Salary
💰 $102,000 - $170,000 per year
Tech Stack
AWSAzureCloudCyber SecurityFirewallsSplunk
About the role
- Enhance SIEM and tool monitoring, tuning, detection, and alerting across multiple domains to support cyber incident response capabilities and tooling
- Identify, analyze, and mitigate security threats across the Guidehouse environment to protect Guidehouse and Client data within systems, networks, and cloud environments
- Mentor and work with SOC analysts to increase knowledge and skill with detection techniques and other SecOps technologies
- Participate on IT Security projects to enhance IT Security capabilities, improve monitoring coverage, drive detection and threat hunting efforts
- Apply technical knowledge and experience to drive innovation and performance improvement while demonstrating critical thinking, problem solving, and sound logic when assessing problems and opportunities
- Assist with issue resolution, risk mitigation and contingency planning in alignment with IT Security risk mitigation plans
- Use critical thinking, analysis, expertise, and collaboration to develop technical solutions and solve problems
- Mentor, train, and guide IT Security technical staff across the organization, fostering a culture of technical excellence, continuous learning, and security-first principles
- Promote the development of new technical knowledge and skills within IT Security Operations team
- Take ownership of tasks, resolving issues, prioritizing in a fast-paced environment, escalating as appropriate
- Stay current on cybersecurity events, trends, and issues and map issues to prescribed IT Security policies, procedures, and standards
Requirements
- Bachelor’s degree plus 6 years of experience; OR 10+ Years of experience in lieu of degree
- United States Citizenship
- Must be able to work East Coast US business hours
- Experience supporting Microsoft Windows operating systems
- Familiar with Microsoft Azure, M365, and AWS cloud environments
- Knowledge of the MITRE ATT&CK framework
- Experience working with Security Operation Centers, physically or virtually
- Experience executing processes and procedures in compliance with required NIST, regulatory, and IT standards
- Experience using a SIEM, such as Splunk, developing queries with Search Processing Language (SPL) or Kusto Query Language (KQL)
- Experience with SIEMs, SOAR technologies, IR tools and processes, programming/scripting, threat hunting, log ingestion, and SIEM detection engineering/tuning
- Demonstrates effective written and verbal communication skills
- Action-oriented and able to manage and meet aggressive timelines and deadlines
- Excellent organizational and time management skills
- Preferred: Degree in computer-related or cyber field
- Preferred: Working knowledge of NIST SP 800-171, NIST 800-61, and NIST SP 800-53
- Preferred: Experience in application security, security architecture, security code reviews, security/pen-testing, cloud security, cyber threat intelligence, incident response, or security infrastructure
- Preferred: Experience interpreting vulnerability scan data and CVEs, foundational understanding of risk management
- Preferred: Demonstrated knowledge of adversary TTPs
- Preferred: Experience working with Executive Leadership
- Preferred: Active US government security clearance (DoE, DoD, etc.)
- Preferred certifications: CISSP, GIAC (e.g., GCIH, GCFA), OSCP, CEH, CompTIA Security+
- Preferred: AWS and/or Azure Cloud
- Preferred: Experience working with firewalls/web application firewalls, implementing changes, and monitoring status
- Preferred: Experience conducting Incident Response and Security Investigations
- Preferred: Working knowledge of Active Directory, Exchange, SharePoint, and Teams
- Preference will be given to candidates who are located within 50 miles of a Guidehouse office.