SAIC has an opening for a Cybersecurity Ops Analyst. This position is located in Oak Ridge, Tennessee. SAIC is open to the position working remotely within the United States.
The SAIC Cybersecurity Ops Analyst (Shift Leader) leads advanced security event analysis as part of the 24/7/365 Security Operations Center's Detection & Response team. They manage daily activities using a SIEM, monitoring events from multiple sources while overseeing a team of Cybersecurity Ops Associates.
This position will be for second shift (2pm – midnight) Wednesday-Saturday.
In addition to their incident response duties, the Shift Leader manages the operations of the shift, including timecard and expense approval, as well as daily training and performance tracking. They also participate in threat hunting, intelligence gathering, and strive to improve procedures and processes within the ESOC.
Job Duties:
- Conduct Lead the identification, prioritization, and response to intrusion activities and anomalous behavior as shift leader on an 24/7/365 Detection & Response Team.
- Assess the impact of potentially malicious traffic on the network and infrastructure.
- Perform in-depth analysis of security anomalies and incidents using network forensics via a SIEM and host level forensic via an EDR tool.
- Document all incidents within the shift and maintain incident tickets.
- Communicate and escalate issues and incidents as necessary.
- Handle IP/URL/Hash block requests and develop new correlation content.
- Conduct second-level real-time monitoring and analysis of security alerts.
- Delegate event analysis tasks to Cybersecurity Ops Associates, as required.
- Provide feedback on tuning for enhanced anomaly detection.
- Retrieve and review data files associated with security events.
- Evaluate malicious activity and review vulnerability information to assess risk.
- Collaborate with other teams for incident resolution.
- Manage shift operations: Train, mentor, and oversee Cybersecurity Ops Associates, including approving timecards, expenses, providing feedback, writing performance reviews and ensuring shift coverage for 24/7/365 operation.
- Continually review and improve documentation procedures.
- Participate in knowledge sharing.
- Additional responsibilities will include the ability to train, mentor Cybersecurity Ops Associates.
QUALIFICATIONS
Required Education and Experience Requirements:
- Bachelors and two (2) years or more experience OR AA Degree in related discipline and three (3) years or more experience.
- Must have a minimum of two (2) year cybersecurity operations related experience.
- Must possess the following certification(s): Security+ AND CySA+.
- Strong leadership skills; proven ability to lead and motivate a team effectively.
- Can-do attitude.
- Self-motivated and quick-learner.
- Excellent communication skills both verbal and written.
- Ability to multitask and collaborate to solve complex technical problems.
- US citizenship is required.
Desirables:
- Three (3) years cybersecurity operations related experience.
SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.