Cyber Security Operations Specialist, SPRINGFIELD, VA

SPRINGFIELD, VA General Dynamics Information Technology

LEARN MORE / APPLY

Req ID: RQ193821

Type of Requisition: Regular

Clearance Level Must Be Able to Obtain: Top Secret SCI + Polygraph

Public Trust/Other Required: None

Job Family: Cyber Security

Skills:

Cybersecurity,Cybersecurity Operations,SIEM Tools

Experience:

6 + years of related experience

US Citizenship Required:

Yes

Job Description:

GDIT is seeking a motivated, career and customer-oriented Cybersecurity Operations Specialist to perform on our Cybersecurity Data Analysis Services team in the Springfield, VA area.

The team member shall provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) capability (i.e. Enterprise Audit), long-term analytics platform, log aggregation platform, and the cyber threat intelligence capability, signature development and deployment, and reputation management services. This includes the onboarding of all new and existing IT resources, and ensuring the correct routing of all audit events to mission partners in accordance with Intelligence Community Standards (ICS) 500-27.

Job Duties Include:

Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software

Maintain system availability and reliability with a threshold of 99.99%

Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation

Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform

Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management

Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions

Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.

Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost)

Configure all assets assigned to this service within the Government Furnished Information – Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, polices, guidance, procedures etc.

Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information – Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN – Joint Incident Management System, DoD CIO – DoD Scorecard/Get to Green reporting, IC CIO – Cybersecurity Performance Evaluation Model reporting, etc.)

Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions

Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services

Required Skills:

SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)

Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules

Create SIEM playbooks

Linux (RHEL) Expert (administration and engineering)

Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives

Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events

Creation of ArcSight rules based on use cases of malicious events

Tuning and aggregation of queries and filters

Skilled in troubleshooting event flow through Enterprise Audit infrastructure

Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools

Active TS/SCI Clearance

DoD 8570.01-M IAT Level II and CSSP Infrastructure Support certifications

6+ years Experience with SIEM and Development Projects

6+ years Experience with SIEM support for projects and technical exchange meetings

6+ years Experience developing and maintaining enterprise audit projects

Desired Skills:

Kibana

Data Analytics

The likely salary range for this position is $91,811 – $112,700. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

We connect people with the most impactful client missions, creating an unparalleled work experience that allows them to see their impact every day. We create opportunities for our people to lead and learn simultaneously. From securing our nation’s most sensitive systems, to enabling digital transformation and cloud adoption, our people are the ones who make change real.

GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.

S:SKINTIAGP3

LEARN MORE / APPLY

General Dynamics Information Technology

BillGoldenJobs.com Jobs Careers

Job Hiring / SPRINGFIELD, VA / Cyber Security Operations Specialist / General Dynamics Information Technology >> APPLY/LEARN MORE >> https://de.jobsyn.org/6480962b34294291b86b560bf166d9168003 >> #job #jobs #hiring #BGJobs   

+++++++++++++++
? Looking for more jobs like this? Find more at CareerOneStop, sponsored by the U.S. Department of Labor Employment and Training Administration.
+++++++++++++++

US Work-eligible

SPRINGFIELD, VA

Share:

More Posts

BillGoldenJobs by IntelligenceCareers.com

Senior Strategic Policy Analyst, Strategic Planner 2, TAMPA FL

TS/SCI … Huntington Ingalls Industries / TAMPA FL … must have experience writing documents and briefing military General Flag Officers and other leadership within the Department of Defense. Track and analyze specific United States military activities the USCENTCOM area of responsibility, to include submissions from component commands and external agencies

BillGoldenJobs.com

Aeronautics Drone Internship Summer 2025, BOSTON MA

BS or Grad Student … State of Massachusetts / MassDOT Aeronautics Division … Opportunities exist for interns to support operational development of drone use cases – exploring how data collected by drones can meet MassDOT and MBTA needs, as well as develop data solutions to more efficiently ingest and analyze drone-collected data, and disseminate final data products to end users.

BillGoldenJobs by IntelligenceCareers.com

Summer Internship, Cyber Security, TAMPA FL

SECRET-clearable, Enrolled AS/BS program, GPA 3+ … SMX / TAMPA FL … Will work on a meaningful target project throughout the internship, culminating in a final project presentation to leadership

Send Us A Message

Cyber Security Operations Specialist, SPRINGFIELD, VA

US Work-eligible ... General Dynamics Information Technology / SPRINGFIELD, VA VA_SPRINGFIELD , , SKINT, SKCYB, 1/2/2025 16:24SKINTIAGP3
BillGoldenJobs.com

BillGoldenJobs is an IntelligenceCareers.com website
~~~ Focused on information-centric careers across all industries ~~~
Search Jobs / Hot Job Indexes / About