Shift Lead - Senior Security Analyst

Fusion Technology LLC
Chantilly, VA, US
Full-time
Quick Apply

Shift Lead (Senior Security Analyst) Who is Fusion Technology? Fusion Technology is a performance-driven HUBZone Small Business concern residing in the heart of the beautiful mountainsides of West Virginia, steps away from the Federal Bureau of Investigation's Criminal Justice Information Services Division's Headquarters.

Founded in 2007 by an Engineer-by-trade, Fusion Technology dedicates our valuable resources to providing comprehensive IT services and solutions to mission-critical US Government programs and the Intel Community.

Who are you? Trusted Employee : You must possess an active Secret security clearance. You must also be able to obtain TSA suitability .

Education requirements : High school diploma Field Certified : One or more vendor specific certifications (CYSA+, CEH, or equivalent) What you’ll do : Functional Description The Sr Security Analyst will monitor and analyze security events and alerts reported by the TSA SIEM on a 24x7 basis to identify and investigate suspicious or malicious activity, or other cyber events which violate TSA policy.

The analyst will be responsible for analyzing logs and events from any other device types which may send logs or events to the TSA SOC in the future.

Non-traditional device feeds will deliver data to the SIEM architecture (e.g., Human Resources (HR) data, badging information, and physical security devices, etc.

The analyst will provide documentation detailing any additional information collected and maintained for each security investigation.

The analyst will record all artifacts (i.e. emails, logs, documents, Uniform Resource Locators (URLs), screenshots, etc.

associated with all security events and incident investigations within the TSA SOC incident and tracking application. Required Skills At least five years of experience working in a Security Operations Center (SOC) or Network Operations Center (NOC) environment performing security event monitoring and analysis.

Working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks.

Must possess a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.

g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.) Must be capable of analyzing security logs and events from the following types of devices such as, but not limited to : Firewalls (FWs), Intrusion Detection Sensors / Intrusion Prevention Sensors (IDS / IPS), Host-based Intrusion Detection System / Host-based Intrusion Prevention System (HIDS / HIPS), proxy / web filter, vulnerability scans, routers, router Internet Protocol (IP) accounting systems (i.

e., Cisco NetFlow), Virtual Private Network (VPN) gateways / concentrators, server event logs, e-mail and host anti-virus, desktop security monitoring agents, anti-virus servers, IP services (i.

e. Domain Name System (DNS) Services, Dynamic Host Configuration Protocol (DHCP), network address translation devices, MDM (e.

g. cellphones), Public Key Infrastructure (PKI), and cloud security infrastructure (e.g. Amazon Web Services (AWS), Azure, Oracle, Salesforce, etc.

Advanced knowledge of common adversarial tactics, techniques, and procedures (TTPs) Preferred Skills Ability and prior experience with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents.

This includes the identification of malicious code present within a computer system as well identification of malicious activities that are present within a computer system and / or enterprise network.

Experience with Splunk query language. Experience with IDS / IPS / firewall / security configurations and signature development.

Experience with PCAP analysis. Experience with Tanium threat response. Experience working with a ticket management system to collect, document and maintain information pertinent to security investigations and incidents.

Excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings.

Experience in monitoring the operational status of monitoring components and escalating and reporting outages of the components.

Conceptual understanding of Windows Active Directory is also desired. Experience working with various event logging systems and must be proficient in the review of security event log analysis.

Previous experience with SIEM platforms that perform log collection, analysis, correlation, and alerting is also preferred.

Experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment Experience in collecting and maintaining information pertinent to security;

investigations and incidents in a format that supports analysis, situational awareness reporting, and law enforcement investigation efforts.

What matters to you matters to us. Fusion Technology values its employees and works hard to ensure proper care for them and their families.

We desire to compensate employees in a competitive, motivational, fair, and equitable way with other employers in the marketplace.

Salary is only one component of employee compensation but an integral part of recruiting and retaining qualified employees.

However, at Fusion Technology, we take a comprehensive approach and consider each employee's needs to tailor a compensation plan that provides financial security and peace of mind.

Our competitive package includes a best-in-class matching 401K program, comprehensive Cigna healthcare plan, a competitive employer contribution to a health savings account, vision and dental plans, life insurance, short- and long-term disability, and personal leave, in addition to paid certifications and training.

Fusion Technology LLC is an Equal Opportunity Employer. We respect and seek to empower each individual and support the diverse cultures, perspectives, skills, and experiences within our workforce.

Qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Powered by JazzHR

30+ days ago
Related jobs
Promoted
MITRE
McLean, Virginia

The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. The SME will serve as a team lead for the software engineering team that encompasses early career engineers. Providing task managem...

Promoted
Axiologic Solutions
North Springfield, Virginia

Overall Assignment Description:.FM Business Solutions Office (FMZ):.Developing and implementing solutions to.Active TS/SCI clearance, CI poly preferred.Minimum eight (12) years of experience and six (8) years of relevant experience.Server, Microsoft Access, and Microsoft Excel.Momentum-based financi...

Promoted
Peraton
Sterling, Virginia

Peraton is seeking a Senior SOC Analyst/Threat Detection Engineer ("Senior SOC Analyst") to join our team of qualified, diverse individuals. The Senior SOC Analyst will be part of the Department of State (DOS) Consular Affairs Enterprise Infrastructure Operations (CAEIO) Program for the Bureau of Co...

Promoted
LMI
Tysons, Virginia

LMI is seeking a seasoned Data Scientist to support the development, testing, and deployment of machine learning (ML) models.These models are crucial for encapsulating extensive discrete event simulation data, aiding a critical supply chain risk program for the Department of Defense.At LMI, we’re re...

Fusion Technology LLC
Chantilly, Virginia

Shift Lead (Senior Security Analyst)   Who is Fusion Technology?   Fusion Technology is a performance-driven HUBZone Small Business concern residing in the heart of the beautiful mountainsides of West Virginia, steps away from the Federal Bureau of Investigation's Criminal Justice Informat...

Promoted
Blue-Halo.org
McLean, Virginia

Evaluate, test, recommend, coordinate, monitor and maintain cybersecurity policies, procedures and systems, including access management for hardware, firmware and softwareEnsure that cybersecurity plans, controls, processes, standards, policies and procedures are aligned with cybersecurity standards...

Northrop Grumman
Fairfax, Virginia

The selected candidate will require experience in program security, with knowledge of implementing a multi-disciplined security program (access control, personnel security, physical security, OPSEC etc. Senior Principal Industrial Security Analyst. Working collaboratively in a team environment with ...

JPMorgan Chase & Co.
McLean, Virginia

As a Senior Lead Cybersecurity Architect at JPMorgan Chase within the Cybersecurity and Technology Controls organization, you are an integral part of a team that works to develop high-quality cybersecurity solutions for various software applications and platform products. We are looking for a cloud ...

McIntire Solutions
Springfield, Virginia

McIntire Solutions is seeking a Cyber Security Analyst to support our Springfield Customer. Hours: 24x7 Shift Work (Panama Shift Schedule; hours dependent on location). IAT Level II (GSEC, Security+, SSCP, or CCNA-Security) certification required. Performs security event and incident correlation usi...

Erickson senior Living
Fairfax, Virginia

We’re part of a growing network of communities developed and managed by Erickson Senior Living, a national provider of senior living and health care with campuses in 11 states—and growing. Woodleigh Chase by Erickson Senior Living. The Gatehouse Officer staffs the Gatehouse entrance to the community...