely resolution of issues.
Minimum Qualifications
- 5 years of experience as a cybersecurity analyst/engineer in a security operations center, or equivalent knowledge.
- 5 years of experience with cybersecurity attack countermeasures for adversarial activities such as malicious code, DDOS, and phishing.
- 5 years of experience with Analyzing And Responding To Security Events And Incidents With Security Information And Event Management System (SIEM)
- 5 years of experience with cybersecurity attack methodology to include tactics and techniques, and associated countermeasures.
- 5 years of experience with TCP/IP Protocols, Services, Networking, And Experience Identifying, Analyzing, Containing, And Eradicating Cybersecurity Threat
- 11-15 yrs implementing, administering, and operating IS tech such as firewalls, IDS/IPS, SIEM, Antivirus, net traffic analyzers, and malware analysis
- 11-15 yrs years utilizing advanced experience with scripting and tool automation such as Perl, PowerShell, Regex
- 11-15 yrs developing, leading and executing information security incident response plans
- 11-15 yrs years developing standard and complex IT solutions & services, driven by business requirements and industry standards
--Regards
Kanchan Illa
CSZNet, Inc.
Direct:
Email:
Similar jobs
- CD
Sr. Staff Network Security Engineer with Palo Alto Networks PAN OS firewalls and Prisma Access experience
NewCloud Destinations LLC
Dublin, CA🇺🇸Hybrid23 hours agoAnsiblePrismaPython+2Technology - BL
Cyber Range Engineer with Security Clearance
By Light
Annapolis Junction, MD🇺🇸$135k/yrOn-site3 days agoTCP/IPDNSVMwareTechnology - IA
Information Systems Security Officer (ISSO) (Senior) with Security Clearance
NewIPT Associates (IPTA)
Huntsville, AL🇺🇸Hybrid23 hours agoTechnology - IU
Security Engineer
IBOTIX US Inc.
Sunnyvale, CA🇺🇸On-site3 days agoMicroservicesBashLLM+2Technology - WS
Information Security Analyst - Monitoring & Reporting with Security Clearance
NewWoodside Staffing Solutions & Consulting
Tyndall AFB, FL🇺🇸On-site23 hours agoTechnology - KA
Security Automation SOAR Engineer
NewKaltechsoft
United States🇺🇸Hybrid23 hours agoAdministrative