Cyber Incident Response Analyst with Security Clearance

4 weeks ago


Bay St Louis MS United States Base One Technologies Full time
Primary Responsibilities
• Coordinate investigation and response efforts throughout the Incident Response lifecycle
• Correlate and analyze events and data to determine scope of Cyber Incidents
• Acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts
• Recognize attacker tactics, techniques, and procedures as potential indicators of compromise (IOCs) that can be used to improve monitoring, analysis and Incident Response.
• Develop, document, and maintain Incident Response process, procedures, workflows, and playbooks
• Tune and maintain security tools (EDR, IDS, SIEM, etc) to reduce false positives and improve SOC detection capabilities
• Document Investigation and Incident Response actions taken in Case Management Systems and prepare formal Incident Reports
• Create metrics and determine Key Performance Indicators to drive maturity of SOC operations
• Develop security content such as scripts, signatures, and alerts Basic Qualifications
Requires a minimum of a Bachelors degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field PLUS four (4) years of professional experience in incident detection and response, malware analysis, or cyber forensics.
Must have at least one of the following certifications:
• SANS GIAC: GCIH, GCIA, GCFA, GPEN GCFE, GREM
• CISSP OSCP, OSCE, OSWP
Must have current TS/SCI
In addition to specific security clearance requirements, all Department of Homeland Security SOC employees are required to obtain an Entry on Duty (EOD) clearance to support this program
Preferred Qualifications
• In-depth knowledge of each phase of the Incident Response life cycle
• Expertise of Operating Systems (Windows/Linux) operations and artifacts
• Understanding of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc), and devices (Firewalls, Proxies, Load Balancers, VPN, etc)
• Ability to recognize suspicious activity/events, common attacker TTPs, and perform logical analysis and research to determine root cause and scope of Incidents
• Be familiar with Cyber Kill Chain and have utilized the ATT&CK Framework
• Have scripting experience with Python, PowerShell, and/or Bash
• Ability to independently prioritize and complete multiple tasks with little to no supervision
• Flexible and adaptable self-starter with strong relationship-building skills
• Strong problem solving abilities with an analytic and qualitative eye for reasoning Potential for Telework:No
Clearance Level Required: Top Secret/SCI
Travel: No
Scheduled Weekly Hours: 40
Shift: Day

  • St Louis, United States SITEC Consulting LLC Full time

    Position Overview: Provide CSOC Tier 2 services, which is 24x7x365 coordination, execution, and implementation of all actions required for the containment, eradication, and recovery measures for events and incidents. CSOC Tier 2 services includes malware and implant analysis, and forensic artifact handling and analysis. When a CIRT is stood up, all...


  • St Louis, United States SITEC Consulting LLC Full time

    Position Overview: Provide CSOC Tier 2 services, which is 24x7x365 coordination, execution, and implementation of all actions required for the containment, eradication, and recovery measures for events and incidents. CSOC Tier 2 services includes malware and implant analysis, and forensic artifact handling and analysis. When a CIRT is stood up, all...


  • Quincy, MA, United States State Street Corporation Full time

    Who are we looking for: State Street seeks to recruit an Early Career Cyber Security Operations Center (SOC) analyst that will assist in the detection, triage, analysis and response to cyber-attacks. The analyst will join our SOC team which will run a 24/7 coverage, 365 days a year model, with a partner team in Ireland. The SOC team is responsible for...

  • Cyber Hunt Level II

    2 weeks ago


    St Louis, United States Strategic ASI Full time

    What You'll Get to Do: Our client is hiring a new member to our Cyber Security Hunt Services team. This role will proactively search for indicators of compromise on NGA systems through planned Hunt missions. Assign the Cybersecurity Operations Manager to direct and oversee all Contractor support for this sub-service and serve as the primary...


  • Quincy, MA, United States State Street Corporation Full time

    State Street seeks to recruit a SOC Manager for its Cyber Defense Center. The SOC Manager will help lead the triage, analysis and response to cyber-attacks. Join us in evolving our response capabilities to protect State Street, its customers and partners from ever-evolving and sophisticated threat actors. State Streets Cyber Fusion Center is responsible for...


  • Saint Louis, United States RISA Full time

    Job DescriptionJob DescriptionSkill Level: Mid-Senior LevelSecurity Clearance: Top Secret /SCIJob Type: Full-TimeRemote: NoAbout RISA:In this time of rapid change, as technologies expand at lightning speed, RISA seeks to remain at the forefront - applying them in unique ways to address our customers’ challenges and providing our employees with engaging...


  • Saint Louis, United States SITEC Consulting Full time

    Job DescriptionJob DescriptionPosition Overview: Provide CSOC Tier 2 services, which is 24x7x365 coordination, execution, and implementation of all actions required for the containment, eradication, and recovery measures for events and incidents. CSOC Tier 2 services includes malware and implant analysis, and forensic artifact handling and analysis. When a...


  • St. Louis, United States CALIBRE Full time

    CALIBRE Systems Inc., an employee-owned Management Consulting and Digital Transformation Company is seeking aSoftware Developer (Senior) will develop, create, maintain, and write/code new (or modify existing)computer applications, software, or specialized utility programs.The Software Developer’s responsibilities include, but are not limited to, the...


  • Palm Bay, United States City of Palm Bay Full time

    MINIMUM TRAINING AND EXPERIENCE Bachelor’s degree in computer science, Information Technology, Cyber Security, or a closely related field with a minimum of two (2) years of experience in information/cyber security system support, preferably in a governmental setting. or Associate Degree in Computer Science, Information Technology, or a closely related...


  • Saint Louis, United States RISA Full time

    Job DescriptionJob DescriptionAbout RISAIn this time of rapid change, as technologies expand at lightning speed, RISA seeks to remain at the forefront - applying them in unique ways to address our customers’ challenges and providing our employees with engaging career opportunities. We seek professionals excited by a challenge and focused on assisting our...

  • Sr Infosec Analyst

    3 weeks ago


    St Louis, United States CareerBuilder Full time

    Must Have Qualifications: Completion of one of the following recognized professional certifications: QSA (Qualified Security Assessor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), SSCP (Systems Security Certified Practitioner), Certified Ethical Hacker (CEH)Technical Expertise: Cisco Firepower,...

  • Sr Infosec Analyst

    2 weeks ago


    St Louis, United States Phaxis Full time

    Must Have Qualifications: Completion of one of the following recognized professional certifications: QSA (Qualified Security Assessor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), SSCP (Systems Security Certified Practitioner), Certified Ethical Hacker (CEH) Technical Expertise: Cisco Firepower,...


  • St. Louis, Missouri, United States Block Full time

    Job Description Block is seeking an experienced Global Security Operations Center (GSOC) Lead to oversee security operations on a global scale. This role oversees the day to day operations of the GSOC, and will be responsible for leading a team of security professionals in monitoring, assessing, and responding to security incidents across our distributed...


  • St Louis, United States Strategic ASI Full time

    Our client is seeking multiple Cybersecurity Operations Analyst II who could potentially be located in either Springfield, VA or Saint Louis, MO. What You'll Get to Do: Coordinate and implement tasks, performing analysis, and building/documenting response activities required during cyber security incident response, including but not limited to actions...


  • St Louis, United States Stifel Full time

    Summary Under general supervision, the IT Security Governance Analyst II is a front-line member of the IT Security Program team responsible for the overall management of the IT Security Program. The IT Security Governance Analyst is responsible for supporting internal, external, and client audits, managing security risks within a GRC solution, and assessing...


  • Saint Louis, United States SITEC Consulting Full time

    Job DescriptionJob DescriptionAbout SITECSITEC is an employee and customer focused Information Technology and Professional Services Firm specializing in design, development, and delivery of state-of-the-art technology solutions, as well as cybersecurity, software and systems engineering services.SummaryThe Cyber Security Engineering Specialist provides...

  • IT Specialist II

    3 weeks ago


    St Louis, United States CareerBuilder Full time

    Job Description Information Technology Under general direction, develop and enforce enterprise information security policies and standards across The District, IT and OT. Work involves coordinating and/or planning, implementing, and monitoring security measures for the protection of the district's information assets from unauthorized use, modification, or...


  • Palm Bay, United States Harris Geospatial Solutions Full time

    Job Title:Lead, Systems Engineer – Cyber Effects (Active TS/SCI Clearance Required) Job Code: 9226 Job Location:Palm Bay, FL or Columbia, MD or Herndon, VA Job Description: As aLead, Systems Engineer – Cyber Effectsyou will lead and contribute to architecting, implementing, testing, and troubleshooting cyber applications. Evaluate development and COTS...


  • St Paul, United States Blue Star Partners, LLC Full time

    Job Description Job Description Job Title: Senior Cybersecurity Analyst Location: St. Paul, MN – Onsite – Local candidates only Period: 05/13/2024 to 12/20/2024 – possibility of extension Hours/Week: 40 hours Rate: $40-$45/hour (Hours over 40 will be paid at Time and a Half) Contract Type: W-2 Scope of Services: The Senior Cybersecurity Analyst...

  • Senior CND-SP Analyst

    3 hours ago


    Fredericksburg, VA, United States City of Fredericksburg, VA Full time

    Senior CND-SP Analyst This Position is located in Washington, DC ARTTRA Inc. is seeking a highly qualified Cyber Network Defense-Service Provider Analyst to ensure the safety of information systems assets, and to protect systems from intentional or inadvertent access or destruction. The ideal candidate will:• Perform Computer Security Incident Response•...