Cybersecurity Analyst

South Dakota State Government
Sioux Falls, United States of America
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 94K

Job location

Sioux Falls, United States of America

Tech stack

Bash
Cloud Computing
Computer Security
Computer Forensics
Data Security
Intrusion Detection and Prevention
Python
Powershell
Security Information and Event Management
Scripting (Bash/Python/Go/Ruby)
Malware
Cyber Threat Analysis
Cybercrime
Security Orchestration, Automation & Response

Job description

The Bureau of Information and Technology is seeking a full-time, permanent Cybersecurity Analyst. Under general supervision, this role involves detecting and mitigating cybersecurity threats in the organization. The Cybersecurity Analyst will be responsible for analyzing a variety of log sources such as network, endpoint, server, cloud, identity and web events to identify cyber threats, perform threat response activities to neutralize threats, and create or improve threat detections to improve overall security operations., * Security Monitoring: Review security logs for threats, anomalies, intrusions, and abnormal connection behavior.

  • Incident Investigation: Investigate, report, and escalate issues to cybersecurity staff and management as required.
  • Incident Response: Participate in incident response, computer forensics, data preservation, and investigations related to network breaches or unauthorized data access.
  • Process improvements: Recommend enhancements for an efficient threat-hunting function.
  • Reporting and Analysis: Support regular and special reporting, including reports of vulnerabilities, risks, control deficiencies, remediation strategies, and performance metrics.
  • Threat Intelligence Gathering: Collect, analyze, and disseminate threat intelligence from various sources to identify potential threats and vulnerabilities.
  • Threat Hunting: Proactively search for indicators of compromise (IOCs) and advanced persistent threats (APTs) within the network.
  • Malware Analysis: Perform static and dynamic analysis of malware samples to understand their behavior and develop mitigation strategies.
  • Threat Detection Modeling: Develop and maintain threat models to understand potential attack scenarios and improve defensive strategies.
  • Threat Awareness: Provide threat awareness to other teams on the latest threats, attack techniques, and mitigation strategies.
  • Collaboration: Work closely with other cybersecurity teams.

Join our team and contribute to maintaining our organization's security and integrity.

Requirements

Preferred qualifications include a bachelor's degree in a cybersecurity-related field and 3 to 5 years' experience in cybersecurity operation center (CSOC) functions such as detection & analysis, threat hunting and threat intelligence.

Knowledge of:

  • Core Cybersecurity Operation Functions;
  • threat actor attack chains and campaigns;
  • Cybersecurity standard frameworks, controls, technologies, and solutions;
  • Incident Response Management;
  • IT Domains such as network, endpoint, server, cloud, identity and web.

Skill to:

  • use SIEM, EDR, and SOAR platforms;
  • build effective threat detection rules and queries;
  • develop and enhance cybersecurity playbooks;
  • develop and perform cybersecurity analysis and threat hunts;
  • consume and disseminate cybersecurity threat intelligence;
  • perform strong communication, both oral and written.

Ability to:

  • work within a team and with other teams;
  • understand scripting languages (e.g. Python, Powershell, Bash);
  • emulate threats against enterprise infrastructure.

Additional Requirements: To be considered, please attach your resume.

This position is eligible for Veterans' Preference per ARSD 55:10:02:08.

Successful applicant(s) will be required to undergo a background investigation. An arrest/conviction record will not necessarily bar employment.

The State of South Dakota does not sponsor work visas for new or existing employees. All persons hired will be required to verify identity and eligibility to work in the United States and complete an Employment Eligibility Verification, Form I-9. The State of South Dakota as an employer will be using E-Verify to complete employment eligibility verification upon hire.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • Retirement plan
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance
  • Paid holidays, This is a Full-Time 40 Hour Weekly position with the Bureau of Information and Technology (BIT). For more information on BIT, please visit https://www.sd.gov/bit . If you are highly motivated, enjoy cybersecurity, and looking to build a career, we want you to join our team!

BIT consists of five divisions - Administration, Enterprise Platform and Infrastructure, Development, Technology Operations and Communications, and South Dakota Public Broadcasting - which serve the State of South Dakota by providing technology solutions, services, and support. The Cyber Security Analyst is a key position within the Technology Operations and Communications division.

Benefits of working for the State of South Dakota include:

  • multiple health plan options, including a $0 employee premium option;
  • 6% fully matched retirement plan. Includes long term disability and family survivor benefits;
  • $25,000 paid life insurance;
  • generous leave policies;
  • stable industry sector;
  • flexible work schedule, providing the ability to maintain a great work/life balance.

Apply for this position