Cyber Defense Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cyber Defense Analyst (SOC): Perform proactive monitoring, incident detection, triage, investigation, containment, and reporting of cybersecurity incidents across enterprise, cloud, and hybrid environments with an accent on threat analysis, log correlation, and vulnerability management. Focus on utilizing SIEM, EDR, IDS/IPS platforms, supporting 24x7x365 operations, and collaborating with SOC teams and stakeholders to strengthen security posture.
Location: US-based supporting SBA Enterprise Cybersecurity Services (ECS) SOC, federal cybersecurity standards (NIST, CISA).
Company
Incorporated supports the Small Business Administration (SBA) with enterprise cybersecurity services.
What you will do
- Perform cybersecurity monitoring, incident detection, triage, analysis, and response in 24x7x365 SOC operations.
- Monitor security alerts, analyze network, endpoint, cloud, and application activity for indicators of compromise.
- Investigate incidents using SIEM, EDR, IDS/IPS, firewall, and threat intelligence platforms.
- Support containment, eradication, remediation, recovery, and threat hunting activities.
- Document incidents, create reports, escalate based on severity, and coordinate with stakeholders.
- Assist with vulnerability management, cloud security (Azure, AWS, M365), and compliance.
Requirements
- Bachelor’s degree in Cybersecurity, IT, Computer Science or related; 5+ years in SOC analysis, cyber defense, or incident response.
- Experience with SIEM, EDR, IDS/IPS, vulnerability management, network security tools.
- Knowledge of incident response (NIST SP 800-61), threat analysis, log analysis, IOCs.
- Understanding of federal frameworks (NIST SP 800-53), cloud security (AWS, Azure, M365).
- Strong analytical, technical, communication skills; ability to work rotating SOC shifts.
Nice to have
- CompTIA Security+, CySA+; GIAC GCIH, GCIA; CEH; Splunk certification.
- AWS Certified Security – Specialty; Microsoft Azure Security Engineer Associate.
Culture & Benefits
- Work in fast-paced operational environment supporting federal cybersecurity mission.
- Collaborate with SOC personnel, incident responders, engineers, and government stakeholders.
- Participate in shift turnover briefings, exercises, COOP activities, and readiness initiatives.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →