Cybersecurity Data Analyst
Public Trust: None
Requisition Type: Regular
Your Impact
Own your opportunity to serve as a critical component of our nation’s safety and security. Make an impact by using your expertise to protect our country from threats.
Job Description
GDIT is seeking a motivated, career and customer-oriented Cybersecurity Data Analyst to perform on our Cybersecurity Data Analysis Services team in Saint Louis, MO.
The team member shall provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) capability (i.e. Enterprise Audit), long-term analytics platform, log aggregation platform, and the cyber threat intelligence capability, signature development and deployment, and reputation management services. This includes the onboarding of all new and existing IT resources, and ensuring the correct routing of all audit events to mission partners in accordance with Intelligence Community Standards (ICS) 500-27.
Job Duties Include:
- Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software
- Maintain system availability and reliability with a threshold of 99.99%
- Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation
- Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform
- Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management
- Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions
- Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.
- Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost)
- Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, polices, guidance, procedures etc.
- Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN – Joint Incident Management System, DoD CIO – DoD Scorecard/Get to Green reporting, IC CIO – Cybersecurity Performance Evaluation Model reporting, etc.)
- Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions
- Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services
Required Skills:
- SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)
- Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules
- Create SIEM playbooks
- Linux (RHEL) Expert (administration and engineering)
- Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives
- Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events
- Creation of ArcSight rules based on use cases of malicious events
- Tuning and aggregation of queries and filters
- Skilled in troubleshooting event flow through Enterprise Audit infrastructure
- Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools
- Active TS/SCI with POLY
- DoD 8570.01-M IAT Level II and CSSP Infrastructure Support certifications
- 6+ years Experience with SIEM and Development Projects
- 6+ years Experience with SIEM support for projects and technical exchange meetings
- 6+ years Experience developing and maintaining enterprise audit projects
Desired Skills:
- Kibana
- Data Analytics
Work Requirements
Years of Experience
6 + years of related experience
* may vary based on technical training, certification(s), or degree
Certification
CompTIA Project+ | CompTIA - CompTIA
Travel Required
None
Citizenship
U.S. Citizenship Required
Recommended Jobs
Virtual Store Support Operator (Remote)
Virtual Store Support Operator (Remote) Location Remote in Roanoke, VA : The Retail Customer Care Phone Support Operator is considered the front-line representative, providing best in class service t…
Software Engineer - Big Data Ingestion and Processing
About the Organization Now is a great time to join Redhorse Corporation. Redhorse specializes in developing and implementing creative strategies and solutions with private, state, and federal custom…
Kennel Attendant - West Chester Pet Resort
Overview: At West Chester Pet Resort , we’re more than a boarding and daycare facility; we’re a luxury retreat where pets come to play, relax, and be cared for like royalty. Our nearly 5-acre resor…
DESIGNER 4
Req ID: 43592 Team: E24 CVN MACH SYS&COMP Entity: Newport News Shipbuilding US Citizenship Required for this Position: Yes Full-Time Shift: 1st Relocation: No relocation assistance av…
Buffers Assessment Individual Placement - Appalachian Conservation Corps
Title: Buffers Assessment Intern Location: Mt. Crawford, VA Positions Available: 1 Internship Position Dates: June 24 – August 16(8 weeks) Pay Rate: $600/week and AmeriCorps Education A…
Software Test Engineer
APEX TK is seeking a highly experienced Software Test Engineer to join our team supporting a critical government client. This role will focus on ensuring the quality and reliability of complex space …
Fire Alarm Inspector IV
At Johnson Controls, we are dedicated to enhancing the functionality and safety of modern buildings through innovative and intelligent solutions. As a Fire Alarm Inspector IV, you will play a pivotal …
Part-Time Economic Analyst, TS/SCI
Description: Candidate sought to provide on-site technical SETA support. Supply chain disruptions impose enormous economic costs on businesses and consumers while threatening DOD readiness. B…
Production Technician
Job Title: Production Associate Job Description The New Hire Utility role involves learning to operate equipment associated with extrusion or tube mill processes and handling aluminum products.…
Sourcing Analyst
Public Trust: None Requisition Type: Regular Your Impact Own your opportunity to be at the center of GDIT’s business operations. Make an impact by collaborating across functions to make mi…