Source description
About the role
Position Description:
The Junior Security Operations Center Analyst position will be a member of a dedicated security team within IBM Consulting Federal. In this role, the Jr. SOC analyst will support a dedicated 24x7x365 operation for a Federal program. The Jr. SOC Analyst will be responsible for monitoring alerts for potential threats and security anomalies, analyzing content of those alerts and providing a written analysis for each. The analyst will work closely with Tier 2 SOC analysts who will serve as their escalation point.
Specific job duties include:
Perform 24x7x365 Security Monitoring, Analysis and Response
Support incident investigations, response, and reporting
Security Reporting
Vulnerability Analysis
SOC ticket queue management
Document actions taken and analysis in the authorized ticketing system to a level of detail where the actions taken and analysis are capable of being systematically reconstructed.
Required skills/Level of Experience:
Bachelor's Degree + minimum 3 years of work experience with 3 years working in a 24x7x365 SOC environment.
Analyzing system and network logs for security events, anomalies, and configuration issues.
Experience working with SIEM technology to monitor and manage security events.
Background in incident response, system/network operations and threat intelligence.
Experience utilizing enterprise security technologies such as SIEM/SOAR, NGAV/EDR,
Vulnerability Scanners, and Threat Intelligence Platforms.
Hands-on troubleshooting, analysis, and technical expertise to resolve incidents and/or service requests.
Understanding of possible attack activities such as network reconnaissance probing, DDOS, malicious code activity, etc.
Experience SOC operations including but not limited to: Alert and notification activities- analysis / triage / response, Review and action on Threat Intel for IOCs and other operationally impactful information, initial review and triage of reported Incidents
Demonstrated ability to evaluate events (through a triage process) and identify appropriate prioritization for response
Demonstrated experience and understanding of event timeline analysis and correlation of events between log sources
Demonstrated experience of the underlying logs generated by operating systems (Linux/Windows), Network Security Devices, and other enterprise tools
Demonstrated proficiencies with an enterprise SIEM or security analytics solution including the Elastic Stack or Splunk.
Solid understanding and experience analyzing security events generated from security tools and devices not limited to: Crowdstrike and Palo Alto
Experience and solid understanding of Malware analysis
Understanding of security incident response processes
CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+ **, GCIA, GCIH, GICSP,
Cloud+, SCYBER, PenTest+ (Any certs)
Understanding and experience with Federal Security Standards such as NIST and DoD
Understanding and experience with FedRAMP Cloud Security Requirements
Security clearance: Able to obtain Public Trust Clearance.
More at 3B Staffing