Company

RISASee more

addressAddressSpringfield, VA
type Form of workFull-Time
CategoryInformation Technology

Job description

Job Description

Type: Mid-Senior Level

Time Type: Full time, ExemptMinimum Clearance Required to Start: Top Secret/SCIPercentage of Travel Required: Up to 10%Type of Travel: LocalPosition Overview:

As the Cyber Security Operations Specialist III / SIEM, you will provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) capability (i.e. Enterprise Audit), long-term analytics platform, log aggregation platform, and the cyber threat intelligence capability, signature development and deployment, and reputation management services. This includes onboarding all new and existing IT resources and ensuring the correct routing of all audit events to mission partners per Intelligence Community Standards (ICS) 500-27.

More About the Role:
  • Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capabilities, such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software.
  • Maintain system availability and reliability with a threshold of 99.99%.
  • Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation.
  • Perform day-to-day maintenance and specific scheduled maintenance activities that result from manufacturers' recommended service intervals, alerts, bulletins, available patches, and updates according to agency-approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform.
  • Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution and coordinated through and approved by CSOC and ESC government management.
  • Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions.
  • Perform continuous engineering assessments to improve this service's performance, effectiveness, coverage, and maturity.
  • Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost).
  • Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, policies, guidance, procedures etc.
  • Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuring all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN – Joint Incident Management System, DoD CIO – DoD Scorecard/Get to Green reporting, IC CIO – Cybersecurity Performance Evaluation Model reporting, etc.).
  • Utilize agency-approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions.
  • Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services.
You’ll Bring These Qualifications:
  • TS/SCI clearance required (current). Must successfully pass and maintain a Government Polygraph (post-hire requirement).
  • Bachelor's Degree and Six (6) years of job-related experience. Additional experience may be considered in lieu of a degree.
  • DoD 8570.01-M IAT Level II certification.
  • DoD 8570.01-M CSSP Infrastructure Support certification
  • SIEM experience with one of the following: ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA).
  • Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules.
  • Create SIEM playbooks.
  • Linux (RHEL) Expert (administration and engineering).
  • Proficient in manipulating SIEM filters to find better and analyze potential malicious/atypical activity and reduce false positives.
  • Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events.
  • Creation of ArcSight rules based on use cases of malicious events.
  • Tuning and aggregation of queries and filters.
  • Skilled in troubleshooting event flow through Enterprise Audit infrastructure.
  • Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools.
  • Experience with SIEM and Development Projects.
  • Experience with SIEM support for projects and technical exchange meetings.
  • Experience developing and maintaining enterprise audit projects.
These Qualifications Would Be Nice to Have:
  • Kibana
  • Data Analytics
  • TS/SCI w/Poly
Work Environment:

Professional Office Environment: Must be able to sit at a desktop or laptop computer for extended periods of time.

Physical Demands:
  • While performing the duties of this job, the employee is regularly required to sit, stand, talk, hear, and use hands and fingers to operate a computer and telephone.
  • Must be able to communicate regularly via telephone and verbally present information to employees, customers, and outside vendors.
Expected Hours of Work:

40 hours per week based on the customer’s core operating hours.

About RISA:

In this time of rapid change, as technologies expand at lightning speed, RISA seeks to remain at the forefront - applying them in unique ways to address our customers’ challenges and providing our employees with engaging career opportunities. We seek professionals excited by a challenge and focused on assisting our customers to reach their goals. At RISA, our success comes from the talent and commitment of our employees. As a team, we share the challenges and rewards of providing valuable services to our customers. Come along for the journey and be part of our growth and success.

Benefits:

RISA offers a comprehensive benefits package that includes medical, dental, and vision insurance; company-paid disability; life insurance; retirement savings plans: 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

RISA is an Equal Opportunity Employer.


Refer code: 7631078. RISA - The previous day - 2024-01-04 00:38

RISA

Springfield, VA
Popular Cyber Security Operation jobs in top cities

Share jobs with friends

Related jobs

Cyber Security Operations Specialist Iii - Seim

Cyber Security Operations Specialist / CSOC Tier 2, 3

Abile Group, Inc.

$100K - $127K a year

Springfield, VA

3 months ago - seen

Cyber Security Operations Specialist

SITEC Consulting

Springfield, VA

5 months ago - seen