Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Parental leave
- Relocation bonus
- Tuition assistance
- Vision insurance
Portfolio: Operations
Program: Monitoring and Detection
Location: Falls Church, VA or Remote
Requested start date: ASAP
Title: Threat Management Specialist (Tier 1)
Number of Resources: 1
PCTS Project # and Name: 127626 - OPS: M&D Gatehouse
Task description and/or any specific requirements:
Program: Monitoring and Detection
Location: Falls Church, VA or Remote
Requested start date: ASAP
Title: Threat Management Specialist (Tier 1)
Number of Resources: 1
PCTS Project # and Name: 127626 - OPS: M&D Gatehouse
Task description and/or any specific requirements:
Â
Threat Management Specialist (Tier 1)
High Level Description:
The Tier 1 Analysts receive all of the alerts from various sources, including SIEM, CSOC mailboxes, and phone calls directly from the central SIEM and handle as defined in Playbooks and SOPs. Tier 1 Analyst will escalate the events to Tier 2 after initial triage, along with providing input and analysis on how to leverage Artificial Intelligence, Machine Learning, and SOAR capabilities to improve CSOC efficiency and accuracy
Â
Key Responsibilities:
- Identification of security problems which may require mitigating controls
- Interpret output from the SIEM, CSOC mailboxes, and phone calls to identify potential security incidents
- Collect basic information to support analysis such as IP address, location, affected asset(s), etc.
- Escalate items which require further investigation to other members of the Threat Management team
- Execute operational processes in support of response efforts to identified security incidents
- Utilize AI/ML-based tools and techniques to detect anomalies, automate incident triage, and improve threat intelligence
- Performing and analyze threat intelligence to assess risk and adapt defenses using ML enhance tools
- Stay current on the latest cybersecurity trends, threat actors, and AI/ML research relevant to the field
- Identify and support automation use cases, including the use of AI/ML to enhance SOC capabilities.
- Collaborate across Operations to provide SOC enhancement capabilities through the use of automation and AI.
Â
Language Skills: English
Educational Requirements or Comparable work Experience:
- BA or BS in Computer Science, Information Technology or related field
- One or more relevant certifications such as CEH, CISSP, CompTIA Security+, or GCIH are advantageous.
Â
Qualifications Requirements:
- 1+ years’ experience in IT Operations
- 1+ year experience in IT Security
- Working knowledge of:
- Platform Security Basics
- Threat Lifecycle Management
- TCP / IP
- Incident Management
- Knowledge of Control Frameworks and Risk Management techniques
- Excellent oral and written communication skills
- Excellent interpersonal and organizational skills
- Familiarity with the application of AI/ML techniques in cybersecurity, including but not limited to automated threat detection, incident response automation, and predictive analytics. Experience in evaluating the effectiveness of AI/ML solutions in a SOC environment is a plus.
- Understanding of ethical AI principles and their implications in cybersecurity.
- Familiarity with cloud security (AWS, Azure, GCP)
- Understanding and experience identifying and implementing automation use cases.
Learn more about this Employer on their Career Site
