Summary
EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support for critical U.S. government missions. The Security Operations Center Analyst will support U.S. Cyber Command by analyzing logs, forensic data, and threat intelligence to identify advanced cyber threats, perform complex incident response, and recommend ways to harden networks.
Responsibilities
- Are you ready to take a strategic role in cyber defense for U.S Cyber Command? Do you want to use your experience-based knowledge to protect critical warfighter infrastructure from the constant onslaught of cyber threats? If you want a position that uses your extensive threat analysis skills to perform advanced threat identification and complex incident response, you want to be a SOC analyst. As an analyst on our SOC team, you’ll analyze logs, forensic data, and threat intelligence to find the advanced threats that are escaping detection. Using your deep understanding of your customer’s networks, combined with your cybersecurity experience, you’ll analyze patterns to understand attackers’ goals and stop them from succeeding. Once you find the adversary in the SEIM’s blind spot, you’ll advise on ways to close the gaps and harden their network. Let’s outsmart malicious actors and protect U.S. Cyber Command
- Join us. The world can’t wait
Skills
- Experience with SIEM Fundamentals, including Splunk
- Knowledge of basic networking fundamentals
- Knowledge of the basic functions and configurations of Bro (Zeek)
- Knowledge of Suricata or Snort
- Ability to review Nessus scans and Firewall configurations
- Ability to review Linux hosts for indicators of compromise and hardening of Linux systems
- Ability to navigate \•nix based systems via CLI
- Ability to find, read, and analyze various logs
- TS/SCI clearance with a polygraph
- HS diploma or GED and 6+ years of experience with incident response procedures and analysis, or Bachelor's degree and 2+ years of experience with incident response procedures and analysis
- Experience with correlating threat intelligence (INTEL) to determine the threat actor, the attack's scope, and the affected systems
- Experience with AI Fundamentals
- Knowledge of Splunk Phantom or SOAR
Qualifications
Must Haves
- Experience with SIEM Fundamentals, including Splunk
- Knowledge of basic networking fundamentals
- Knowledge of the basic functions and configurations of Bro (Zeek)
- Knowledge of Suricata or Snort
- Ability to review Nessus scans and Firewall configurations
- Ability to review Linux hosts for indicators of compromise and hardening of Linux systems
- Ability to navigate \•nix based systems via CLI
- Ability to find, read, and analyze various logs
- TS/SCI clearance with a polygraph
- HS diploma or GED and 6+ years of experience with incident response procedures and analysis, or Bachelor's degree and 2+ years of experience with incident response procedures and analysis
Nice to Haves
- Experience with correlating threat intelligence (INTEL) to determine the threat actor, the attack's scope, and the affected systems
- Experience with AI Fundamentals
- Knowledge of Splunk Phantom or SOAR