Phone/Skype Hire. Mostly remote. The candidate needs to spend 1 week every 3 months at the client site.
Location: Columbia, SC / Remote
Duration: 12+ months
This specific Statement of Work is for a Cyber SOC Experienced Analyst to prevent, detect, investigate, and assist in directing remediation to cyber-attacks and threats against organization enterprise applications, networks, and services by investigating indicators of suspicious and malicious activity, and proactively discovering threats to organization. Individual must have at least 7 years' experience in Security with a MINIMUM of 5 years hands on working with a SIEM creating offenses, alerts and grooming logs. Preference is an individual who has experience leading a CSIRT, CERT, SOC or Investigations team. SIEM preference is QRadar or Azure Sentinel.
This position requires previous security operational center experience - monitoring, investigating, alerting, and reporting security threats. It also requires previous experience in developing SOPs and documentation.
Candidate will be required to explain previous experience in the following:
You will have a technical role, supporting the SOC Analysts to find the threat actors attempting to attack infrastructure. You will need to be a technical and professional leader, someone who enjoys training and mentoring teammates, and a person who can encourage and elevate the team.
Under general supervision, the contractor will serve as an analyst reporting directly to a functional manager. Contractor will be a team member that ensures the stability and integrity of data, and server services through monitoring, maintenance, support, and optimization of all server infrastructure. This individual has 24/7 on-call responsibilities shared with the group. This position can be remote, but we require contractor to report on-site for one week each quarter at vendor's expense.
Responsibilities:
Proactively search for active intrusions in the environment, recognizing potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information
Skills Needed
Required Education/Certifications:
Seven (7) years of experience in security information technology systems or related area, with a minimum of 5 years utilizing SIEM technology.
Cloud Certifications
Microsoft Certifications, Azure, Security related
GCIH, GCTI, GCCC, GCWN, GSEC, CEH, GCIA, GCFA, GCFE, GREM, CCIM, CFCE, CCE, CIFI, CHFI, CCNA, CCNA Cyber Ops
IBM Certified Associate Analyst - Security QRadar SIEM