SOC Analyst I
$80,538–$80,538 year
On-siteMonterey, California, United States
Job Summary
Track and report cyber security threats, events, and incidents while performing threat analysis and investigating security incidents. Identify the source, scope, and impact of incidents to provide initial response and containment measures, escalating to higher tiers as necessary. Utilize intrusion detection technologies to identify host and network-based threats, create and resolve incident tickets, and document all alerts. Capture, contain, and report malware using tools like NIPS and anti-malware software. Review SOC standard operating procedures and checklists to determine alert relevancy and urgency, transitioning events to the incident response process. Under supervision, manage and configure security monitoring tools including SIEM, IDS, and firewalls to mitigate threats. This team operates in a 24/7 shift environment with support from Monday through Thursday, 6:45am to 5:15pm PST.
Required Qualifications
- U.S. Citizen
- Active DOW Interim Secret or Secret Clearance
- At least one certification as required by Dept. of War (DoW) 8570.01-M and Department of War Directive 8140.01, IAT Level II or Higher OR have the ability to obtain within 6 months of hire
- At least one of the following certifications or have the ability to obtain within 6 months of hire: CompTIA CySA+, EC-Council CEH, GIAC GCIA, Microsoft AZ 900, Palo Alto Networks PCCET, or Splunk Core Certified Advanced Power User
- Minimum of one (1) year of professional experience in networking, UNIX/Linux system administration, software engineering, or software development
- Bachelor's degree in computer science, engineering, information technology, cybersecurity, or related field in place of the 1 year of experience
- Knowledge of or experience with Computer networking concepts, OSI model, and network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services, and network security
- Knowledge of or experience with Host/network access control mechanisms (e.g., access control list, capabilities lists)
- Knowledge of or experience with Network traffic analysis methods an packet-level
- Knowledge of or experience with Cyber threats and vulnerabilities; cyber-attack stages, classes of attacks and attackers; cyber defense and information security policies, procedures, and
- Knowledge of or experience with Incident response and handling methodologies, incident categories, and timelines for
- Knowledge of or experience with Intrusion detection methodologies and techniques for detecting host and network-based intrusions
- Knowledge of or experience with Malware analysis concepts and methodologies
- Knowledge of or experience with System administration, network, and operating system hardening techniques as well as data backup and
- Proficiency in at least one programming language
- Working understanding of computer forensic techniques and methodologies
- Availability for a 24/7 shift environment, specifically Monday - Thursday, 6:45am - 5:15pm PST
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.