Talent.com
GDIT
Cyber Security Operations Specialist -SIEM ServicesGDIT • Louis, St., MO, USA
Cyber Security Operations Specialist -SIEM Services

Cyber Security Operations Specialist -SIEM Services

GDIT • Louis, St., MO, USA
30+ days ago
Salary
$60,549.00–$101,109.00 yearly
Job type
  • Full-time
Job description

Job Description:

  • Job Duties Include:

    Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software Maintain system availability and reliability with a threshold of 99.99% Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service. Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost) Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, polices, guidance, procedures etc. Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN – Joint Incident Management System, DoD CIO – DoD Scorecard/Get to Green reporting, IC CIO – Cybersecurity Performance Evaluation Model reporting, etc.) Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services

    Required Skills: SIEM experience with one of the following ArcSight, Elasticsearch, Splunk, Event Broker, User Behavioral Analysis (UBA) Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules Create SIEM playbooks Linux (RHEL) Expert (administration and engineering) Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events Creation of ArcSight rules based on use cases of malicious events Tuning and aggregation of queries and filters Skilled in troubleshooting event flow through Enterprise Audit infrastructure Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools Active TS/SCI Clearance DoD 8570.01-M IAT Level II and CSSP Infrastructure Support certifications 3+ years' Experience with SIEM and Development Projects 3+ years' Experience with SIEM support for projects and technical exchange meetings 6+ years' Experience developing and maintaining enterprise audit projects.

    Desired Skills: Kibana Data AnalyticsInvestigates, analyzes, and responds to cyber incidents within a network environment or enclave.

    Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats.

    Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events.

    Evaluates, tests, recommends, coordinates, monitors, and maintains cybersecurity policies, procedures, and systems, including access management for hardware, firmware, and software.

    Ensures that cybersecurity plans, controls, processes, standards, policies, and procedures are aligned with cybersecurity standards.

    Identifies security risks and exposures, determines the causes of security violations and suggests procedures to halt future incidents and improve security

    Develops techniques and procedures for conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of hardware, firmware and software for possible impact on system security, and the investigation and resolution of security incidents such as intrusion, frauds, attacks or leaks

    May coach and provide guidance to less experienced professionals.

    May serve as a team or task lead.

    EDUCATION AND EXPERIENCE: Technical Training, Certification(s) or Degree, 5+ years of experience

The likely salary range for this position is $60,549 - $101,109. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Onsite

Work Location:

USA VA Springfield

Create a job alert for this search

Cyber Security Operations Specialist -SIEM Services • Louis, St., MO, USA

Similar jobs

Specialist, Product Security Compliance

Hubbell IncorporatedSt. Louis, Missouri, United States
Full-time

As a Product Security Compliance Specialist, you will support Hubbell's product security operations, focusing on SOC 2 compliance for SaaS products while also supporting other relevant product secu... Show more

 • Promoted

Cybersecurity Engineering Specialist III

RISASt. Louis, MO, USA
Full-time
Quick Apply

Cybersecurity Engineering Specialist III - CDAS.Minimum Clearance Required to Start.Responsible for building and automating efficient and resilient infrastructure that our business depends on.In th... Show more

Shift Lead

Pizza HutJerseyville, IL, United States
Full-time

Every pizza needs a bit of pizzazz.Serve up great food and great moments for our guests and team as a Shift Leader for Pizza Hut.In this role, you'll be responsible for managing restaurant operatio... Show more

 • Promoted

Operations Specialist

AeroCare AdaptHealth WisconsinFestus, MO, United States
Full-time

Operations Specialist New Berlin, WI Description Position Summary:The Operations Specialist is responsible for supporting the Operations Team through multiple tasks required for the successful supp... Show more

 • Promoted

Clinical Supervisor RN Weekend - full time, nights - Mercy Jefferson

MercyFestus, Missouri, United States
Full-time

Assists in the planning, coordination, implementation and evaluation of the operations and patient care of designated areas.Serves as a clinical resource for staff and patients in the department.Fu... Show more

 • Promoted

Ops Support Specialist - C04 - OFALLON

CitigroupSaint Charles, MO, United States
Full-time

The Ops Support Specialist 4 is an entry-level position responsible for providing operations support services, including but not limited to record/documentation maintenance, storage & retrieval of ... Show more

 • Promoted

Compliance Investigation Specialist I

Kindeva Drug DeliverySaint Louis, MO, United States
Full-time

At Kindeva we make products that save lives, ensuring better health and well-being for patients around the world.The incumbent will provide guidance, coaching and coordination for all aspects relat... Show more

 • Promoted

Server - Arnold Chili's

Chilli'sArnold, MO, United States
Full-time +1

Server Arnold, MO 63010 Job #0042VA ← Back to search results Role Overview Our Servers don't just provide our Guests with amazing food and drinks.They deliver hospitality and service that is ab... Show more

 • Promoted

Technical Analyst, Operations

NISA Investment Advisors, LLCClayton, Missouri, United States
Full-time

NISA Investment Advisors, LLC (NISA) offers customized investment solutions for tax-exempt and taxable institutional clients.NISA manages over $295 billion in fixed income and equity securities and... Show more

 • Promoted

Industrial Security Specialist

Scale AI, Inc.St. Louis, Missouri, United States
Full-time

Scale is at the forefront of powering artificial intelligence.We believe that trust in AI is earned with high-quality data for training, fine-tuning, and evaluating AI systems.Our products are tran... Show more

 • Promoted

Security Specialist III

ServiceSource, Inc.Arnold, Missouri, United States
Full-time

Make an impact by joining ServiceSource, a champion for people with disabilities.Explore new opportunities! ServiceSource is an organization of talented people who drive innovation, embrace change,... Show more

 • Promoted

Sr. Network Security Project Manager

Match Point SolutionsMaryland Heights, MO, United States
Full-time
Quick Apply

MatchPoint Solutions is a fast-growing, young, energetic global <b>IT-Engineering services company with clients across the US</b>.We provide technology solutions to various clients like... Show more

Hiring Now - Work from Home - No Experience

OCPAAlton, Illinois, us
$15.00 hourly
Remote
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Service to the Armed Forces Specialist - Scott AFB

American National Red CrossLiguori, MO, United States
Full-time

Please use Google Chrome or Mozilla Firefox when accessing Candidate Home.By joining the American Red Cross  you will touch millions of lives every year and experience the greatness of the human sp... Show more

 • Promoted

Operations Support Compliance Auditor

Monro, Inc.Saint Louis, MO, United States
Full-time

Operations Support Compliance Auditor.Reporting to the Director of Operations Support, this individual will evaluate, inspect, audit, and determine the effectiveness of compliance and store operati... Show more

 • Promoted

Information Technology Professional

US NavyCrystal City, MO, US
Full-time

Information Technology Professional (IT/CTN/IS).Information Systems Technicians, Cryptologic Technician Networks, and Intelligence Specialists keep the Fleet connected, informed, and secure by oper... Show more

 • Promoted

Software Engineer, Infrastructure & Security

Scale AI, Inc.St. Louis, MO, US
Full-time

Scale AI is seeking a highly skilled and motivated.Software Engineer, AI Infrastructure & Security.Public Sector Engineering team.As a part of this team, you will play a critical role in delivering... Show more

 • Promoted

Sr Mgr, Information Security

Core & MainSt. Louis, Missouri, United States
Full-time

Louis, Core & Main is a leader in advancing reliable infrastructure with local service, nationwide.As a specialty distributor with a focus on water, wastewater, storm drainage and fire protection p... Show more

 • Promoted

Service Technician I

Securitas TechnologySt. Louis, MO, United States
Full-time

Securitas Technology, part of Securitas, is a world-leading provider of integrated security solutions that protect, connect, and optimize businesses of all types and sizes.More than 13,000 colleagu... Show more

 • Promoted

Operations Specialist

Focus Financial PartnersSaint Louis, MO, United States
Full-time

As an Operations Specialist, you will have the opportunity to work as part of a collaborative team responsible for supporting our network of advisors in all things related to servicing client accou... Show more