Veteran Firm Seeking a Senior Security Operations Center (SOC) Analyst - Tier 3 for an Onsite Assignment in Washington, DC
My name is Stephen Hrutka, and I lead a Veteran-owned consulting firm in Washington, DC, focused on strategic sourcing, supply chain, and IT Staffing.
We want to fill a Senior Security Operations Center (SOC) Analyst - Tier 3 role for the Office of the Chief Technology Officer (OCTO) in the DC Government.
The ideal candidate is a DMV resident with 11+ years of IT and cybersecurity experience, 5+ years of hands-on operational experience handling SOC incidents, and in-depth expertise with SIEM technologies and threat countermeasures. A Bachelor's degree and relevant SANS certifications (GCIA, GCED, GPEN, GCIH) are highly desired.
If you’re interested, I'll gladly provide more details about the role and further discuss your qualifications.
Thanks,
Stephen M Hrutka
Principal Consultant
Executive Summary: HRUCKUS is looking for an experienced Senior Security Operations Center (SOC) Analyst - Tier 3 to monitor, detect, analyze, remediate, and report on cybersecurity events and incidents impacting the technology infrastructure of the Government of the District of Columbia.
Position Description: The SOC Analyst - Tier 3 is a cybersecurity technical resource responsible for providing technical analytical oversight to a team of SOC Analysts. The candidate will utilize an advanced technical background to scrutinize escalated events, conduct in-depth analysis of log and event data, tune security tools, ingest indicators of compromise, and serve as an advanced escalation point to identify root-causes of cybersecurity exploits, vulnerabilities, and intrusions.
Position Responsibilities:
- Utilize advanced technical background and experience in information technology and incident response handling to scrutinize and provide corrective analysis to escalated cybersecurity events from Tier 2 analysts.
- Distinguish events from benign activities, and escalate confirmed incidents to the Incident Response Lead.
- Provide in-depth cybersecurity analysis, and trending/correlation of large data-sets such as logs, event data, and alerts from diverse network devices and applications within the enterprise.
- Identify and troubleshoot specific cybersecurity incidents and make sound technical recommendations that enable expeditious remediation.
- Proactively search through log, network, and system data to find and identify undetected threats.
- Support security tool/application tuning engagements with analysts and engineers to develop/adjust rules, analyze/develop related response procedures, and reduce false-positives from alerting.
- Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs) into network security tools/applications to protect the network.
- Quality-proof technical advisories and assessments prior to release from SOC.
- Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
- Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements.
- Formulate and coordinate technical best-practice SOPs and Runbooks for SOC Analysts.
- Respond to inbound requests via phone and other electronic means for technical assistance, and resolve problems independently.
- Coordinate IT project management, engineering, maintenance, QA, and risk management.
- Plan, coordinate, and monitor project activities, ensuring the project life-cycle complies with district standards.
- Develop, implement, maintain, and enforce documented standards and procedures for the design, development, installation, and modification of assigned systems.
- Perform application upgrades, monitoring, maintenance, and reporting on real-time databases, network and serial data communications.
- Develop technical applications to support users and provide training for system products and procedures.
Required Qualifications:
- 11-15 years of experience implementing, administering, and operating IS tech such as firewalls, IDS/IPS, SIEM, Antivirus, net traffic analyzers, and malware analysis.
- 11-15 years of experience developing, leading, and executing information security incident response plans.
- 11-15 years of experience developing standard and complex IT solutions & services, driven by business requirements and industry standards.
- 11-15 years of experience utilizing advanced scripting and tool automation (e.G., Perl, PowerShell, Regex).
- 5 years of demonstrated operational experience as a cybersecurity analyst/engineer handling and coordinating cybersecurity incidents and response in critical environments (SOC).
- 5 years of in-depth understanding of cybersecurity attack countermeasures for adversarial activities such as malicious code, DDoS, phishing, ransomware, botnets, and C2 activity.
- 5 years of in-depth hands-on experience analyzing and responding to security events and incidents with SIEM systems.
- 5 years of strong knowledge of TCP/IP protocols, services, and networking, with experience identifying, analyzing, containing, and eradicating cybersecurity threats.
- 5 years of strong knowledge of cybersecurity attack methodologies, including tactics, techniques, and associated countermeasures.
Minimum Education/ Certification Requirements:
- Bachelor's Degree in Cyber Security, Information Technology, Computer Science, or a related field (or equivalent experience).
The target annual salary is $89,488.00 - $95,880.00.