Job ID :
9203
Company :
DC Government
Location :
WASHINGTON, DC
Type :
Contract
Duration :
long term
Salary :
open
Status :
Active
Openings :
1
Posted :
10 Aug 2016
Job Seekers, Please send resumes to resumes@hireitpeople.com
Required Skills - SIEM Security Engineer, Malware, breach methodology.  
INTERVIEW: Must do a face to face interview.
Duration: Long term. At least 6 to 12 months+

Complete Description:

The role of this function involves experience SEIM administration and experience with other log management technologies.

The SEIM Developer shall be responsible for the following, but not limited to:

•  Implement, support and test information security technologies.

Develop, implement and maintain information security policies and procedures.

Anticipate and identify threats and vulnerabilities through monitoring, analysis, planning, and engineering.

Provide subject matter expertise on enterprise cyber security risks, threats, technologies, and potential impact.

• Assist customers in the response to security incidents, conduct investigations on behalf of the DC IT Security team.

• Work with Agency departments and 3rd parties to design and implement remediation and recovery plans.

• Develop custom scripts and tools to solve specific programs related to investigations.

• Research new techniques and artifacts and present findings in daily reports, white papers, conference presentations, and other media.

• Perform as subject matter expert on INTEL SEIM Security Suite.

• Perform all administration, management, configuration, testing, and integration tasks related to the Client INTEL SEIM system focusing primarily on content development, reporting, and metrics.

• Deliver customization to the Client INTEL ESM platform to facilitate operations.

• Create rules, filters, active channels, queries, trends and all other informational content based on use cases.

• Develop, implement, maintain and execute standard content development practices for the Client INTEL SEIM system infrastructure.

• Work with business unit SMEs on use cases and to create correlation rules and content that is relevant to that business unit.

• Communicate and collaborate with security operations center analysts to optimize Client INTEL SEIM performance to better meet the needs of operations.

• Tune correlation rules and event data quality to maximize INTEL SEIM system efficiency.

• Provide support recommendations and optimization for the INTEL SEIM platform; as well as SEIM expertise and input related to protecting company's cyber related assets.

• As part of a team, provide secondary operational support of a tiered INTEL SEIM to include; INTEL ESM, Connector appliances, SmartConnectors, Logger appliances, Windows and Linux servers and a variety of network and security related devices.

• Perform secondary support for upgrades and apply patches and/or bug fixes to INTEL ESM.

• Use INTEL ESM and Remedy in the daily operational work and workflow.

• Establish and maintain excellent working relationships/partnerships with the cyber security and infrastructure support teams throughout the Information Technology organization, as well as business unit stakeholder SMEs.

Behavioral Characteristics:

Working in a collaborative team environment, the Incident Response and Forensic Consultant will work with stakeholders to identify, investigate and remediate anomalies within a secure network infrastructure and support best practices.

Skill

Required / Desired

Amount

of Experience

Expertise Rating

BS degree in Computer Science, Engineering, related technical degree or equivalent experience preferred

Highly desired

4

Years

2 - Proficient

Certifications from ISC2, GIAC, CompTIA, or EC-Council

Required

5

Years

2 - Proficient

Expert knowledge of incident handling procedures

Highly desired

8

Years

3 - Expert

Understanding malware and breach methodology

Required

10

Years

3 - Expert

Experience with behavioral and static malware analysis

Highly desired

8

Years

3 - Expert

Network Log and packet capture analysis

Highly desired

8

Years

3 - Expert

Understanding of networking protocols and secure network design

Desired

8

Years

2 - Proficient

Experience in CSIRT and SOC environments

Highly desired

10

Years

2 - Proficient

Overall IT experience

Required

10

Years

 

SEIM Administration

Highly desired

5

Years

3 - Expert