Security Operation Center

3 weeks ago


Schriever AFB, United States IC-CAP Full time

Security Operation Center (SOC) Analyst Lead 1: Position Description: Lead SOC Analyst's primary function is to develop, implement, and evaluate a SOC teams' ability to provide comprehensive Computer Network Defense and Response support through 24×7×365 monitoring and analysis of potential threat activity targeting the enterprise. This position is responsible leading the team responsible for monitoring the organization's network and devices for security breaches, maintain software such as log management; research latest security trends; Conduct security assessments, and compliance reviews of the SOC operations and assists with Security Policy and Procedure maintenance and training of all SOC personnel. This position requires a solid understanding of cyber threats and information security in the domains of TTP's, Threat Actors, Campaigns, and Observables. Additionally, this candidate must be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management. This position will support activities within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide "day-to-day" support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities. Performance shall include: * Must have strong analytical and technical skills in computer network defense operations, ability to lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management) and Malware Analysis * Experience and ability to analyze information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes security event triage, incident investigation, implementing countermeasures, and conducting incident response Must be knowledgeable and have extensive hands-on experience with a Security Information and Event Monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting. * Strong logical/critical thinking abilities, especially analyzing security events (windows event logs, network traffic, IDS events for malicious intent) * Excellent organizational and attention to details in tracking activities within various Security Operation workflows * A working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks, a conceptual understanding of Windows Active Directory is also required, and a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.) * Experience with the identification and implementation of countermeasures or mitigating controls for deployment and implementation in the enterprise network environment. * Experience with one or more of the following technologies Network Threat Hunting, Big Data * Analytics, Endpoint Threat Detection and Response, SIEM, workflow and ticketing, and Intrusion * Detection System Support the design, implementation, operation and maintenance of security applications and tools based upon the established security architecture. * Expert knowledge on SIEM technologies, content filtering/ firewall technology, and cloud technology * Prepare, validate, and maintain security documentation including, but not limited to cybersecurity incident response plan, risk assessments, legal investigations. * Develop and implement SOC processes and procedures. * Excellence in communicating business risk from cybersecurity issues. * Expresses information to individuals or groups effectively, considering the audience and nature of the information while making clear and convincing oral presentations; listens to others, and responds appropriately. Education and Experience: * Bachelor's degree * 8-10 years related experience; Prior performance in roles such as ISSO, ISSM, or SOC analyst; Training and Certifications: * CSSP Incident Responder (in lieu of CSSP Auditor) * Combatting Trafficking in Persons (CTIP) Security Clearance: * DoD Approved Clearance and Poly



  • Schriever AFB, United States P-11 Security Full time

    The Program Security Representative’s primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAPs). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities. Performance...


  • Schriever AFB, United States K2 Group, Inc. Full time

    Description *This position is a contingency opportunity The Personnel Security Specialist primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide "day-to-day" support for...


  • Schriever AFB, United States K2 Group, Inc. Full time

    Description *This position is a contingency opportunity The Program Security Representative's primary function is to provide multi-discipline security support for one or more of the customer's Special Access Programs (SAPs). The position will provide "day-to-day" multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and Special...


  • Schriever AFB, United States K2 Group, Inc. Full time

    Description *This position is a contingency opportunity The Activity Security Manager's primary function is to provide multi-disciplined security support to a customer's facility and organization. The position will provide "day-to-day" support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities. The position...


  • Schriever AFB, United States K2 Group, Inc. Full time

    Description *This position is a contingency opportunity The ISSO's primary function is working within Special Access Programs (SAPs) supporting SMC and AFSPC mission areas. The position will provide "day-to-day" support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities. Performance shall include: * Review,...


  • Schriever AFB, United States K2 Group, Inc. Full time

    Description *This position is a contingency opportunity. The System Security Engineer's primary function is working within Special Access Programs Facilities (SAPFs) and SCIF's supporting SMC and AFSPC acquisition programs. The position will provide "day-to-day" support for Collateral, Sensitive Compartmented Information (SCI) and/or Special Access Program...


  • Schriever AFB, United States IC-CAP Full time

    Information Technology-Information Assurance (IT-IA) Specialist 1: Position Description: The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide "day-to-day" support for...


  • Bolling AFB, United States Base One Technologies Full time

    Our DC Metro based client is looking for a Security Subject Matter Expert/Lead. This position requires an active Secret. If you are qualified for this position. Please email me your updated resume in word format to    Work location:St. Elizabeths Campus, Washington, DC We are looking for a Cyber Security Subject Matter Expert/Lead that will support the...


  • Lackland AFB, United States TEKsystems co Allegis Group Full time

    -Review all IDS/IPS alerts per AFCERT Operating Instruction (OI) and checklists at the AOL, COOP, or Ops Floor. Conduct host security monitoring, alert review, and intrusion detection analysis for the AFIN‐SOC mission. -Develop, Review and Maintain procedures related to the overall monitoring of Hosts/Systems. -Comply with 3rd party MOU/MOA monitoring and...


  • Offutt AFB, United States TEKsystems co Allegis Group Full time

    High Level Position Overview: This Security Analyst is going to be performing two primary tasks: Taking inventory of all industrial control systems on the base in order to begin the assessment process. From there, the individual will build an Authority to Operate (ATO) package in eMASS. This package will be vetted by the Compliance Team at Tyndall. This...

  • Program Manager

    8 hours ago


    Hill AFB, United States BAE Systems Full time

    Job Description The OpportunityJoin BAE Systems as an Infrastructure and Deployment Operations Program Manager to be part of a diverse and enthusiastic team who solve some of the world's most complex technical challenges and directly support the nation's security! The Role will primarily support the 'Sentinel' Intercontinental Ballistic Missile (ICBM)...


  • Lackland AFB, United States Apex Systems Full time

    Client Industry: Government/Professional Services and Information Technology Job Type: 6 month contract to hire Location: Remote to Start/After ~3-6 weeks, required to sit fully onsite in San Antonio, TX Schedule: Night shift (6:00pm-6:00am CST)Panama schedule: 2 days on, 2 days off, 3 days on, 2 days off, 2 days on, 3 days off. Works weekends and holidays....


  • Hill AFB, United States c3el Full time

    Job Title: Network Controller Location: Hill Air Force Base, Utah Shift: Rotating Compensation: $60,000 (May be flexible depending on skill level and experience.) Overview: C³EL is currently recruiting a Network/Transport Controller to support mission critical work at Hill AFB, UT. This position supports the Transport Desk within DISA’s 24x7 Network...


  • Hill AFB, United States Credence Management Solutions Full time

    Responsibilities include, but are not limited to the duties listed below * Support internal and external briefings and reports by applying knowledge, experience and capability in the management of acquisition, physical, personnel, and documentation security pertaining to Sensitive Compartmented Information Facilities (SCIF) and Special Access Program...


  • Hill AFB, United States AxioLogic Solutions Full time

    Responsibilities: * This position requires the employee to occasionally travel away from the normal duty location, to include deployments CONUS and OCONUS. * The employee must be willing and able to travel on military and commercial aircraft. * The employee may be required to work other than normal duty hours, which may include evenings, weekends, holidays,...


  • Scott AFB, United States TEKsystems co Allegis Group Full time

    Our customer is the Defense Information Systems Agency (DISA) located at Scott AFB and acts as the provider of GIG/Defense Information System Network (DISN) services to its customers, the department of Defense (DoD) and national security organizations. The core telecommunications capabilities supported by GSM-O enables the Warfighter to meet operational...


  • Hill AFB, United States BAE Systems Full time

    Job Description BAE Systems, Inc. Air and Space Force Solutions, located at Hill AFB, UT, is looking to hire a Security Professional in support of the Sentinel programs. In this exciting role, the Sr. Security Specialist will work closely with a BAE Security Manager to assist in the daily security operations of the Government Security Programs in support of...


  • Bolling AFB, United States Executive Management Services, LLC Full time

    Federated IT seeks a highly qualified Hardware Engineer to join a mission-focused team that maintains applications, services, microservices, configuration, integration, and support services. The effort requires the development, testing, maintenance, deployment, and enhancement of a network and underlying services/microservices’ while identifying future...


  • Macdill AFB, United States RMantra Solutions Inc. Full time

    Information Assurance Engineer Location: Tampa, FL – MacDill AFBWork Schedule: 100% OnsiteClearance: TS/SCICertification: CompTIA Sec+Education: BS Degree and +4 years of prior relevant experience. Specific experience, education and training may be considered in lieu of degree. Description: Key elements of this position include: Capture and refine...


  • Hill Afb, United States SmoothStack Full time

    Smoothstack is recruiting for a qualified Lead Cloud Project Manager with an ACTIVE US Government Clearance to support the Hill Component Enterprise Data Center IT Operations and Maintenance Services program located at Hill Air Force Base, Utah (HAFB). This program aims to modernize legacy USAF network infrastructure and migrate services into a new AWS Cloud...