Cyber Security Analyst Tier III

Clearance Level
None
Category
Cyber and IT Risk Management
Location
Bossier City, Louisiana
(Onsite Workplace)
Key Skills For Success

Cyber Defense

Security Information and Event Management (SIEM)

Security Operations

Security Tools

REQ#: RQ215834
Public Trust: Other
Requisition Type: Regular
Your Impact

Own your opportunity to support the missions that matter. From working with technologies like AI, cyber and cloud to careers in intelligence and health, we offer endless opportunities to apply your expertise to create a safer, smarter world while building new skills to propel your career forward.

Job Description

As a member of the Security Operations Center (SOC) team, in support of the Virginia Information Technology Agency (VITA), a Cyber Security Analyst (Tier III) will be responsible for performing investigation and escalation of security alerts triaged by Tier I and Tier II analysts and others that enter the SOC from network and security systems/applications, the client, and/or from intelligence sources. The position may also require an Analyst to monitor and utilize third party toolsets in the client environment.

RESPONSIBILITIES:

  • Provide expertise with Indicators of Compromise (IOCs), Tactics, Techniques, and Procedures (TTPs), Threat Hunting/Intelligence, and customer facing escalations, containment/remediation activities.
  • Provide technical support on event network security logs and trend analysis.
  • Detect the full spectrum of known cyberattacks (e.g., DDoS, malware, phishing, others).
  • Uncover and pinpoint security violations of compromised systems and devices
  • Correlate security events from various capabilities to identify attacks and breaches.
  • Analyze and acts on intelligence information to secure customer networks and devices
  • Recognize successful and unsuccessful intrusion attempts and compromises.
  • Triage security events utilizing relevant details and summary information.
  • Prepare incident reports of analysis methodology and results.
  • Observe, document and report actions taken by malicious actors in customer networks.
  • Accurately and appropriately prioritize and escalate incidents.
  • Examine malware analysis reports and other reporting from incidents to correlate similar events.
  • Conduct log and system analysis for various system, and network and security devices.
  • Document emerging threat intelligence and reported IOCs for security tool integrations.
  • Create and update rules or signatures in security tools and applications.
  • Escalate identified security incidents to the appropriate teams or POCs.
  • Recommend appropriate methods of system remediation and threat mitigation, as needed.
  • Maintain a current understanding of the best practices and strategies used in cyber security.
  • Motivate self and co-workers to expand knowledgebase and capabilities.
  • Develop lessons learned documentation, reporting, and playbooks/SOPs for response within the environment.
  • Provide content engineering expertise to include analyzing, designing, developing and delivering solutions to stop adversaries.

REQUIRED QUALIFICATIONS:

You MUST have:

  • Technical Training, Certification(s) or Degree
  • 8 or more years of related experience
  • Demonstrated Cyber Ark experience
  • Demonstrated Splunk experience
  • An ability to obtain certification to meet DoD IAT Level III and CSSP Analyst (DoD 8570) requirements within 6 months of starting the position: CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, and/or PenTest+
  • Ability to obtain and maintain a public trust
  • Louisiana Residency, living within a reasonable commutable distance (approximately 60 miles or less) of the Bossier City facility

PREFERRED QUALIFICATIONS

Even BETTER if you have:

  • 10 or more years of relevant experience
  • Strong analytical, organizational and project management skills
  • Ability to create and manage vulnerability management dashboards in Splunk
  • Understanding of networking fundamentals, the OSI model, and TCP/IP protocols
  • Knowledge of attack methods and techniques (DDoS, brute force, spoofing, etc.)
  • Experience reviewing network, host and application audit logs (system, security, etc.)
  • Relevant security certifications (Network+, CEH, CCNA, etc.)
  • Familiarity of security standards (NIST, FISMA, Fed RAMP, DCID, CNSS and DoD 8500)
  • Knowledge of cloud IT solutions and security considerations of cloud solution deployment
  • Experience with any SIEM or log aggregation system, Splunk preferred

Location: On-site at GDIT's Integrated Technology Center in Bossier City, LA


GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.

● Growth: AI-powered career tool that identifies career steps and learning opportunities
● Support: An internal mobility team focused on helping you achieve your career goals
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
● Flexibility: Full-flex work week to own your priorities at work and at home
● Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

Work Requirements
Years of Experience

8 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

Security Plus - CompTIA - CompTIA

Travel Required

Less than 10%

Salary and Benefit Information

The likely salary range for this position is $116,813 - $143,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across over 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber and application development. Together with our customers, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans