Security Operations Center

6 months ago


Annapolis Junction, United States EverWatch Full time

Overview

EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support to our country’s most critical missions. We are a full-service government solutions company. Harnessing the most advanced technology and solutions, we strengthen defenses and control environments to preserve continuity and ensure mission success.

EverWatch is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy), gender identity, sexual orientation, national origin, age (40 or older), disability, genetic information, citizenship or immigration status, and veteran status or any other factor prohibited by applicable law.

EverWatch employees are focused on tackling the most difficult challenges of the US Government. We offer the best salaries and benefits packages in our industry - to identify and retain the top talent in support of our critical mission objectives. 

Responsibilities

We are looking for an experienced Security Operations Center (SOC) Tier II Analyst to improve monitoring strategies and analyze threats to safeguard infrastructure supporting global missions focused on seeking out and eliminating cyberspace threats to defend the United States and its Allies. You will guide the team on best practices and security measures. You'll configure defense tools, create reports, and dashboards and build custom queries. You will make recommendations to leadership on best practices to harden infrastructure and improve alerting. You'll lead incident response and remedy potential incidents escalated from Tier 1 SOC Analysts. You'll work with the team to understand, mitigate, and respond to threats quickly, restoring operations and limiting the impact. You will guide efforts to assess how many systems are affected and assist recovery efforts. You'll combine threat intelligence, event data, and assessments from recent events to identify patterns and provide mitigation techniques and strategies. Finally, you will apply knowledge of attacker techniques to uncover threats by analyzing log data, and building and tuning detections. 

Qualifications

Qualifications:

6+ years of experience in modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), and operations incident response Experience with writing detections within SIEM solutions, including Splunk, ArcSight, ElasticSearch, or Azure Sentinel Experience with Intrusion Detection System or Intrusion Prevention System (IDS/IPS) monitoring Knowledge of the basic functions and configurations of Bro or Zeek Knowledge of OS internals, including Windows, Linux, or Mac Knowledge of common security threats and vulnerabilities Ability to perform Nessus scans and review results, firewall configurations, and Linux hosts for indicators of compromise and hardening of Linux systems TS/SCI clearance with a polygraph Bachelor's degree IAT Level II Certifications

Nice If You Have:

Experience in creating and debugging Splunk Dashboards and creating Snort rules  Experience with security subjects and trends, including digital forensics, reverse engineering, and penetration testing Experience with security principles in virtual and hosting software, including MISP, HIVE, CORTEX, WikiJS, VPN, and SecurityOnion Experience with leading teams in a technical capacity Experience with leveraging common scripting languages, including PowerShell or Python to parse logs and automate repeatable tasks Ability to use Splunk to hunt for indicators of compromise, create Splunk Dashboards, and review logs Ability to code or script using any language Ability to partner and collaborate with teams, both internal and external, including developers, vendors, analysts, tech leads, and project managers DOD 8570 CSSP Analyst Certification  GCIA, GSLC, GCIH, CISM, CISSP, or- CEH Certifications

Clearance Level

TS/SCI polygraph

Job Locations

US-MD-Annapolis Junction

Skills

SIEM, Intrusion Detection

  • Annapolis Junction, Maryland, United States MAXIMUS Full time

    We are seeking a highly skilled Facilities & Data Center Manager to join our team at MAXIMUS. This key role will play a pivotal part in ensuring the reliability, efficiency, and security of our mission-critical data center and facility operations.The successful candidate will be responsible for leading the management and operation of multiple data centers...


  • Annapolis Junction, Maryland, United States Insight Global Full time

    Data Center Operations TechnicianJob Summary: We are seeking a highly skilled Data Center Operations Technician to join our team at Insight Global. As a Data Center Operations Technician, you will be responsible for ensuring the smooth operation of our data center facilities.Key Responsibilities:Perform routine maintenance and repairs on data center...

  • Lead AI Engineer

    4 months ago


    Annapolis Junction, United States MITRE Full time

    Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work...


  • Annapolis Junction, Maryland, United States Dobbs Defense Solutions, LLC Full time

    Job Title: Data Center EngineerJob Summary:Dobbs Defense Solutions, LLC is seeking a skilled Data Center Engineer to manage and maintain our data center infrastructure and cloud-based services. The ideal candidate will have experience in designing, delivering, and optimizing virtual infrastructure services to improve security, availability, performance, and...


  • Annapolis Junction, Maryland, United States Microsoft Corporation Full time

    Job Summary:We are seeking a highly skilled Data Center Technician to join our team at Microsoft Corporation. As a Data Center Technician, you will play a critical role in delivering the core infrastructure and foundational technologies for our online services, including Bing, Office 365, Xbox, OneDrive, and the Microsoft Azure platform.Key...


  • Annapolis Junction, United States ELEVI Associates Full time

    Job DescriptionJob DescriptionIn Order to Join the ELEVI Team you will need to have the following You must be willing to work in the Annapolis Junction, MD, areaYou must have a current and active security clearance with polygraphFive (5) years of experience as an SWE in programs and contracts of similar scope, type, and complexity are required....


  • Annapolis Junction, United States Maximus Full time

    General information ...


  • Annapolis Junction, United States Maximus Full time

    General information ...


  • Annapolis Junction, United States MITRE Full time

    Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work...


  • Annapolis Junction, United States MSCCN Full time

    Description Are you passionate about creating innovative solutions that solve challenging National Security problems? Do you like helping customers envision new ways of securing a cloud infrastructure? Do you have ideas for new ways to experience security operations instead of traditional lecture and documented best practice? Amazon Web Services is looking...


  • Annapolis Junction, United States Transportation Security Administration Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment to safeguard the American way of life. In cities across the country, you would secure airports, seaports, railroads, highways, and/or public transit systems, thus protecting America's transportation infrastructure and...

  • Cyberspace Operations

    3 weeks ago


    Annapolis Junction, United States Huntington Ingalls Industries Full time

    Requisition Number: 18479 Required Travel: 0 - 10% Employment Type: Full Time/Salaried/Exempt Hours Per Week: 40.00 Security Clearance: TS/SCI with Poly Level of Experience: Mid Job Description Mission Technologies a division of HII - Cyber Electronic Warfare and Space (CEWS) provides full-spectrum cyber, EW and space capabilities that address...


  • Annapolis Junction, United States MITRE Full time

    Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work...


  • Annapolis Junction, Maryland, United States Leidos Full time

    Job Summary:A Senior Security Engineer is needed to provide support for adding new capabilities to a complex system with exacting interface, performance, and security requirements. The selected individual will become part of a team of Security Engineers working on solving challenging issues on a large, significant program. The position requires a solid...


  • Annapolis Junction, Maryland, United States Phoenix Operations Group Full time

    Job Description:As a Cloud Administrator at Phoenix Operations Group, you will be responsible for designing, implementing, and sustaining large multi-node clusters for enterprise applications. This role requires expertise in cloud provisioning technologies and automation tools to implement a robust solution that scales with our computing needs. A typical day...


  • Annapolis Junction, United States Maximus Full time

    General information ...


  • Annapolis Junction, United States Maximus Full time

    General information ...


  • Annapolis Junction, United States ARSIEM Corporation Full time

    About ARSIEM Corporation At ARSIEM Corporation we are committed to fostering a proven and trusted partnership with our government clients. We provide support to multiple agencies across the United States Government. ARSIEM has an experienced workforce of qualified professionals committed to providing the best possible support. As demand increases, ARSIEM...


  • Annapolis Junction, Maryland, United States Visionary Technology Consultants Full time

    Job DescriptionWe are seeking a highly skilled IT Security and Cloud Infrastructure professional to support our Nessus vulnerability scanning and configuration compliance scanning processes. The ideal candidate will contribute to the development of secure AWS instances and lead the deployment of new and emerging technologies.Key Responsibilities:Nessus...

  • Cyber Security Expert

    1 month ago


    Annapolis Junction, Maryland, United States The MITRE Corporation Full time

    Cyber New Professionals ProgramJoin a dynamic team of cybersecurity professionals at The MITRE Corporation, where you can develop your skills and expertise in a collaborative and innovative environment.As a Cyber New Professional, you will have the opportunity to work on a variety of projects that provide a breadth of experiences to develop into well-rounded...