IT SOC Engineer I
Indexed description
Responsibilities Are
- Responsible for performance of forensic analysis on various digital media devices and mediums to identify, reverse engineer, and obfuscate content related to an incident, such as malicious content.
- Consult with security operations regarding cybersecurity communications and deliver or request assistance or assist with investigations.
- Provide technical expertise in cyber adversary capabilities and an assessment of the intentions of these groups to conduct Computer Network Exploitation (CNE) and Computer Network Attack (CNA) against U.S. private sector and Government networks and information systems.
- Consult and provide onsite and remote vulnerability assessment capabilities as a sustained, full-time program independent of incident detection, recovery, or reporting activities.
- Consult both internal and external penetration and security testing which mimics real-world attacks to identify methods for circumventing the security features of an application, system, and network.
- Consult with teams to detect, prevent, and respond to threats posed by malicious, negligent, or compromised insiders by maintaining in-depth visibility into the DFC Enterprise and having a means of filtering and prioritizing threat data into concise, actionable intelligence.
- Provide expert security engineering and subject matter expertise to conduct market research, product evaluation, testing, configuration, deployment, operations, and maintenance support for various SOC software tools and technologies.
- Advise and assist with SOC architecture activities for all DFC SOC information systems initiatives supporting all SOC tools and capabilities.
- Create procedures and documentation for maintaining SOC hardware and software.
- Determine and document the security impact of proposed or actual changes to the information systems and their environment of operation.
- Assess the technical, management, and operational security controls employed within and inherited by the information systems in accordance with the organization defined monitoring strategy.
- Facilitate and perform remediation actions based on the results of ongoing monitoring activities and the outstanding items in the POA&M.
- Update the System Security Plan, SAR, and POA&Ms. Key Deliverables: updated Residual Risk Statement and Risk Acceptance Recommendation Report.
- Report the security status of information systems to appropriate organizational officials on an ongoing basis.
- Review the reported security status of information systems ongoing Risk Determination and Acceptance.
- Incident Assessment and Response Support; work with the DFC CIRT or any other pertinent parties (including external vendors) at any DFC location to recover from any incident.
General Description Of Benefits
Required Skills
- Must possess an Active Secret clearance.
- 3+ years of technical experience in Cybersecurity, maintaining IT security policies, processes, and guidance.
- 8570.01/8140.03 Cybersecurity certification. (CompTia Security+CE)
- Experience with mitigation of security control vulnerabilities based on Cybersecurity principles and tenets. (e.g., STIG, NIST SP 800-53, Cybersecurity Risk Management Framework, etc.).
- Hands-on experience supporting Security Operations Center (SOC) operations in an enterprise environment.
- Experience performing Tier 1 security alert monitoring, triage, investigation, and escalation using SIEM platforms.
- Experience managing and resolving SOC ticket queues, including documenting findings, escalating incidents, and tracking issues through resolution.
- Experience performing phishing email triage and analysis, including supporting phishing investigations and campaigns.
- Hands-on experience with security tools and platforms such as Microsoft Defender, Splunk, Security Onion, and Absolute, or similar technologies.
- Ability to analyze security alerts and events, identify potential threats, and follow established incident response and escalation procedures.
- Experience with NIWC and/or a DOD SOC.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We Value
- Attracting and developing top talent and high-performing teams
- Fostering a culture that is engaging, accountable, and mission-driven
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search