Cybersecurity Operations Center Analyst Lead

1 week ago


Colorado Springs, Colorado, United States General Dynamics Information Technology Full time

Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Top Secret/SCI

Clearance Level Must Be Able to Obtain:
Top Secret SCI + Polygraph

Suitability:

Public Trust/Other Required:
None

Job Family:
Cyber Security

Job Qualifications:

Skills:
Cyber Incident Response, Cybersecurity, Incident Handling

Experience:
8 + years of related experience

US Citizenship Required:
Yes

Job Description:
As the RQ166630 Cybersecurity Operations Center (SOC) Analyst Lead, your primary responsibility will be to strategize, execute, and assess the capabilities of a SOC team in delivering comprehensive Computer Network Defense and Response support through continuous monitoring and analysis of potential threat activities targeting the organization.


This role entails leading a team dedicated to overseeing the organization's network and devices for security vulnerabilities, maintaining essential software such as log management systems, researching current security trends, conducting security evaluations, and ensuring compliance with SOC operations while assisting in the maintenance of Security Policies and Procedures and training all SOC personnel.

This position demands a robust understanding of cyber threats and information security, particularly in the areas of Tactics, Techniques, and Procedures (TTPs), Threat Actors, Campaigns, and Observables.

Moreover, the ideal candidate should possess familiarity with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management.

This role will support initiatives within Special Access Programs (SAPs) in collaboration with Department of Defense (DoD) agencies, providing daily support for Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities.

Performance Expectations:
Demonstrate strong analytical and technical skills in computer network defense operations, with the ability to lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management), and Malware Analysis.


Exhibit experience and capability in analyzing information technology security events to differentiate between legitimate security incidents and non-incidents, which includes security event triage, incident investigation, implementing countermeasures, and conducting incident response.

Possess extensive hands-on experience with Security Information and Event Monitoring (SIEM) platforms and/or log management systems that facilitate log collection, analysis, correlation, and alerting.

Demonstrate strong logical and critical thinking abilities, particularly in analyzing security events (e.g., Windows event logs, network traffic, IDS events for malicious intent), along with excellent organizational skills and attention to detail in tracking activities within various Security Operation workflows.

Have a working knowledge of various operating systems (e.g., Windows, OS X, Linux) commonly used in enterprise networks, along with a conceptual understanding of Windows Active Directory and a working knowledge of network communications and routing protocols (e.g., TCP, UDP, ICMP, BGP, MPLS) and common internet applications and standards (e.g., SMTP, DNS, DHCP, SQL, HTTP, HTTPS).

Experience in identifying and implementing countermeasures or mitigating controls for deployment in the enterprise network environment is essential.

Familiarity with technologies such as Network Threat Hunting, Big Data Analytics, Endpoint Threat Detection and Response, SIEM, workflow and ticketing, and Intrusion Detection Systems is required.

Support the design, implementation, operation, and maintenance of security applications and tools based on established security architecture.

Possess expert knowledge of SIEM technologies, content filtering/firewall technology, and cloud technology.

Prepare, validate, and maintain security documentation, including but not limited to cybersecurity incident response plans, risk assessments, and legal investigations.

Develop and implement SOC processes and procedures while effectively communicating business risks associated with cybersecurity issues.

Express information clearly to individuals or groups, considering the audience and nature of the information, while making clear and convincing oral presentations; listen to others and respond appropriately.


Experience:
8-10 years of related experience
Prior roles such as ISSO, ISSM, or SOC analyst
2+ years of SAP experience required

Education:
Bachelor's degree in a related field or equivalent experience (4 years)

Certifications:
IAT Level 3 or IAM Level 3 or CND Auditor or Incident Responder - within 6 months of hire (CEH, CFR, CCNA Cyber Ops, CySA+, GCIA, GCIH, GICSP, SCYBER)

Clearance Required to Start:
TS/SCI required
Must be able to attain – TS/SCI with CI Polygraph

Other Requirements:


Demonstrated strong knowledge of NIST and other guidelines and standards and their relation to the System Development Life-Cycle (SDLC).

Strong background in distributed client/server environments, Windows server/desktop environments, and IP networking is required.

Ability to develop rules, filters, views, signatures, countermeasures, and operationally relevant applications and scripts to support analysis and detection efforts.

Robust knowledge of common attack methodologies, tactics, and protocols.

Understanding of researching Emerging Threats and recommending monitoring content within security tools.

Knowledge of standard and advanced defense and remediation techniques and processes.

Experience in analyzing NetFlow data and packet capture (PCAP).

Knowledge of the TCP and IP protocol suite, security architecture, DNS, and remote access security techniques and products.

Technical experience in the information security field utilizing a mix of security technologies such as Intrusion Detection & Prevention Systems (IDS/IPS), Firewalls, and Log Analysis.

Experience with SIEM, Network Behavior Analysis tools, Antivirus, and Network Packet Analyzers, as well as Digital Forensics tools in an Enterprise environment, and Cyber Incident Response activities.


Scheduled Weekly Hours:
40

Travel Required:
10-25%

Telecommuting Options:
Onsite

Total Rewards at GDIT:


Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.

To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement, and jury duty leave.

To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance are provided or available.

We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

We are GDIT.

A global technology and professional services company that delivers consulting, technology, and mission services to every major agency across the U.S. government, defense, and intelligence community.

Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation.

We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber, and application development.

Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.


We connect people with the most impactful client missions, creating an unparalleled work experience that allows them to see their impact every day.

We create opportunities for our people to lead and learn simultaneously.

From securing our nation's most sensitive systems to enabling digital transformation and cloud adoption, our people are the ones who make change real.

GDIT is an Equal Opportunity/Affirmative Action employer.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.



  • Colorado Springs, Colorado, United States IC-CAP, LLC Full time

    Cybersecurity Operations Center (CSOC) Analyst Lead: Position Overview: The primary responsibility of the Lead CSOC Analyst is to design, execute, and assess the effectiveness of a CSOC team's capability to deliver comprehensive Computer Network Defense and Response services through vigilant monitoring and analysis of potential threat activities aimed at the...


  • Colorado Springs, Colorado, United States General Dynamics Information Technology Full time

    Position Overview:The Cybersecurity Operations Center (SOC) Lead plays a pivotal role in shaping the effectiveness of a SOC team dedicated to delivering robust Computer Network Defense and Response capabilities. This includes continuous monitoring and analysis of potential threats targeting the organization. Key Responsibilities:This role involves leading a...


  • Colorado Springs, Colorado, United States Auria Full time

    Job OverviewAuria Space is on the lookout for a dedicated Cybersecurity Analyst to enhance our team. This role is pivotal in ensuring the integrity and security of our data transport systems, which are essential for reliable telemetry, tracking, command, control, and communications.Role SummaryThe Cybersecurity Analyst will be responsible for designing,...


  • Colorado Springs, Colorado, United States Targeted Solutions, LLC Full time

    Job DescriptionJob Summary:Targeted Solutions, LLC is seeking a highly skilled Cybersecurity Operations Specialist to join our team. As a key member of our security operations center, you will be responsible for providing comprehensive computer network defense and response support through 24/7/365 monitoring and analysis of potential threat activity...


  • Colorado Springs, Colorado, United States MITRE Full time

    Welcome to MITREAt MITRE, we invite you to join a dedicated team focused on addressing some of the most pressing challenges facing our nation. As a not-for-profit organization, we are committed to serving the public interest without the influence of commercial interests. Our research and development centers strive to create a meaningful impact across various...


  • Colorado Springs, Colorado, United States Rothe Full time

    Job OverviewWe are a leading provider of critical support services to government and commercial industries, including engineering, cybersecurity, communication, multimedia, and IT. Our team has served NASA and the DoD since 1978, and we are committed to delivering exceptional results to our customers.Job SummaryWe are seeking an experienced Cyber...


  • Colorado Springs, Colorado, United States Rothe Full time

    Job DescriptionWe are a leading provider of critical support services to government and commercial industries, including engineering, cybersecurity, communication, multimedia, and IT. Our company has a rich history of serving NASA and the DoD since 1978.We are seeking an experienced Cyber Security/Risk Vulnerability Analyst to join our security control...


  • Colorado Springs, Colorado, United States The Aerospace Corporation Full time

    The Aerospace Corporation stands as a premier collaborator in the nation's space initiatives, offering unparalleled technical acumen and innovative solutions for defense, civil, and commercial sectors. As a federally funded research and development center, we provide state-of-the-art solutions across satellite, launch, ground, and cyber systems.Our...

  • Cybersecurity Analyst

    2 weeks ago


    Colorado Springs, Colorado, United States MCSG Technologies Full time

    Position Title: Cybersecurity AnalystOrganization: MCSG TechnologiesWork Type: Full TimeSector: Information TechnologyCompensation Range: $118,000 - $148,000Role Overview:Oversee specialized access program networks within the organizationGather and sustain cybersecurity performance metricsApply Security Technical Implementation Guide (STIG) protocolsDesign...


  • Colorado Springs, Colorado, United States General Dynamics Information Technology Full time

    Job Summary:The Cybersecurity Operations Specialist will provide comprehensive Computer Network Defense and Response support through 24×7×365 monitoring and analysis of potential threat activity targeting the enterprise. This position will conduct security event monitoring, advanced analytics and response activities in support of the government's...


  • Colorado Springs, Colorado, United States The Aerospace Corporation Full time

    The Aerospace Corporation stands as a premier collaborator in the nation's space initiatives, offering unparalleled technical proficiency and innovative solutions for defense, civil, and commercial sectors. As a federally funded research and development entity, we provide state-of-the-art solutions across satellite, launch, ground, and cyber domains.Our...


  • Colorado Springs, Colorado, United States Scientific Research Full time

    MINIMUM SKILLS & REQUIREMENTS:At least 3 years of experience in a Senior Cybersecurity Engineer role, specifically leading efforts on a DOD program of comparable size and complexity.Current ISC2 Certified Information Systems Security Professional (CISSP) certification is mandatory.A minimum of 5 years of hands-on experience in a Senior Cybersecurity Engineer...


  • Colorado Springs, Colorado, United States Galapagos Federal Systems, LLC Full time

    Position Title: Senior Cybersecurity Engineer LeadLocation: Colorado Springs, ColoradoSalary Range: $155,000 - $165,000OverviewGalapagos Federal Systems LLC is seeking a dedicated and highly skilled individual for the role of Senior Cybersecurity Engineer Lead. This position is crucial for overseeing the management of systems, with a focus on the design,...


  • Colorado Springs, Colorado, United States Galapagos Federal Systems, LLC Full time

    Position Title: Senior Cybersecurity Engineering LeadLocation: Colorado Springs, ColoradoSalary Range: $155,000 - $165,000Position OverviewGalapagos Federal Systems LLC is seeking a highly skilled and motivated individual for the role of Senior Cybersecurity Engineering Lead. This position is critical for overseeing system management support with an emphasis...


  • Colorado Springs, Colorado, United States The Aerospace Corporation Full time

    The Aerospace Corporation stands as a premier collaborator in the nation's space initiatives, offering unparalleled technical knowledge and inventive solutions for defense, civil, and commercial sectors. As a federally funded research and development entity, we provide state-of-the-art solutions across satellite, launch, ground, and cyber domains.Our...


  • Colorado Springs, Colorado, United States Rothe Full time

    Job OverviewWe are a leading provider of critical support services to government and commercial industries, including engineering, cybersecurity, communication, multimedia, and IT. Our team has served NASA and the DoD since 1978, and we are committed to delivering exceptional results to our customers.Job SummaryWe are seeking an experienced Cyber...


  • Colorado Springs, Colorado, United States Jacobs Full time

    About the Role:We are seeking a highly skilled Senior Information Systems Security Engineer to join our team at Jacobs. As a key member of our cybersecurity team, you will play a critical role in ensuring the confidentiality, integrity, and availability of our systems, networks, and data.Key Responsibilities:Develop and implement comprehensive cybersecurity...


  • Colorado Springs, Colorado, United States Parsons Corporation Full time

    About the Role:Parsons Corporation is seeking a highly skilled Cybersecurity Specialist to join our Federal Solutions team. As a key member of our team, you will be responsible for designing, implementing, and maintaining a secure network infrastructure to support our Defensive Cyber Operations.Key Responsibilities:Participate in Agile Mission Deployment...


  • Colorado Springs, Colorado, United States Galapagos Federal Systems, LLC Full time

    Job Title: Senior Cyber Engineer LeadJob SummaryGalapagos Federal Systems LLC is seeking a highly skilled and motivated individual for the position of Senior Cyber Engineer Lead. This role involves overseeing system management support with a primary focus on the design, specification, integration, and implementation of extensive management architectures that...


  • Colorado Springs, Colorado, United States Nightwing Full time

    Position Overview: At Nightwing, we are committed to safeguarding our nation and allies through advanced cybersecurity solutions. We leverage over a century of expertise to address contemporary challenges and anticipate future threats. Our team tackles significant issues that contribute to a safer, more secure environment.We are currently seeking a highly...