5 дней назад
Cyber Real-Time Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Real-Time Analyst (Cybersecurity): Monitoring and defending Joint Fires Network environments in a 24/7/365 SOC with an accent on real-time alert triage, incident response, SIEM operations, and classified DoD networks. Focus on tuning Corelight and Elastic Defend sensors, developing behavioral threat-hunting playbooks, and executing response procedures in TS/SCI SCIF facilities.
Location: Full-time onsite in Ford Island, Hawaii; telework is not permitted. The role requires 24/7/365 rotating shifts in a secure SCIF. Relocation expenses may be eligible for reimbursement.
Company
provides security compliance, program governance, consulting, and customized technology solutions for public sector clients.
What you will do
- Monitor Joint Fires Network transport components, edge nodes, and management channels around the clock; triage alerts and investigate anomalies.
- Review syslogs, verify ingestion pipelines, correlate events, and identify malicious activity, configuration drift, and indicators of compromise.
- Operate Elastic SIEM and Elastic Defend, analyze Kibana dashboards, write KQL queries, and manage incident workflows in JIRA.
- Support development, testing, and execution of the JFN Incident Response Plan and DIA-aligned TS/SCI incident reporting.
- Tune Corelight, Darktrace, and related security sensors while developing threat-hunting, containment, and remediation playbooks.
- Coordinate with NOC engineers, DISA defenders, NIWC data-pipeline engineers, and other mission stakeholders.
Requirements
- U.S. citizenship and an active Top Secret clearance with current SCI eligibility are required before starting.
- Level II qualification: a relevant bachelor’s degree and 2+ years of SOC or defensive cyber operations experience, or equivalent associate-degree or experience pathways.
- An active DoD 8140.03 / DCWF Work Role Code 531 Cyber Defense Analyst certification or qualifying degree at the Intermediate Proficiency Level is required.
- Hands-on experience in a live 24/7/365 SOC with event correlation, alert triage, intrusion analysis, and SIEM operations.
- Practical knowledge of Elasticsearch, Logstash, Kibana, Elastic Defend, KQL, JIRA, network protocols, packet inspection, and syslog parsing.
- Ability and willingness to work rotating days, nights, weekends, and holidays onsite inside a secure SCIF.
Nice to have
- Experience with DoD IL-6/7 networks, SIPRNet, TS/SCI or JWICS enclaves, C4ISR systems, or joint tactical environments.
- Experience with Corelight/Zeek, Darktrace MDR, Palo Alto ATP logs, or MITRE ATT&CK detection logic.
- Level III experience: a technical bachelor’s degree with 4+ years of SOC/CND experience or equivalent pathways.
Culture & Benefits
- Medical, dental, and vision coverage with multiple medical plan options.
- Paid time off, paid holidays, and paid parental leave.
- Pre-tax and Roth retirement savings accounts, life insurance, and disability coverage.
- Tuition and training reimbursement, flexible and dependent care savings accounts, and an employee assistance program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Cyber Security Analyst, Senior (High Level Clearance Required)
108 476 - 184 409$
12 дней назад
Sr. IR Specialist (Cyber Threat Intelligence)
99 000 - 206 000$
7 дней назад
Cyber Security Analyst - Sr. Consultant Level (Cybersecurity)
152 200 - 243 700$
12 дней назад
Tier 3 Security Analyst (AI)
140 000 - 152 000$
6 дней назад
SNOC Engineer III (Cybersecurity)
105 000$
CrowdStrike
7 дней назад
Analyst I, Falcon Complete (Cybersecurity)
85 000 - 120 000$