Cybersecurity Data Analyst jobs in United States
cer-icon
Apply on Employer Site
company-logo

General Dynamics Information Technology · 2 days ago

Cybersecurity Data Analyst

General Dynamics Information Technology is a global technology and professional services company that delivers consulting, technology and mission services to major agencies across the U.S. government. They are seeking a Cybersecurity Data Analyst to provide cybersecurity data analysis services, including the maintenance and improvement of Security Information Events Management (SIEM) capabilities, and ensure the reliability and security of IT resources.

Artificial Intelligence (AI)Cloud ComputingConsultingCyber SecurityInformation Technology
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software
Maintain system availability and reliability with a threshold of 99.99%
Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation
Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform
Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management
Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions
Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service
Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost)
Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NGA laws, directives, orders, polices, guidance, procedures etc
Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN – Joint Incident Management System, DoD CIO – DoD Scorecard/Get to Green reporting, IC CIO – Cybersecurity Performance Evaluation Model reporting, etc.)
Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions
Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services

Qualification

Cyber Security AssessmentsData AnalyticsSIEM experienceLinux (RHEL) ExpertCompTIA Project+KibanaData MetricsSoft Skills

Required

Top Secret SCI + Polygraph clearance level must currently possess
Top Secret SCI + Polygraph clearance level must be able to obtain
6 + years of related experience
US Citizenship Required
Cyber Security Assessments
Data Analytics
Data Metrics
CompTIA Project+ certification
SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)
Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules
Create SIEM playbooks
Linux (RHEL) Expert (administration and engineering)
Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives
Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events
Creation of ArcSight rules based on use cases of malicious events
Tuning and aggregation of queries and filters
Skilled in troubleshooting event flow through Enterprise Audit infrastructure
Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools
Active TS/SCI with POLY
DoD 8570.01-M IAT Level II and CSSP Infrastructure Support certifications
6+ years Experience with SIEM and Development Projects
6+ years Experience with SIEM support for projects and technical exchange meetings
6+ years Experience developing and maintaining enterprise audit projects

Preferred

Kibana
Data Analytics

Benefits

Medical plan options
Health Savings Accounts
Dental plan options
Vision plan
401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match
Full flex work weeks
Paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
Short and long-term disability benefits
Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance

Company

General Dynamics Information Technology

company-logo
General Dynamics Information Technology is an IT consulting company that specializes in cyber security, AI, and quantum computing. It is a sub-organization of General Dynamics.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Paul Nedzbala
Senior Vice President
linkedin
leader-logo
Ben Buckley
Vice President and General Manager
linkedin
Company data provided by crunchbase