Search jobs > St Louis, MO > Cyber security specialist

Cyber Security Operations Specialist -SIEM Services

GDIT
Louis, St., MO, USA
$60.5K-$101.1K a year
Full-time

Job Description : Job Duties Include :

Job Duties Include :

Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment / software, installation and testing of new equipment / software, and configuration of new equipment / software Maintain system availability and reliability with a threshold of 99.

99% Detect and ticket degradations (volume / velocity) of all SIEM data flows within 60 minutes of the start of the degradation Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes.

This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.

Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost) Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, polices, guidance, procedures etc.

Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list.

This includes ensuing all data flows are properly parsed for ingestion / transmission to internal and external automated reporting systems (e.

g. JFHQ DoDIN Joint Incident Management System, DoD CIO DoD Scorecard / Get to Green reporting, IC CIO Cybersecurity Performance Evaluation Model reporting, etc.

Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services

Required Skills : SIEM experience with one of the following ArcSight, Elasticsearch, Splunk, Event Broker, User Behavioral Analysis (UBA) Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules Create SIEM playbooks Linux (RHEL) Expert (administration and engineering) Proficient in manipulating SIEM filters to better find and analyze potential malicious / atypical activity and reduce false positives Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events Creation of ArcSight rules based on use cases of malicious events Tuning and aggregation of queries and filters Skilled in troubleshooting event flow through Enterprise Audit infrastructure Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools Active TS / SCI Clearance DoD 8570.

01-M IAT Level II and CSSP Infrastructure Support certifications 3+ years' Experience with SIEM and Development Projects 3+ years' Experience with SIEM support for projects and technical exchange meetings 6+ years' Experience developing and maintaining enterprise audit projects.

Desired Skills : Kibana Data Analytics

Investigates, analyzes, and responds to cyber incidents within a network environment or enclave.

Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats.

Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events.

Evaluates, tests, recommends, coordinates, monitors, and maintains cybersecurity policies, procedures, and systems, including access management for hardware, firmware, and software.

Ensures that cybersecurity plans, controls, processes, standards, policies, and procedures are aligned with cybersecurity standards.

Identifies security risks and exposures, determines the causes of security violations and suggests procedures to halt future incidents and improve security

Develops techniques and procedures for conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of hardware, firmware and software for possible impact on system security, and the investigation and resolution of security incidents such as intrusion, frauds, attacks or leaks

May coach and provide guidance to less experienced professionals.

May serve as a team or task lead.

EDUCATION AND EXPERIENCE : Technical Training, Certification(s) or Degree, 5+ years of experience

The likely salary range for this position is $60,549 - $101,109. This is not, however, a guarantee of compensation or salary.

Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours :

Travel Required : None

None

T elecommuting Options :

Onsite

Work Location : USA VA Springfield

USA VA Springfield

30+ days ago
Related jobs
GDIT
St. Louis, Missouri

SIEM experience with one of the following ArcSight, Elasticsearch, Splunk, Event Broker, User Behavioral Analysis (UBA) Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules Create SIEM playbooks Linux (RHEL) Expert (administration and engineering) Proficien...

RISA
St. Louis, Missouri

RISA has an exciting and challenging opportunity available for a Cybersecurity Operations Lead supporting an Intelligence Community customer's wide-area (WAN), local-area (LAN), and campus-area (CAN) networks across multiple security domains. The Security Operations Center (SOC) Shift Lead will repo...

GDIT
St. Louis, Missouri

Provide subject matter experts capable of conducting a deep analysis of raw data from assets supporting Network Security Services, Endpoint Security Services, and Cybersecurity Data Analysis Services. Cyber Security Operations 3 - Hunt Services. Assign the Cybersecurity Operations Manager to direct ...

CACI
St. Louis, Missouri

CACI's Transport & Cybersecurity Services (TCS) program is actively hiring TS/SCI cleared Cyber Security Operations Specialists to join our CSOC Tiered Services team! We are seeking mission-focused individuals to provide various levels of CSOC services (Tier 1, Tier 2, and Tier 3). Our team of t...

CACI International Inc
St. Louis, Missouri

CACI's Transport & Cybersecurity Services (TCS) program is actively hiring TS/SCI cleared Cyber Security Operations Specialists to join our CSOC Tiered Services team! We are seeking mission-focused individuals to provide various levels of CSOC services (Tier 1, Tier 2, and Tier 3). Our team of talen...

RISA
St. Louis, Missouri

Cyber Security Engineering Specialist III / Network Security Services. RISA has an exciting and challenging opportunity available for a Network Security Engineer supporting an Intelligence Community customer's wide-area (WAN), local-area (LAN), and campus-area (CAN) networks across multiple security...

Hubell
St. Louis, Missouri

Hubbell Utility Solutions is seeking a Cybersecurity Specialist with expertise in protection of SaaS and software solutions. Aclara’s distribution operations, sensor and analytics, and AMI solutions help electric, water, and gas utilities provide safe, reliable, and efficient operations of their dis...

General Services Administration
Saint Ann, Missouri

As a Transportation Operations Specialist, you will serve in the Program Support Center and work under the general guidance of Zonal Operations and the supervision of the Program Support Supervisor. Transportation Operations Specialist (Motor)**. General Services Administration**. Provides administr...

Edward Jones
St. Louis, Missouri

Knowledge of security dispatch operations, physical security systems, and the security field operations is required. The Senior Security Control Specialist is responsible for the operation of a 24-hour Global Physical Security Control Center. Collect and triage security-relevant information for diss...

Edward Jones
St. Louis, Missouri

Knowledge of security dispatch operations, physical security systems, and the security field operations is required. The Senior Security Control Specialist is responsible for the operation of a 24-hour Global Physical Security Control Center. Collect and triage security-relevant information for diss...