Jr. Information Assurance/Security Specialist
This is for shift work 12 hour shifts 4 days on 4 days off.
- Use SIEM technologies and other native tools to perform the monitoring of security events on a 24x7 basis. Perform analysis on logs produced by network devices utilized within the OCC such as firewalls, content filtering, syslog from various sources/devices, assorted Intrusion Detection capabilities, substantiating vulnerability scanner results, directory services, DHCP logs, Secure Email Gateway logs, and approved OCC applications.Use the Intel McAfee SIEM to monitor the network and perform analysis, while integrating the results and information needed to proactively protect the OCC enterprise. This includes developing customized signatures, enterprise content filtering, or firewall ACL change recommendations.Provide security events analysis and support to include identifying potential threat, anomalies, and infections, documenting findings, providing recommendations within the OCC’s incident management system, performing triage of incoming security events, performing preliminary and secondary analysis of those events, and validating the eventsPerform technical analyses, such as analysis of malicious code, network traffic, web log data, cyber intelligence, hard drives, and other storage and forensics media, to control exploitative activity.Manage inbound requests via the OCC ticketing system (Service Now), as well as via telephone calls, and provide security notifications via three methods: logging incident tickets, sending emails, and placing telephone calls