Cyber Defense Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cyber Defense Analyst (Cybersecurity): Providing cybersecurity monitoring and incident response for the SBA's SOC with an accent on threat analysis and cyber defense operations. Focus on identifying and mitigating cyber threats across enterprise, cloud, and hybrid environments to strengthen the agency's security posture.
Location: Must be based in the USA (Supporting SBA Enterprise Cybersecurity Services)
Company
provides enterprise cybersecurity services and SOC operations for government agencies.
What you will do
- Perform 24x7x365 cybersecurity monitoring, incident detection, triage, and response activities.
- Investigate cybersecurity incidents and suspicious events using SIEM, EDR, IDS/IPS, and threat intelligence platforms.
- Conduct log analysis, event correlation, and threat hunting to identify indicators of compromise.
- Support containment, eradication, remediation, and recovery activities during active incidents.
- Manage incident tickets and document findings, response actions, and operational recommendations.
- Provide operational security support for cloud environments including Microsoft Azure, AWS, and Microsoft 365.
Requirements
- Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related technical discipline.
- Minimum of 5 years of experience in cybersecurity operations, SOC analysis, or incident response.
- Experience with SIEM, EDR, IDS/IPS, and vulnerability management tools.
- Strong understanding of NIST SP 800-53 and NIST SP 800-61 federal frameworks.
- Experience supporting cloud security operations in AWS, Azure, or hybrid environments.
- Ability to work effectively in fast-paced environments supporting rotating SOC shifts.
Nice to have
- Certifications: CompTIA Security+, CySA+, GCIH, CEH, or GCIA.
- Splunk Core Certified User or other SIEM-related certifications.
- AWS Certified Security – Specialty or Microsoft Azure Security Engineer Associate.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →