Monitoring and Analysis Deputy Lead (w/ TS)

Washington D.C., DC 20530, USA

Critical Solutions

Critical Solutions specializes in providing expert cyber security services in the areas of automation, integration and research development.

View all jobs at Critical Solutions

Apply now Apply later

Monitoring and Analysis Deputy Lead (w/ TS)

Location: Washington, DC
Clearance: active Top Secret
Full-time, On-site


JOB DESCRIPTION

Critical Solutions has an immediate opening for a Monitoring and Analysis Deputy Lead to support our federal customer in Washington, DC.

PRIMARY ROLES AND RESPONSIBILITIES:

  • Onboarding Optimization:
    • Lead efforts to reduce onboarding time through continuous observation and assessment of operations and administrative processes.
    • Implement process improvements to enhance efficiency and reduce unnecessary efforts, leveraging process improvement methodologies, e.g. Lean Six Sigma.
  • Process Improvement:
    • Continuously review and refine Standard Operating Procedures (SOPs) and workflows to ensure they are modern, efficient, and aligned with current needs.
    • Collaborate with the SOAR team and other special teams to enhance automation and workflow capabilities.
  • Customer Service Enhancement:
    • Provide superior customer service to the Agency by accurately identifying and addressing ad hoc requests from federal leadership.
    • Act as a point of contact for high-level leaders and leads on the federal side to ensure clear communication and understanding of requirements.
  • Training and Tools Management:
    • Oversee and maintain compliance with required training programs, including on-the-job cybersecurity training and Agency-mandated e-learning courses.
    • Manage and maintain access to cybersecurity tools, ensuring all team members have the necessary permissions to perform their roles effectively.
    • Provide training on the use of various cybersecurity tools to team members, enhancing their capability to use the tools efficiently.
  • Shift Liaison and Task Management:
    • Ensure that all shifts (Front Days, Back Days, Front Nights, Back Nights) do not miss important emails or tasks, maintaining consistency in task completion.
    • Monitor and follow up on asks to ensure they are addressed and not overlooked, addressing gaps in previous processes.
  • Quality Assurance and Content Improvement:
    • Perform quality assurance checks on Splunk comment closures, Splunk investigations, and cybersecurity investigations (ECMs).
    • Conduct quality checks on EBMs or proxy and firewall blocks submitted within the network.
    • Review trends and data to develop better content for Splunk alerting and monitoring.
    • Continuously work to improve the accuracy and efficiency of monitoring content by analyzing investigation trends.
  • Process and Workflow Enhancement:
    • Collaborate with the federal cybersecurity leads to reduce waste and improve meaningful cybersecurity processes.
    • Engage with various teams to explore new methods to improve the work environment and cybersecurity services, including liaising with SOAR engineers and other special teams.
  • Tools and Service Evaluation:
    • Test and evaluate new tools and services requested by the customer in a testing or development environment, providing critical feedback and analysis before enterprise-wide acquisition.

BASIC QUALIFICATIONS:

  • Must have current TS/SCI. In addition to specific security clearance requirements, selected candidate will be required to obtain an Entry on Duty (EOD) clearance to support this program.
  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field AND a minimum of four (4) years total professional experience in at least two of the areas listed below:
    • Vulnerability Assessment
    • Intrusion Prevention and Detection
    • Access Control and Authorization
    • Policy Enforcement
    • Application Security
    • Protocol Analysis
    • Firewall Management
    • Incident Response
    • Encryption
    • Web-Filtering
    • Advanced Threat Protection
  • Military experience and training may be considered in lieu of degree
  • Experience conducting detailed technical analysis of Cybersecurity Events and Incidents
  • Extensive knowledge of a SOC's/NOSC's purpose and role within an organization
  • Detailed understanding of common network ports and protocols (e.g. TCP/UDP, HTTP, ICMP, DNS, SMTP, etc)
  • Expertise with network topologies and network security device functions (e.g. Firewall, IDS/IPS, Proxy, DNS, etc).
  • Expertise with packet analysis tools such as Wireshark
  • Able to perform critical thinking and analysis to investigate cyber security alerts
  • Extensive knowledge of common malware and attack vectors
  • Extensive experience with Windows operating systems and standard OS logging
  • Extensive experience with Antivirus, DLP, and host-based firewalls
  • Active advanced cybersecurity certification(s)
  • Must possess and maintain one of the following professional certifications: CCNA-Security, CompTIA Cyber Security Analyst (CySA+), GICSP-Cyber Security Professional, GSEC-Security Essentials, Security+ CE, CND-Certified Network Defender, SSCP-ISC2 Systems Security Certified

PREFERRED QUALIFICATIONS:

  • Expertise in Lean Six Sigma, e.g. Black Belt or Green Belt
  • Familiarity with other continuous improvement methodologies, e.g. Theory of Constraints
  • Strong analytical skills with the ability to perform quality assurance and content improvement.
  • Demonstrated ability to liaise between multiple teams and organizational levels.
  • Excellent communication skills, both written and verbal, with the ability to interact effectively with federal leadership and team members across all shifts.

LOCATION:

  • Washington, DC. Onsite
  • Must be able and willing to commute to work location

ADDITIONAL INFORMATION:

CLEARANCE REQUIREMENT: Must possess an active DoD Top Secret/SCI clearance. In addition, selected candidate must undergo background investigation (BI) and finger printing by the federal agency and successfully pass the preceding to qualify for the position. US CITIZENSHIP IS REQUIRED due to the nature of the government contracts we support.

CRITICAL SOLUTIONS PAY AND BENEFITS:

Salary range $ - $. The salary range for this position represent the typical salary range for this job level and this does not guarantee a specific salary. Compensation is based upon multiple factors such as responsibilities of the job, education, experience, knowledge, skills, certifications, and other requirements.

BENEFIT SNAPSHOT: 100% premium coverage for Medical, Dental, Vision, and Life Insurance, Supplemental Insurance, 401K matching, Flexible Time Off (PTO/Holidays), Higher Education/Training Reimbursement, and more


Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Antivirus Application security Automation Business Intelligence Clearance CND Compliance CompTIA Computer Science DNS DoD Encryption Firewalls GICSP GSEC IDS Incident response Intrusion prevention IPS Malware Monitoring Network security Security Clearance SMTP SOAR SOC Splunk SSCP Top Secret TS/SCI Windows

Perks/benefits: Career development Flex vacation Health care Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.