Cybersecurity Incident Response & Threat Detection Analyst
Goldbelt, Inc. Columbus, Ohio, United States
Health and Human Services · 201-500 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The analyst will perform 24/7/365 monitoring of SIEM tools to detect, analyze, and respond to cybersecurity threats within the enterprise network. They will also provide technical analysis and sustainment support for cybersecurity tools and implement defense-in-depth signatures.
What they look for
Requirements
Candidates must have at least five years of relevant experience, including two years of root cause analysis of cybersecurity incidents. A DOD Top Secret clearance with eligibility for IT-1 and SCI access is mandatory.
Benefits
Full description
Overview
Please note that this position is contingent upon the successful award of a contract currently under bid.
Global in service but local in approach, Nisga'a Tek is committed to high-quality service to those who defend us. Nisga'a Tek ensures mission assurance and execution for customers and warfighters. Providing intelligence, IT, cyber security, training, logistics, administrative, acquisition, and background investigation services.
Summary:
The Cybersecurity Incident Response & Threat Detection Analyst participates in 24x7x365 monitoring of SIEM and other cybersecurity monitoring tools to detect and respond to cybersecurity threats within the Enterprise Network Environment.
Responsibilities
Essential Job Functions:
- Performs actions to protect, monitor, detect, analyze, and respond to unauthorized activity.
- Employs Cybersecurity capabilities and deliberate actions to respond to specific alerts or emerging threats.
- Reviews logged events for trends that are indicative of attack or compromise within the environment.
- Actively monitors logs and traffic for Advanced Persistent Threats (APT) and "low and slow" attacks within the environment.
- Maintains awareness of possible threats with the use of intelligence resources which include Open Source Intelligence (OSINT).
- Provides technical analysis and sustainment support for the enterprise for Cybersecurity tools and applications and assists with the application of Defense-In-Depth signatures and perimeter defense controls to diminish network threats.
- Perform other duties as needed or required.
Qualifications
Necessary Skills and Knowledge:
- Working knowledge of at least two types of security tools: Firewall, IDS/IPS, Host based antivirus, Data loss prevention, Vulnerability Management, Forensics, Malware Analysis, Device Hardening
- Ability to build scripts and tools to enhance threat detection and incident response capabilities (Preferably in SPL, Python, PowerShell)
- Understanding of Defense-in-Depth
- Analytical skills to resolve issues effectively and efficiently.
- Demonstrated ability to work well with diverse teams and individuals.
Minimum Qualifications:
- Five (5) years relevant experience
- Two (2) years performing root cause analysis of cybersecurity events and incidents.
- Must possess IT-I Critical Sensitive security clearance or Tier 5 (T5) at time of proposal submission.
- Must possess a DOD TOP SECRET Clearance and be eligible for an IT-1 and be eligible for SCI access.
Preferred Qualifications:
- Bachelor’s degree in a related field.
Pay and Benefits
The annual salary range for this position is $87,000 to $160,000.
At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.
Similar roles
-
Mainframe Security Engineer - Logical Security
Ensono Chennai, Tamil Nadu, India
-
RMF and Cybersecurity Lead
Amyx, Inc. O'Fallon, Illinois, United States
-
Cybersecurity Engineer 6
M.C. Dean, Inc Chantilly, Hauts-de-France, France
-
Cybersecurity - Summer 2027 Internships
Rivian Plymouth, England, United Kingdom
-
Cybersecurity Systems Engineer
Arcfield Chantilly, Virginia, United States
-
Cybersecurity Analyst
Kearney & Company Alexandria, Virginia, United States