Cybersecurity Analyst

Artech Information Systems LLC
Tampa, FL, United States
about 1 month ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$124,800.0 - $145,600.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Access Network Cyber Security Continuous Availability Linux Intrusion Detection and Prevention Network Security Security Information and Event Management Network Routers Firewalls (Computer Science) Splunk

Job description

  • Utilize your experience with a Security Information and Event Management (SIEM) tool. Splunk is preferred, but experience with an equivalent SIEM would be acceptable.
  • Develop and Implement Splunk Queries: Create and optimize complex Splunk queries to extract, analyze, and visualize security data from diverse sources. Utilize Splunk Search Processing Language (SPL) to generate actionable insights for proactive threat detection and response.
  • Design Splunk Dashboards and Reports: Design user-friendly Splunk dashboards and reports tailored to different stakeholders, such as security operations teams, management, and auditors. Provide real-time visibility into security events, trends, and key performance indicators.
  • Configure and Maintain Splunk Infrastructure: Configure and fine-tune Splunk deployments, including data inputs, data parsing, field extractions, and data enrichment pipelines. Ensure the continuous availability and optimal performance of Splunk indexes, search heads, and forwarders.
  • Utilize Splunk Enterprise Security: Leverage Splunk Enterprise Security to develop and implement security use cases, correlation searches, and notable events for threat detection and analysis. Monitor security-related alerts and incidents to identify and prioritize security threats.
  • Utilize Trellix/Endpoint Security Solutions (ESS), formally Host Based Security System (HBSS) to detect and counter known threats.
  • Collaborate with Cross-Functional Teams: Collaborate with cross-functional teams, including IT, network, and application teams, to integrate Splunk with various platforms and systems. Provide technical expertise in advising security on best practices and designing effective security controls.
  • Investigate Security Incidents: Conduct in-depth investigations into security incidents, anomalies, and breaches using Splunk’s forensic capabilities. Perform root cause analysis, incident triage, and post-incident reviews to identify gaps in security controls and recommend remediation actions.
  • Documentation and Reporting: Document Splunk configuration, operational procedures, and security findings. Prepare comprehensive reports detailing security events, trends, and mitigation strategies. Communicate technical information effectively to non-technical stakeholders.
  • Stay current with Industry Trends: Stay abreast of the latest cybersecurity threats, vulnerabilities, and industry best practices. Continuously enhance your knowledge of Splunk features and capabilities through self-study, professional training, and certifications.
  • Individual must have a solid understanding of security information and event management (SIEM) concepts and best practices to include proficiency in troubleshooting Splunk configurations and performance issues.
  • Ability to collaborate with other teams to investigate security incidents and provide insights for improving security posture.

Requirements

  • Bachelor’s degree with 2 years of experience
  • U.S. Citizenship required
  • A current/active DoD TS/SCI clearance
  • Must possess DoD 8570 Certification for IAT Level II or higher prior to start date.
  • Experience with a Security Information and Event Management (SIEM) tool.
  • Ability to collaborate with other teams to investigate security incidents and provide insights for improving security posture.
  • Working knowledge of network security controls such as routers, switches, firewalls and network access controls.
  • Working Knowledge of Linux and Windows Operating Systems.
  • Knowledge of vulnerabilities, threat detection, encryption, and security audits.
  • Must be willing to work a Panama schedule that includes working 12-hour shifts.

Benefits & conditions

Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply, only if they are willing to work on-site. This position follows a Panama schedule that includes working 12-hour shifts. This schedule allows for employees to have a three-day weekend every other week and rotates from days to nights approximately every 12 weeks. Employees are compensated with a pay differential during their night shift rotations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

9:33 min

Limiting script execution permissions in Node and package managers

Chris Heilmann +2 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all