Cybersecurity Analyst
Company | AnaVation LLC |
---|---|
Location | Clarksburg, WV, USA, Washington, DC, USA |
Salary | $Not Provided – $Not Provided |
Type | Full-Time |
Degrees | Bachelor’s |
Experience Level | Senior |
Requirements
- Bachelor’s Degree in related field or equivalent combination of relevant experience and education (degree strongly preferred)
- 8 years (minimum)
- Must have experience with Splunk Enterprise Security
- Experience actively detecting, monitoring, preventing, and analyzing real-time cybersecurity information, events, and threats in a federal government environment
- Must have expertise in using security information and event management (SIEM) tools, including configuration, tuning, and optimization for real-time monitoring and incident response.
- This position requires an active Top Secret clearance and the ability to successfully pass a polygraph and obtain SCI accesses.
Responsibilities
- Detection and resolution of potential security incidents
- Monitor, fuse, correlate, analyze, and respond to threat and security event data for enterprise systems
- Conduct continuous monitoring of security alerts and events from various sources, such as security tools, logs, and sensors; analyze the data to identify potential security incidents or anomalies.
- Utilize security information and event management (SIEM) systems to correlate data and detect patterns indicative of malicious activity.
- Coordinate and collaborate with incident response teams to contain, eradicate, and recover from security breaches.
- Leverage threat intelligence to proactively defend against potential attacks.
- Maintain SIEM software across multiple environments; ensure deployed SIEM platforms are in compliance with federal requirements.
- Demonstrate thorough knowledge of compliance requirements and regulations relevant to cybersecurity, ensuring adherence to industry standards.
- Generate and disseminate reports on security incidents, including their nature, scope, and impact.
- Mentor junior staff and ensure quality of technical support and contractual deliverables.
Preferred Qualifications
- Experience with Microsoft Sentinel
- Watch desk experience a strong plus
- GIAC Continuous Monitoring Certification (GMON)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Network Forensic Analyst (GNFA)
- GIAC Cloud Threat Detection (GCTD)
- GIAC Cloud Forensics Responder (GCFR)