Agile Defense provides leading-edge Digital Transformation solutions to support and advance our customers' mission. We deliver innovative and high-quality services to our customers worldwide through an empowered and engaged workforce.
Job Title: SOC Analyst Lead
Location: 1155 21st St NW Washington, District of Columbia20581
Clearance Level: Public Trust
Required Certification(s):
An industry technical certification such as GCIH, MS-SC200 or other MS cloud certifications
SUMMARY:
Agile Defense is currently seeking a talented and ambitious self-starting Security Operations Center (SOC) Team Lead with advanced skillsets in cyber security with emphasis on applied cloud security to develop operational strategy in the effort to continually move forward the skills and capabilities of our dynamic team of security analysts for a variety of federal customers.
This is a unique opportunity for the right candidate to embed themselves into the next generation of operational environments which is now taking place across the US government. The existing team is a multi-faceted interdisciplinary set of experts with ever-increasing prowess in this unique environment. Our security operations project is aimed at establishing innovative techniques for a comprehensive, cloud-first network enclave defense, identifying the emerging threats, and detecting malicious activity using advanced toolsets provided in the Microsoft cloud security ecosystem.
The ideal candidate will have hands-on experience as a SOC analyst performing Incident Response and Intrusion Detection on an operational Federal network, ideally having been migrated to a cloud environment, specifically, the Microsoft Sentinel SIEM and related security portals in Azure. Candidates should have excellent written and oral communication skills, be able to work independently and as part of a team, with demonstrated leadership capabilities. Skills and experience in Operations Management, Security Event Analysis, Incident Response, Cyber Hunt, Forensics, Malware Analysis, and Cyber Threat Intelligence (skills in more than one cyber discipline are preferred) are required for this position.
The ideal candidate will have hands-on experience supporting a 24x7x365 SOC environment as an analyst or engineer, experience as a technical team lead within the SOC, and operations management experience. A solid understanding of cyber threats and information security in the domains of TTP’s, Threat Actors, Campaigns, and Observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management. Corporate duties such as solution/proposal development, corporate culture development, mentoring employees, supporting recruiting efforts, will also be required.
JOB DUTIES AND RESPONSIBILITIES
Manage a SOC to provide cyber defense capabilities to a federal entity in a comprehensive Computer Network Defense support service through security event monitoring, advanced analytics and response, and cyber intelligence activities.
Conduct quality assurance reviews of all SOC activities through reviewing of metrics and case analysis while reporting to the Program Manager.
Serve as a technical Cyber SME and onsite Task Lead.
Maintain a 24x7 schedule and minimum-manning requirements.
Lead efforts Planning, organization, scheduling and progress reporting of various projects.
Construct and optimize operational workflows for 24x7 teams across multiple shifts.
Develop, collect, analyze security operational metrics to optimize SOC performance and minimize organizational ris.k
Research, evaluate, recommend, and design new security technologies and supporting infrastructure.
Develop technical cyber security solutions in response to customer requests or in support of proposal solution development.
Provide technical writing support in support of corporate response to RFPs/RFQs from various customers.
Support new XOR engagements as transitional program or operations lead.
Support documentation of all business and workflow processes in this area.
Provides technical consultation in cyber security capability development.
Maintains current knowledge of relevant cyber security and related technologies as assigned.
Serves as liaison with various customers (internal and external).
Acts as a subject-matter expert to multiple tasks and/or programs.
SUPERVISORY DUTIES
Manage, lead, coordinate, and schedule a team of incident responders across 3 different shifts, day, night, and weekend.
QUALIFICATIONS
Required Certifications
An industry technical certification such as GCIH, MS-SC200 or other MS cloud certifications.
Education, Background, and Years of Experience
Bachelors Degree is required.
ADDITIONAL SKILLS & QUALIFICATIONS
Required Skills
At least 3 years of experience in a cyber network defense environment performing analysis and engineer functions and 2 years of experience as a team lead or operations management.
Work independently to design cloud security operations strategy and report progress.
Experience with MS tools such as Active Directory, Azure Active Directory, AD Connect, SAML, Kerberos, Cisco IOS, MS Server, Azure cloud environments, Incident Handling, Threat hunting experience, fundamental knowledge of IEEE 7 layers.
Experience with deployment and documentation of enterprise project management and change management processes.
Ability to identify solutions to potential network/data/asset issues/embrace network simplification and apply strengthened security methods.
Ability to conduct event triage and analysis and incident investigation.
Write threat reports and incident reports.
Read and ingest various govt. regulations for application to agency environment.
Preferred Skills
Experience in mentoring and training junior, mid-level, and senior analysts.
Proficiency in utilizing various packet capture (PCAP) applications/engines and in the analysis of PCAP data.
Ability to develop rules, filters, views, signatures, countermeasures and operationally relevant applications and scripts to support analysis and detection efforts.
One or more certifications for CND Analysts: GCIA, GCFA, GCFE, GREM, GISF, GMON, GXPN, CHFI, GNFA, CCFP, LPT, CHFI, CSA.
One or more certifications for a manager: CISSP, PMP, CISM, ITILv3.
WORKING CONDITIONS
Environmental Conditions
Contractor will work Onsite as required Mondays and Wednesdays at CFTC HQ in Washington DC and 3 Days remote.
Strength Demands
Sedentary – 10 lbs. Maximum lifting, occasional lift/carry of small articles. Some occasional walking or standing may be required. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Physical Requirements
Stand or Sit
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. We believe several attributes are the root of our very best employees and extraordinary culture. We have named these attributes “The 6 H’s” – Happy, Helpful, Honest, Humble, Hungry, and Hustle.
Happy: We exhibit a positive outlook in order to create a positive environment.
Helpful: We assist each other and pull together as teammates to deliver.
Honest: We conduct our business with integrity.
Humble: We recognize that success is not achieved alone, that there is always more to learn, and that no task is below us.
Hungry: We desire to consistently improve.
Hustle: We work hard and get after it.
These Core Values are present in all our employees and our organization's aspects. Learn more about us and our culture by visiting us here.
COVID-19 Vaccination Requirements
Agile Defense is subject to federal vaccine mandates or other customer/facility vaccination requirements as a federal contractor. As such, to protect its employees' health and safety and comply with customer requirements, Agile Defense may require employees in certain positions to be fully vaccinated against COVID-19. Vaccination requirements will depend on the status of the federal contractor mandate and customer site requirements.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)
Agile Defense's mission is to transform our government customers' organizations using Information Technology so that they can meet their mission's deadlines with efficiency and quality.
68 jobsSubscribe to Rise newsletter