Jobs and Careers
PE

Senior SOC Analyst

Peraton
Washington, United Statesfull_timeVerifiedPosted 30 Jul 2024
💰 $166,000/yr($104,000/yr$166,000/yr)

About the role

Responsibilities

Work Location: Hybrid: remote AND at least two days per week in GSA, Washington, DC.

 

Requirements

A Senior Security Operations Center (SOC) Analyst/Cybersecurity Engineer (“Senior SOC Analyst”) to be part of the Presidential Transition Team Program for General Services Administration (GSA). This position will provide hands-on expertise in support of NOC/SOC, PTT IRT, and Cloud Architecture Team, including monitoring, reporting, threat intelligence, threat hunting and incident response. This position will partner with M365, Intune, and Citrix engineering teams in the design and review of projects with respect to implementation of security requirements (e.g., logging, authentication, alerting, etc.). The primary responsibility of this position will be the administration of Continuous Diagnostics and Mitigation (CDM) tools including Qualys and CrowdStrike. Experience with integration of ServiceNow with CDM tools (Qualys) for the purpose of automation and reporting is highly desirable but not required. The candidate should also have experience with the deployment and administration of Endpoint Detection and Response (EDR) systems including CrowdStrike Falcon. The engineer should have experience conducting regular audits to ensure security controls such as CrowdStrike and our Qualys vulnerability software are functioning as expected. In addition to audits, this position will test for vulnerabilities by conducting regular scans of networks using Qualys vulnerability scanning platform and works with third party vendors during annual security assessments and testing. Knowledge of how to set up Qualys Patch Management (PM) will be greatly needed as the engineer will have to scan for the vulnerabilities and then work to patch them, meeting with the engineers in the different groups to get this accomplished.

This is a highly technical role that requires a solid understanding of security systems, capabilities, and best practices. As part of a growing team this role will have the ability to leverage and work with new capabilities as they are deployed including working with groups which will be doing penetration testing, Tabletop exercises, and data loss prevention (DLP). This role is expected to contribute to maturing the overall IR and security capability through experience and recommendations at every level of security. The development of Standard Operating Procedure (SOP)(s) will be asked to be created as the ability to train others to do the job duties and tasks assigned.

 Responsibilities

  • Rollout Policy Compliance in Qualys for in-scope technologies, aligning to CIS benchmarks.
  • Facilitate the patch management of all vulnerabilities within the network utilizing Qualys PM.
  • Fine-tune controls within Qualys to meet the client standards
  • Ability to analyze the differences in Qualys CIDs between DISA STIG & CIS frameworks, articulate differences to stakeholders, and work with the technology owners to get them to comply to the agreed upon baselines
  • Ability to utilize Qualys TotalCloud to scan Infrastructure as a Code (IaC) scanning in Azure (Terraform)
  • Provide Qualys SME advisory
  • Execute weekly BAU activities as directed by the client
  • Extensive experience configuring, managing, and troubleshooting the Qualys VM, PC, Web Application Scanner, and Container Security modules.
  • In-depth knowledge of Qualys dashboarding, reporting and data analysis functionalities.
  • Experience with Qualys APIs for automation and integration purposes.
  • Creating reports in CrowdStrike for daily and weekly delivery.
  • Troubleshooting and remediation of findings from CrowdStrike Falcon and working with support engineers to resolve all findings.
  • Demonstrate strong understanding of large-scale information technology systems, business processes, security regulatory risk management and security vulnerabilities
  • Understand clients' business environment and IT risk management approaches
  • Compose and deliver executive-level reports, presentations, and give after action reports (AAR) to key stakeholders.
  • Provide relevant, strategic recommendations to help improve the security posture of the organization during and after an incident.
  • Analyze emerging threats to improve and maintain the detection and response capabilities of the organization.
  • SIEM and XDR detections
  • Security orchestration, automation, and response (SOAR) playbook development
  • Apply knowledge of monitoring, analyzing, detecting, and responding to cyber events to develop clever, efficient methods and technology to detect all types of threat.
  • Communicate clearly and concisely with managers and colleagues.

 

Qualifications

5 years with BS/BA;  H

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Peraton

View company profile →