Skip to main content

This job has expired

Senior Cyber Incident Response Analyst

Employer
Apex Systems, Inc.
Location
Vienna, VA
Closing date
Dec 9, 2021

View more

Sr. Cyber Security Analyst Location: Remote OR Herndon, VA Clearance: Can hold up to a Top Secret Responsibilities The Senior Cyber Security Analyst will be part of the Cyber Security Operations Center (CSOC) within the CISO organization reporting to the CSOC manager. The CSOC is the primary organization for any suspected security incident and works together with the other teams within Peraton to resolve incidents and remediate threats. The CSOC Support the continuous investigation and correlation of security event feeds and applies appropriate triage and escalation to identified security incidents. The position is responsible for maintaining Security/SOC tools and assisting with cyber incidents. This will involve the use of troubleshooting tools, writing scripts or queries to aid in quick analysis to define and apply an appropriate response. The job involves operating and tuning security tools. Responsibilities: Monitor corporate and DevOps environments for security threats. Investigate security breaches and other cyber security incidents, including account compromise, social engineering & malware events. Respond to detected threats using appropriate scripts, policies and other actions as necessary. Provide accurate and timely information regarding detected threats to the designated customer point of contact. Analyze servers, workstations and other devices suspected to be compromised and accurately assess the scope and type of issue. Perform root cause analysis for cybersecurity incidents to support recommendations made to further improve security posture. Participate in security audits, risk analysis, and security reviews. Assist in the collection and analysis of investigative artifacts to support audits and assessments Proactively identify security issues and risks and develop remediation and mitigation plans Work with a diverse team of analyst and engineers to work through complex issues and tasks in a fast-paced environment Qualifications Experience: Requires 12 to 15 years with BS/BA or 10 to 13 years with MS/MA or 7 to 9 years with Ph.D. or equivalent experience CISSP or other 8570-compliant certification(s) Experience with NIST and FedRAMP Vendor engagement experience Experience with CI/CD pipelines and containerization Ability to implement and monitor IT network protection measures to ensure systems and personnel adhere to corporate cybersecurity standards Technical background focused on defensive cyber operations, including but not limited to, ensuring Windows and Linux Host Based Security System (HBSS) compliance; identifying and remediating cybersecurity incidents using Security Information and Event Manager (SIEM) and other Security Operations Center (SOC) tools Experience with modern security technologies (virtualization, remote services, IAM/PAM, APIs, software-defined networks and firewalls, automated response) Ability to provide engineering support to include install and configuration, performance tuning, and troubleshooting Strong understanding of adversary tactics, techniques, and procedures focused on threats to information networks Working knowledge of technical and nontechnical risk response lifecycles, user and asset-level controls, and maturity model concepts Experience working in complex IT environments with multiple security enclaves Ability to contribute to design reviews of hardware and software components, develop business cases and solution roadmaps aligned with current security investments Applied experience with one or more of the following: PowerShell, Python, Javascript, SQL database design/development Experience leading tasks or projects with the ability to work individually or part of integrated teams Ideal candidates would have experience with three or more of the following: CarbonBlack (AppControl and/or EDR) Proofpoint or other SEG Qradar or other SIEM Zscaler Okta or other IAM solution Sophos or other antimalware platform O365 and Azure Security Center Palo Alto Enterprise Firewalls EEO EmployerApex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at employeeservices@ or 844-463-6178.VEVRAA Federal ContractorWe request Priority Protected Veteran & Disabled Referrals for all of our locations within the state.We are an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic. The EEO is the Law poster is available here.PDN-94d8bd87-d434-42b2-898b-9c695232c2ce

Get job alerts

Create a job alert and receive personalized job recommendations straight to your inbox.

Create alert