Job Requirements
Columbus, OH
Top Secret/SCI Polygraph Unspecified
Career Level not specified
$120,000 - $145,000
Job Description
SarelaTech is seeking an experienced Cybersecurity Incident Response & Threat Detection Analyst to support a Department of War (DoW) cybersecurity mission in Columbus, Ohio. This position will participate in 24x7x365 monitoring of Security Information and Event Management (SIEM) and other cybersecurity monitoring tools to detect and respond to cybersecurity threats within the enterprise network environment.
The Cybersecurity Incident Response & Threat Detection Analyst will perform actions to protect, monitor, detect, analyze, and respond to unauthorized activity and employ cybersecurity capabilities and deliberate actions in response to specific alerts and emerging threats.
The position will review logged events for trends indicative of attack or compromise and actively monitor logs and network traffic for Advanced Persistent Threats (APT) and "low and slow" attacks. The analyst will maintain awareness of potential threats through intelligence resources, including Open Source Intelligence (OSINT).
The position will also provide technical analysis and sustainment support for enterprise cybersecurity tools and applications and assist with the application of Defense-in-Depth signatures and perimeter defense controls to reduce network threats.
Required Qualifications:
Certifications:
Must possess:
Security Clearance:
Compensation: $120,000.00 - $145,000.00 per year
We are an equal opportunity employer. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on any basis or status protected under federal, state, or local law
The Cybersecurity Incident Response & Threat Detection Analyst will perform actions to protect, monitor, detect, analyze, and respond to unauthorized activity and employ cybersecurity capabilities and deliberate actions in response to specific alerts and emerging threats.
The position will review logged events for trends indicative of attack or compromise and actively monitor logs and network traffic for Advanced Persistent Threats (APT) and "low and slow" attacks. The analyst will maintain awareness of potential threats through intelligence resources, including Open Source Intelligence (OSINT).
The position will also provide technical analysis and sustainment support for enterprise cybersecurity tools and applications and assist with the application of Defense-in-Depth signatures and perimeter defense controls to reduce network threats.
Required Qualifications:
- Five (5) years of relevant experience.
- Two (2) years of experience performing root cause analysis of cybersecurity events and incidents.
- Working knowledge of at least two (2) of the following security tool areas
- Firewalls
- Intrusion Detection/Prevention Systems (IDS/IPS)
- Host-based antivirus
- Data Loss Prevention (DLP)
- Vulnerability Management
- Digital Forensics
- Malware Analysis
- Device Hardening
- Understanding of Defense-in-Depth.
- Ability to build scripts and tools to enhance threat detection and incident response capabilities, preferably using SPL, Python, or PowerShell.
Certifications:
Must possess:
- CompTIA Security+; and
- At least one current certification meeting DoD 8570/8140 Cybersecurity Service Provider Incident Responder (CSSP-IR) requirements, including:
- Certified Ethical Hacker (CEH)
- CyberSec First Responder (CFR)
- Cisco Certified CyberOps Associate
- Computer Hacking Forensic Investigator (CHFI)
- CompTIA Cybersecurity Analyst (CySA+)
- CompTIA PenTest+
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Incident Handler (GCIH)
- Systems Security Certified Practitioner (SSCP)
Security Clearance:
- Active DoD TS/SCI clearance.
Compensation: $120,000.00 - $145,000.00 per year
We are an equal opportunity employer. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on any basis or status protected under federal, state, or local law
group id: 91132447