Cybersecurity Engineer - SOC Analyst
QUANTUM SKY LLC
Fort Lee, VA, United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Apple Mac Systems
Microsoft Azure
Border Gateway Protocol
Cyber Security
Computer Networks
Computer Forensics
Dynamic Host Configuration Protocol
Linux
Domain Name System (DNS)
Event Logging
Hypertext Transfer Protocols (HTTP)
+18 more
Internet Control Message Protocol
Networking Hardware
Intrusion Detection and Prevention
Intrusion Detection Systems
Multi-protocol Systems
Pcap
Simple Mail Transfer Protocols
NetFlow
Routing
Packet Analyzer
Pattern Recognition
Security Information and Event Management
SQL Databases
Transmission Control Protocol (TCP)
Web Applications
Computer Networking Systems
Malware
Splunk
Job description
- Lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management) and Malware Analysis
- Analyze information technology cybersecurity events to discern events that qualify as legitimate security incidents as opposed to non-incidents.
- Conduct security event triage, incident investigation, implement countermeasures, and conduct computer incident response.
- Monitor customer’s Security Information and Event Monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting (i.e. Splunk, Azure Sentinel).
- Analyze security events (i.e. windows event logs, network traffic, IDS events for malicious intent)
- Track cyber activities within various SOC workflows.
- View alerts and system logs from various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks.
- View and analyze NetFlow data and packet capture (PCAP).
- View logs derived from network devices and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.)
- Assist with preparing, validating, and maintaining security documentation including, but not limited to cybersecurity incident response plan, risk assessments, legal investigations.
- Conduct SOC level 1tasks and duties, when needed.
- Escalate when necessary to Level 3 support, SOC lead, or watch officer.
- Other services and support as needed or directed by the government.
Requirements
Required:
- 3-7 years’ of experience in a relevant field
- Ensure personnel are compliant with DoDI 8140.02 Identification, Tracking, and Reporting of Cyberspace Workforce Requirements as set forth in the DoD Cyber Workforce Framework (DCWF). Personnel must hold required certifications at time of hire and must maintain certifications for the entire performance period.
- Ensure Incident Response & Analysis personnel also assigned as forensic analysts also hold and maintain an industry-recognized Computer Forensics certification such as the GIAC GCFE, GCFA, or EC-Council CHFI.
- Ensure Incident Response & Analysis personnel are knowledgeable of industry-standard methods and practices concerning the use and monitoring of intrusion detection products in a production network.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
7 Cloud Computing Trends Coming in 2025 for Developers
over 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago