Cyber Data Analytics, TS/SCI (NoVA)

Posted 8 Days Ago
Be an Early Applicant
Springfield, VA
Entry level
Cybersecurity
The Role
Provide cybersecurity data analysis services related to SIEM systems, ensuring reliable and secure service availability. Responsibilities include maintenance, testing, configuration, and integration of cybersecurity tools, as well as ensuring data flows for internal and external reporting systems. Implement emergency maintenance and keep documentation updated.
Summary Generated by Built In

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

An active Top Secret/SCI clearance is required prior to consideration for this role. Work is 100% onsite.

GPS is seeking a motivated, career and customer-oriented Cybersecurity Operations Specialist to perform on our Cybersecurity Data Analysis Services team in Saint Louis, MO or Springfield VA.

The team member shall provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) systems (Splunk, Elastic and/or ArcSight), log aggregation platform, and reputation management services. This includes the onboarding of all new and existing IT resources, and ensuring the correct routing of all audit and security events to mission partners.

What You’ll Get to Do

  • Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software
  • Maintain system availability and reliability with required SLA
  • Detect and ticket degradations (volume/velocity) of all SIEM data flows within required SLA of the start of the degradation
  • Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform
  • Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations,

More About the Role

  • Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions
  • Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.
  • Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, policies, guidance, procedures etc.
  • Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN – Joint Incident Management System, DoD CIO – DoD Scorecard/Get to Green reporting, IC CIO – Cybersecurity Performance Evaluation Model reporting, etc.)
  • Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions

Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services

Skills needed for success

  • Midlevel to advanced Linux administration experience (RHEL preferred) 
  • SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)
  • Creating alerting rules
  • Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives
  • Tuning and aggregation of queries and filters
  • Skilled in troubleshooting event flow through an Enterprise Audit infrastructure
  • Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools
  • Active TS/SCI Clearance
  • DoD 8570.01-M IAT Level II and CSSP Infrastructure Support certifications
  • Experience with SIEM and Development Projects
  • Experience with SIEM support for projects and technical exchange meetings

Additional Qualifications a plus

  • Kibana
  • Cribl
  • Experience developing and maintaining enterprise audit projects
  • Creation of ArcSight rules based on use cases of malicious events
  • Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events
  • Data Analytics


We use Greenhouse Software as our applicant tracking system and Free Busy for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?
GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1000 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 4,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family) and GPS will contribute in one lump sum: ($500 per EE annually / $1000 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option


Top Skills

SIEM
The Company
HQ: Herndon, VA
875 Employees
On-site Workplace
Year Founded: 2011

What We Do

GuidePoint Security is an elite team of highly trained, top certified experts who cut through cyber chaos and confusion to put control back in your hands. We help you make the smartest, most informed decisions, choose and integrate products and services that are the best fit, and build the most effective cybersecurity posture.

We provide organizations with holistic perspective on their cyber ecosystem to minimize gaps, vulnerabilities, and optimize resources, including:

1. Understanding the changing threat landscape, vulnerabilities, and gaps
2. New insights of how product decisions align with resource capacity
3. Insightful product comparisons and integration to save time, money, and mistakes

Similar Jobs

STR Logo STR

Senior Machine Learning Scientist

Machine Learning • Security • Software • Analytics • Defense
Arlington, VA, USA
600 Employees

STR Logo STR

Senior Vulnerability Researcher

Machine Learning • Security • Software • Analytics • Defense
Arlington, VA, USA
600 Employees

Capital One Logo Capital One

Senior Data Engineer (Python, Spark, AWS)

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Richmond, VA, USA
55000 Employees

Capital One Logo Capital One

Senior Data Engineer (Python, Spark, AWS)

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
McLean, VA, USA
55000 Employees
165K-189K Annually

Similar Companies Hiring

Coro Thumbnail
Software • Security • Information Technology • Data Privacy • Cybersecurity • Cloud • Artificial Intelligence
Chicago, IL
330 Employees
MacPaw Thumbnail
Software • Security • Information Technology • Data Privacy • Cybersecurity • App development
Cambridge, MA
550 Employees
Silverfort Thumbnail
Security • Sales • Information Technology • Cybersecurity • Automation
GB
357 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account