Description
Job Description:
The Transportation and Border Security Services (T&BSS) Division is searching for a Security Content Visualization Expert to support and upcoming opportunity for our TSA customer in their Security Operations Center, located in Northern Virginia.
**This position does offer LOCALLY REMOTE capabilities. Must be willing to report onsite as needed.**
Primary Responsibilities
Must have extensive experience
Designing, customizing, and configuring SEIM apps, dashboards, and visual aides to mature and improve medium to large Security Operating Centers
Assisting with the development of advanced reporting & visualizations to meet the requirements of SOC and external stakeholders
Configuring, designing, and testing security operation center dashboards for alerting within SEIM technologies to include data modeling, custom alert notification, and dashboarding supporting the full lifecycle of content (conception, creation, testing, documentation, implementation, tuning)
Analyzing, trending, and filtering of security log data from a large number of disparate security devices to include: FW’s, IPS/IDS, Host-based logs, load balancers, and other security / monitoring solutions.
Performing advanced searching within medium to large-scale SEIM’s and implementation of custom dashboards.
Must have experience
Optimizing security content in enterprise SEIMs
With Cyber Kill Chain and synthesizing the attack life cycle
SOP development and updating along with developing new SOP’s in support of SOC operations
Implementing SOC processes and SOP’s
Mentoring junior and mid-level analysts
Developing custom SPL using macros, lookups and network signatures
Enterprise logging solutions, including application, OS, and security device logging
Identifying/creating and utilizing IOCs
Utilizing Network traffic indicators to identify anomalous user activity associated with lateral movement within an enterprise
Utilizing regex for direct pattern matching
Utilizing network security tools in support of SIEM content generation
Must have demonstrable knowledge of
Network ports and protocols (TCP, UDP, HTTP, SMTP, DNS)
Intel frameworks to include cyber kill chain and Mitre ATT&CK
APT capabilities and ability to implement appropriate detection measures
Custom log parsing
Visualizations for displaying data to include anomalous network traffic
Normal working hours of 8:00am – 5:00pm are anticipated, however actual hours may vary depending on mission requirements
Basic Qualifications
Years of Experience: At least three years of experience working as a senior analyst within Medium-Large Enterprise Security Operations Centers
Clearance Requirements: SECRET
Certification: One of the following certifications is required:
CISSP
GCIH
GCFA
GPEN
GWAPT
GCIA
Or equivalent
Pay Range:
Pay Range $97,500.00 - $150,000.00 - $202,500.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is a Fortune 500® technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, civil, and health markets. The company’s 47,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $14.4 billion for the fiscal year ended December 30, 2022. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.