5 days old

Federal - Cyber Security Operations Center Lead

St Louis, MO 63103

Organization: Accenture Federal Services Location: San Antonio, TX We Are:

Accenture Federal Services, bringing together commercial innovation with the latest technology to unleash the potential for our federal clients. Every day we bring bold thinking and diverse disciplines to solve problems in new ways. Ready to learn as much as you can? Well give you numerous opportunities of formal & informal training sessions to keep your tech smarts sharp.

You Are:

As Team Lead for Security Operations Center (SOC), perform the following tasks: Monitoring of security events, trend analysis, and tuning security event related signatures. Monitor, organize, and coordinate correspondence for emails received to the SOC Inbox, update Standard Operating Procedures (SOPs), and coordinate with Incident Response staff to effectively contain and recover from cyber incidents. Support and coordinate eDiscovery and Freedom Of Information Act (FOIA) requests. Monitor security event feeds for availability and throughput, to quickly identify any gaps in available telemetry. Ideally, candidate will have Cloud experience in AWS or Azure.

Job Responsibilities Include:

+ Operate and manage Enterprise class 24x7 Security Operations Center

+ Maintain, monitor, review alerts, tune defense-in-depth sensors (Snort, Bro, Vectra)

+ Monitors services and networks 24x7x365

+ Report confirmed "incidents" to external organizations as needed

+ Maintain internal ticketing and knowledge base

+ Monitor Splunk, provide historical reach back for correlation and review of IoC data

+ Cloud tenant monitoring, alerts, reviews, response and analysis, threat hunting

+ Point of Contact for URL Filtering requests (unblock, block)

+ Perform pro-active blocks on known bad IPs and URLs imposing risk

+ Assesses Enterprise Risk related to actionable intelligence and intel "in the wild

+ Close, collaborative relationship and information sharing with external organizations as needed

This position requires the ability to work a shift schedule and support coverage efforts on a 24x7x365 basis which includes work on holidays, nights, & weekends.

Heres What You Need:

+ Bachelors Degree and 7+ years of Cyber / SOC / Monitoring Work Experience OR 9 + years with an Associates

+ Monitoring of security events, trend analysis, and tuning security event related signatures to include cloud applications

+ Cyber and/or IT Work Certification (i.e Security+ Certification)

Bonus Points If:

+ Bachelor's Degree

+ Experience working with Security Information and Event Management (SIEM) solutions is a plus

+ Experience monitoring AntiVirus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Vulnerability Assessment tools and other security tools found in large enterprise network environments

+ Familiarity with various network and host based security applications and tools, such as network and host assessment/scanning tools, network and host based intrusion detection systems, and other security software packages. Host based forensics and malware analysis experience.

+ Previous experience working in a large government or corporate enterprise environment.

+ Experience on a Computer Incident Response Team (CIRT), Computer Emergency Response Team (CERT), Computer Security Incident Response Center (CSIRC) or a Security Operations Center (SOC).

+ RSA Security Analytics / NetWitness

+ Splunk, including Splunk for Enterprise Security

+ RSA Archer

+ SourceFire/FirePower/Snort

+ McAfee ePO, HIPS

+ FireEye NX, EX, HX

+ EnCase Enterprise

Important Eligibility Requirements

US Citizenship - No Dual Citizenship

An active security clearance or the ability to obtain one may be required for this role.

Candidates who are currently employed by a client of Accenture or an affiliated Accenture business may not be eligible for consideration.

Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States and with Accenture (i.e., H1-B visa, F-1 visa (OPT), TN visa or any other non-immigrant status).

Accenture is a Federal Contractor and an EEO and Affirmative Action Employer of Females/Minorities/Veterans/Individuals with Disabilities.

Posted: 2021-05-03 Expires: 2021-06-02

Before you go...

Our free job seeker tools include alerts for new jobs, saving your favorites, optimized job matching, and more! Just enter your email below.

Share this job:

Federal - Cyber Security Operations Center Lead

St Louis, MO 63103

Join us to start saving your Favorite Jobs!

Sign In Create Account
Powered ByCareerCast