Description
Job Description:
The Transportation and Border Security Services (T&BSS) Division has an opening in Northern Virginia for a Security Analyst to support our TSA customer in their Security Operations Center. Primary Responsibilities
Must possess strong organizational, analytical and attention to detail skills Must have the ability and prior experience with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes the identification of malicious code present within a computer system as well identification of malicious activities that are present within a computer system and/or enterprise network. Must have experience working with a ticket management system to collect, document and maintain information pertinent to security investigations and incidents Must possess excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings Must possess experience in monitoring the operational status of monitoring components and escalating and reporting outages of the components Must possess a working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks. A conceptual understanding of Windows Active Directory is also required. Must possess a working knowledge of Enterprise Network Architectures, common protocols, and devices (Firewalls, Proxies, Load Balancers, VPN, etc) Must possess a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.) Must have experience working with various event logging systems and must be proficient in the review of security event log analysis. Previous experience with Security Information and Event Monitoring (SIEM) platforms that perform log collection, analysis, correlation, and alerting is also required. Must have experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment Must possess experience in collecting and maintaining information pertinent to security investigations and incidents in a format that supports analysis, situational awareness reporting, and law enforcement investigation efforts Capable of recognizing suspicious activity/events, common attacker TTPs, and perform logical analysis and research to determine root cause and scope of Incidents Recognize attacker tactics, techniques, and procedures as potential indicators of compromise (IOCs) Normal working hours of 8:00am - 5:00pm are anticipated, however actual hours may vary depending on mission requirements
Basic Qualifications
Years of Experience: At least three years of experience working in a network security operations center environment performing security event monitoring and analysis Education: Bachelor's Degree in Information Technology or related disciplines; or have equivalent and direct experience working in a network security operations center environment performing security event monitoring and analysis Certification: Security+, GSEC or equivalent certification is desired. Clearance Requirements: SECRET
Preferred Qualifications
Ability to maintain alert quantity and quality by making recommendations and/or perform tuning across multiple security tools and SIEM Familiarity with Incident Response and Attacker lifecycles Certification: Security+, GSEC or equivalent certification; CCNA, Splunk Power User, CySA+ is desired.
Pay Range:Pay Range $60,450.00 - $93,000.00 - $125,550.00
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
|