DMI logo
DMIPosted 1 month ago

SOC Analyst

On-siteCrownsville, Maryland, United States

Full TimeLarge

Job Summary

Monitor, protect, and defend the enterprise perimeter and internal networks against malicious traffic and emerging threats. Enrich monitoring logs with contextual data to correlate events, identify security issues, and validate incidents. Conduct threat hunting through activity logs, triage validated events, perform initial containment, and escalate for eradication. Review threat intelligence, search application and system logs to thwart identified threats, and prepare management reports. Develop SIEM correlation rules, contribute to Standard Operating Procedures, and participate in post-incident lessons learned. Partner with engineering to refine detection playbooks and provide technical recommendations for remediation.

Required Qualifications

  • Bachelor's degree from an accredited college or university with a major in computer science, information systems, engineering, business, or a related scientific or technical disciplines
  • CompTIA CySA+ certification/ or a CompTIA Security+ (or other relevant IAT Level II/III Certification)
  • one of the following: CEH, CFR, CCNA Cyber Ops, CCNA-Security, GCIA, GCIH, GICSP, Cloud+, SCYBER, PenTest+
  • Experience analyzing intrusion events such phishing emails, malware, privileges misuse, traffic indicating potential malicious activities such DoS/DDoS, brute force, data loss through exfiltration/ inadvertent disclosure
  • Applied experience of threat analysis model/frameworks such Cyber Kill Chain, MITRE ATT&CK, Diamond Model, Pyramid of Pain etc.
  • Working knowledge of advanced threat Tactics, Techniques and Procedures (TTPs)
  • Applied experience with network traffic analysis with tools like Wireshark
  • Applied experience with a variety of Opensource threat research tools/platforms such as Virus Total
  • Working knowledge of network and security architecture principles such as defense-in-depth
  • Experience with proprietary security protection/detections tools such as Firewall, Host and Network IDS/IPS, Anti-Virus, EDR, URL Filtering Gateways, Email Filtering Gateways, DLP tools, and SIEM tools such as Splunk etc.
  • Capable of working independently, establishing priorities and managing task completion within set SLAs
  • Able to communicate effectively through writing, speaking, and presenting to client technical representatives
  • Team player capable of productively contributing to the client mission by supporting fellow teammates in a dynamic growing and changing environment
  • Successful completion of a Fingerprint background investigation
  • Must be a U.S. Citizen
  • Location: Crownsville, MD (100% onsite) Day Shift/Night Shift

Desired Qualifications

  • Master's Degree is preferred
  • Experience with mid-to-advance level malware analysis
  • Experience creating detailed queries and scripts, such as regular expressions, for log, event and correlation analysis
  • Experience scripting in Python, PowerShell, VBScript

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce