Cintel, Inc. ยท 14 hours ago
Mid Level SOC Operations Analyst
Cintel, Inc. is a Small Business providing strategies and services to support an array of Government clients in various domains. They are seeking a Mid Level SOC Operations Analyst to support Watch-Floor Operations, focusing on monitoring, analysis, and response to security events and threats across the enterprise.
AerospaceBusiness IntelligenceCyber SecurityEmbedded SystemsGovernmentMachine LearningMilitarySoftware
Responsibilities
Monitor computer networks in real-time for security issues and suspicious activity
Investigate and respond to security breaches, cyber incidents, and anomalous behavior
Document security breaches and assess the scope and impact of each incident
Perform initial triage and analysis of alerts generated by security tools (e.g., SIEM platforms)
Conduct forensic analysis of digital artifacts including disk images and log data
Assist with penetration testing and vulnerability assessments
Apply remediation measures to detected vulnerabilities and provide security hardening recommendations
Support the deployment and monitoring of firewalls, encryption tools, and other security technologies
Generate incident reports and provide input for root cause analysis and lessons learned
Participate in deployable Incident Response Team (IRT) support tasks
Perform dynamic analysis and develop timelines and file signature comparisons during investigations
Qualification
Required
Hands-on experience or training with Splunk Enterprise Security
Strong knowledge of cybersecurity concepts, attack vectors, and mitigation strategies
Familiarity with network protocols, intrusion detection/prevention systems, and log analysis
Excellent problem-solving and communication skills
Ability to work effectively in a fast-paced, high-stress operational environment on shift schedules
5+ years of directly related experience
Active Top Secret Clearance with SCI Eligibility
Bachelor's Degree (B.S. or B.A.) in Cybersecurity, Information Technology, Computer Science, or a related field
Preferred
Experience with Microsoft Sentinel (SIEM)
One or more of the following certifications: GIAC Continuous Monitoring Certification (GMON), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Intrusion Analyst (GCIA), GIAC Network Forensic Analyst (GNFA)