Now hiring

Security Analyst (IDS/ SIEM) @ OBXtek

USOnsiteFull-timeJob reference REF12I
Apply with ResuMinder

Opens on the employer's site

About this role

Intrusion Protection BackgroundDISSAO provides intrusion protection and vulnerability assessments of the SSA Information systems at various inter-dependent levels. The assessment of the network’s security is a crucial first step in providing intrusion protection. Additionally DISSAO provides remediation to security incidents. A key ingredient of this remediation is the recommendation of immediate corrective actions to systems known to have any security weaknesses or vulnerabilities.Scope of TaskThe objective is to evaluate, identify and classify all anomalous traffic across SSA net and then to provide corrective action.In support of the task, the contractor shall perform activities such as those described in the sub-tasks below.Sub-Task 1: Intrusion Protection and Vulnerability AssessmentsPurpose: Provide intrusion protection and vulnerability assessments at all levels of the SSA computing enterprise including current SSA systems, SSA systems under development or scheduled for implementation.Activities:Provide senior-level advisement to division management and adjacent staff related to Intrusion Protection and Vulnerability Assessments.Monitor Intrusion Detection System (IDS) sensors and infrastructure and other monitoring tools based on a schedule defined by SSA Management.Monitor vulnerability scanning infrastructure based on a schedule defined by SSA Management.Evaluate risk models developed by SSA and provide feedback to the Task Manager.Perform ad-hoc scanning as defined by the Task Manager.Develop scripts using UNIX shell scripting, Perl, PHP or Visual Basic for use in analyzing traffic patterns and anomalies Qualifications & Knowledge RequirementsExperience:Experience: 10 years technically related experience with network and security operations

Desired Security Certifications:CISSPCCNACEHSecurity Plus

Required skills:Analytical experience:Implementing Incident Response proceduresSolid understanding of performing risk and vulnerability assessmentsStrong Security background and experience in large enterprise environmentMcAfee Security Information and Event Management (SIEM)Splunk ESRegex

McAfee Web Gateway ProxyBasic understanding of Web Gateway functionality and operations as they relate to Network Security in an enterprise environment. Additional Applications:VMWare (VCenter Server)SnortDragonCheck Point Firewall (IDS Blade) Sourcefire Defense Center and Sensors:Experience with signature and rule creationDeployment of Virtual Defense CenterSecurity Enhancement and Policy Updates3D Sensor deploymentWhitelist compliance and traffic tuningRNA and RUA functionality/management

All your information will be kept confidential according to EEO guidelines.

Skills

Information TechnologyMid-Senior LevelInformation Technology And Services

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores