Summary
AMERICAN SYSTEMS is a company focused on innovation and customer success, recently expanded by joining with Epsilon, Inc. The SOC Analyst I role involves providing tier I cybersecurity support in a Security Operations Center environment by tracking, analyzing, and responding to cybersecurity threats and incidents. The position requires collaboration with other SOC personnel to ensure effective incident handling and escalation when necessary.
Responsibilities
- Use intrusion detection technologies to apply techniques for identifying host and network-based
- Create, update, and resolve incident tickets that have been tasked to Tier I and appropriately document all alerts and incidents in the ticketing
- Create new incident tickets for alerts that signal an incident requiring escalation for Tier 2 review
- Identify, capture, contain, and report malware to protect networks (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters)
- Recognize and categorize types of vulnerabilities and associated
- Utilize the SOC standard operating procedures (SOP) to perform daily tasks, resolve incidents and preserve evidence integrity. May provide input for and assist with updating procedures
- Perform damage assessments, secure network communications, and use security event correlation
- Utilize the SOC checklist when reviewing the latest alerts and events from various SOC sensors to determine relevancy and urgency
- Review open source and other sources of information to identify events that should be transitioned into the incident response process
- Under supervision, may manage and configure security monitoring tools (SIEM, IDS, Firewall, Access Control Lists, etc.) to mitigate existing threats and vulnerabilities
- May assist with the design of incident response for cloud service models
Skills
- Must be a U.S. Citizen
- Must hold an active DOW Interim Secret or Secret Clearance
- Must hold at least one certification as required by Dept. of War (DoW) 8570.01-M and Department of War Directive 8140.01, IAT Level II or Higher OR have the ability to obtain within 6 months of hire
- Must hold at least one of the following certifications or have the ability to obtain within 6 months of hire: CompTIA CySA+, EC-Council CEH, GIAC GCIA, Microsoft AZ 900, Palo Alto Networks PCCET, or Splunk Core Certified Advanced Power User
- Must have a minimum of one (1) year of professional experience in networking, UNIX/Linux system administration, software engineering, or software development
- Will accept a bachelor's degree in computer science, engineering, information technology, cybersecurity, or related field in place of the 1 year of experience
- Knowledge of or experience with some of the following: Computer networking concepts, OSI model, and network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services, and network security
- Knowledge of or experience with some of the following: Host/network access control mechanisms (e.g., access control list, capabilities lists)
- Knowledge of or experience with some of the following: Network traffic analysis methods and packet-level
- Knowledge of or experience with some of the following: Cyber threats and vulnerabilities; cyber-attack stages, classes of attacks and attackers; cyber defense and information security policies, procedures, and
- Knowledge of or experience with some of the following: Incident response and handling methodologies, incident categories, and timelines for
- Knowledge of or experience with some of the following: Intrusion detection methodologies and techniques for detecting host and network-based intrusions
- Knowledge of or experience with some of the following: Malware analysis concepts and methodologies
- Knowledge of or experience with some of the following: System administration, network, and operating system hardening techniques as well as data backup and
- Proficient in at least one programming language
- Working understanding of computer forensic techniques and methodologies
Qualifications
Must Haves
- Must be a U.S. Citizen
- Must hold an active DOW Interim Secret or Secret Clearance
- Must hold at least one certification as required by Dept. of War (DoW) 8570.01-M and Department of War Directive 8140.01, IAT Level II or Higher OR have the ability to obtain within 6 months of hire
- Must hold at least one of the following certifications or have the ability to obtain within 6 months of hire: CompTIA CySA+, EC-Council CEH, GIAC GCIA, Microsoft AZ 900, Palo Alto Networks PCCET, or Splunk Core Certified Advanced Power User
- Must have a minimum of one (1) year of professional experience in networking, UNIX/Linux system administration, software engineering, or software development
- Will accept a bachelor's degree in computer science, engineering, information technology, cybersecurity, or related field in place of the 1 year of experience
- Knowledge of or experience with some of the following: Computer networking concepts, OSI model, and network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services, and network security
- Knowledge of or experience with some of the following: Host/network access control mechanisms (e.g., access control list, capabilities lists)
- Knowledge of or experience with some of the following: Network traffic analysis methods and packet-level
- Knowledge of or experience with some of the following: Cyber threats and vulnerabilities; cyber-attack stages, classes of attacks and attackers; cyber defense and information security policies, procedures, and
- Knowledge of or experience with some of the following: Incident response and handling methodologies, incident categories, and timelines for
- Knowledge of or experience with some of the following: Intrusion detection methodologies and techniques for detecting host and network-based intrusions
- Knowledge of or experience with some of the following: Malware analysis concepts and methodologies
- Knowledge of or experience with some of the following: System administration, network, and operating system hardening techniques as well as data backup and
- Proficient in at least one programming language
- Working understanding of computer forensic techniques and methodologies
Benefits
- Healthcare benefits
- Paid leave
- Retirement plans
- Insurance programs
- Education and training assistance