Job Description
The ArcSight Analyst will use various tools to perform Tier 2 review of events, escalate incidents as warranted and assist the Incident ResponseHBSSACAS teams in responding to alerts and cybersecurity investigations. Specific job duties include Constant monitoring of intrusion detection systems using SIEM tools Performing independent research and analysis of security threats Coordinating with other teams to analyze, investigate and remediate detected incidents Analyzing and evaluating anomalous network and system activity Recommending modifications to security tools to better detect, prevent, and mitigate intrusions Knowledge of computer network defense and vulnerability assessment tools, including open source tools, and their capabilities Monitoring event alerts and performing Tier 2 categorization of suspicious activity, escalating as appropriate Investigating anomalous, suspicious, or malicious log entries or alerts Conducting security event collection using log management tools, initiate event management, and leverage identity monitoring activities Knowledge and understanding of networking, network layers, protocols, devices and multiple operating systems Performing networksystemapplicationlog intrusion detection analysis and trending Developing dashboards and reports for IA management and system monitoring Required SkillsQualifications Bachelor degree or equivalent experience IAT Level II Baseline Certification (one of the following) Security+ CE CCNA Security GICSP GSEC CND SSCP Must be a and have a Secret clearance with SSBIT5 able to obtain Top Secret Excellent communication, analytical, and troubleshooting skills Desired SkillsQualifications Well-rounded skillset with experience in various computer environments and multiple toolsets for cross-training within the DMDC environment SIEM experience (ArcSight preferred, HBSS, ACAS) TSSCI Eligible Technical writing and organizational skills
Posting ID: 596709964Posted: 2021-01-05