Job Closed
This listing is no longer active.
Advancing the power of technology and innovation to serve and protect our world.
Cybersecurity Ops Associate
Location
Tennessee
Posted
3 days ago
Salary
0
Seniority
Mid Level
Job Description
Cybersecurity Ops Associate
SAIC
• Monitor and analyze identified security events in support of the Enterprise Security Operations Center's Detection & Response team • Perform daily operations utilizing a SIEM and monitoring events from multiple sources • Provide initial response and support to potential intrusion or security breach alerts • Collect and compile historical data on security incidents for trend analysis and security measures improvement • Assist in containment measures during an incident to prevent unauthorized access or data loss • Investigate and approve/deny IP/URL block requests • Contribute to the development of signature patterns based on known or anticipated threats • Provide feedback on signature tuning for better detection of anomalies • Create and maintain incident tickets as needed • PCAP Analysis and correlation of events • Determine urgency and potential impact • Assist with analysis of actions taken by malicious actors • Develop and maintain security documentation including SOPs, incident reports, and policies • Communicate and escalate issues and alerts as required by process or management • Support various Enterprise Security Operations Center activities
Job Requirements
- Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity or a related field and 0-2 years of experience. 4 additional years can be used in lieu of a degree
- Must possess the following certification(s): CompTIA Security+
- Candidates must be U.S. Citizens
- Availability to work flexible hours in a 24x7x365 environment.
- Working knowledge of security architectures and devices.
- Working knowledge of technology and security topics including operating systems, network security, protocols, application security, infrastructure hardening and security baselines.
- Can-do attitude.
- Self-motivated and quick-learner.
- Excellent communication skills both verbal and written.
- Ability to multitask.
Benefits
- 100% remote work for the right candidates
- Health insurance
- Flexible working hours
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Serve as the central security and compliance leader for all public sector engagements • Lead the design, implementation, and oversight of a unified security framework that aligns with NIST 800-53 Rev. 5 controls, FedRAMP High authorizations, GovRAMP, CMMC, and emerging SLED requirements • Ensure timely threat mitigation, streamlined audit processes, and secure delivery of cloud services to government agencies • Compile and submit Monthly Continuous Monitoring (ConMon) reports, including vulnerability scans, POA&M trackers, and asset inventories • Oversee threat hunting and vulnerability remediation to ensure compliance with strict federal timelines • Escalate unremediated vulnerabilities and initiate Plan of Action and Milestones (POA&M) creation within 7 days of issue identification • Coordinate and lead Annual 3PAO Security Assessments, including penetration testing and red team exercises • Manage and maintain a compliant, hosted secure repository for storing, retrieving, and provisioning access to security packages and artifacts • Manage third parties performing public sector security functions and direct project management support for these programs • Serve as System Steward for the VA-F package in eMASS • Submit and maintain accurate documentation for marketplace listings • Oversee actionable incident response testing every 6 months • Manage background checks and reinvestigations for personnel requiring system access • Maintain current SaaS platform architecture diagrams and submit Security Change Requests (SCRs) • Contribute to non-FedRAMP commercial compliance frameworks • Provide security and compliance guidance to IT, engineering, and development teams • Identify, evaluate, and implement GRC and SecOps tools • Assist with responses to customer security assessments • Mentor junior staff or cross-functional team members • Support business continuity planning, disaster recovery documentation, and live operational exercises.
Role Description We are looking for an experienced IT Operations Security Manager to oversee our Operations Security team, providing an exemplary service to our business. This is a fast-paced and diverse role where you'll lead a dynamic team of 4 to deliver an effective, proactive security function. You will be responsible for ensuring all day-to-day activities are carried out within a controlled and compliant framework. You will need to continually improve the security of the platforms, based on our ISMS model. Automation is also very important to us, and we need you to lead the automation agenda. In this rewarding role you'll show excellent interpersonal and conflict management skills, and must be able to ensure that our users receive professional and efficient technical support, in addition to managing ticket escalation. - Leading a skilled team of Operational Security Specialists - Providing oversight and direction on security incident triage, mitigation and remediation - Maintaining and improving security operational dashboards and processes including (but not limited to) security incidents, vulnerabilities, agent and asset health, Azure and M365 security posture - Assessing and managing the updates to hardware, software, and services through our change process - Analysing the threats and risks that face the organisation and developing solutions for them - Assisting with audits, arranging penetration testing and responding to security assessments - Acting as one of the focal points for any security breaches/investigations, recommending the best course of action in consultation with Head of Technology - Participating in the incident management process, and undertaking the security role in the Major Incident Team - Ensuring security enforcing controls are effective by working closely with the Group IT team - Reporting on the effectiveness of security using security metrics - Developing best practice processes in the team - Input into the Security roadmap for with the Head of Technology to continue the evolution of the security services function and platforms, securing our business and client data Qualifications - Around 5 years of security experience - Experience in a similar role - Sound working knowledge of security legislation such as GDPR, Data Protection Act, Computer Misuse Act and Fraud Act - In-depth knowledge of security best practice - Strong knowledge of infrastructure, networking cloud technology and security concepts Benefits - Salary - Up to £70,000 per annum depending on experience - Annual Leave - Start with 24 days, increasing to 26 days with service, plus the flexibility to buy or sell up to 5 extra days each year, public holidays, and an extra day off to celebrate your birthday - Pension - Employer contributions of 5% - Financial Benefits - Free life assurance, a save-as-you-earn scheme, a colleague referral scheme (earning £1,000 per referral), and our Benefits App with discounts and cashback at top retailers - Wellbeing & Lifestyle Services - Access to a colleague assistance programme with 24/7 GP service, mental health support, physiotherapy, cycle to work, eyecare vouchers, Health Cash Plan, Dental Plan and Travel Insurance - Motoring Benefits - Exclusive Colleague vehicle-leasing schemes, discounted repairs, and reduced rates on weekend car and van hires - Stream - A free financial wellbeing app that gives you more control over your pay, helps you save, provides financial advice and offers discounts on shopping
Engineer – Cybersecurity Operations
US LBMUS LBM strives to be the leading distributor of specialty building materials in the United States, offering a wide range of products and services that cater to
• Monitor, investigate, and respond to cybersecurity alerts, incidents, and threats across enterprise and cloud environments. • Administer and optimize Microsoft Sentinel, including log collections, integrations, connectors, analytics rules, watchlists, threat intelligence integrations, and dashboards. • Support and maintain Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud. • Develop and tune detections, alerts, and KQL queries to improve visibility and reduce false positives. • Perform threat hunting and security investigations using Defender XDR and Sentinel. • Coach and mentor junior cybersecurity analysts by providing guidance on investigations, threat hunting, detection engineering, Microsoft security technologies, and incident response best practices. • Implement and maintain automation using Sentinel Automation Rules and Logic Apps. • Manage, monitor, and maintain health of Microsoft Defender for Endpoint, and cyber related agents. • Support and collaborate in the establishment and maintenance of server and workstation security baselines, including QA check on server builds. • Optimize Microsoft Defender for Endpoint security controls, including Attack Surface Reduction (ASR) rules and endpoint hardening. • Support security controls, governance, and monitoring for Microsoft 365 Copilot and AI-enabled technologies. • Coordinate penetration testing engagements and track remediation activities. • Support purple team exercises and validate the effectiveness of security detections and response capabilities. • Collaborate with infrastructure, cloud, identity, and application teams to improve security posture. • Develop and maintain operational procedures, runbooks, and technical documentation.
Analista de Segurança Cibernética – Resposta a Incidentes
MinsaitJoin a more human technology #MoreMinsait
• Atuar na equipe global de Resposta a Incidentes (CSIRT). • Monitorar, investigar, conter e responder a incidentes de segurança. • Gerenciar e acompanhar incidentes por meio do ServiceNow. • Realizar análise de eventos, indicadores de comprometimento (IoCs) e correlação de alertas. • Executar ações de mitigação e escalonamento quando necessário. • Elaborar documentação técnica, procedimentos e relatórios de incidentes. • Monitorar e revisar plataformas de segurança do ambiente. • Participar de reuniões técnicas com equipes internas, clientes e stakeholders globais. • Participar do regime de sobreaviso (on-call), conforme escala.


