CSOC Analyst - Tier 3 Shift 1

Abile Group, LLC

Springfield (VA)

On-site

USD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Abile Group, LLC is seeking a CSOS Analyst – Tier 3 in Springfield, VA, to support Cybersecurity services for an Intelligence Community customer. This role includes coordinating incident response actions, performing digital media analysis, and generating detailed reports in a high-security environment.

The ideal candidate must have a Bachelor's degree, a minimum of 6 years experience in Cyber Security, and the ability to obtain a TS/SCI clearance and CI Polygraph. Required certifications include DoDD 8140.01 and IAT Level II.

Qualifications

  • 6 years of experience in Cyber Security (CSOS).
  • Ability to obtain TS/SCI clearance and CI Polygraph.

Responsibilities

  • Coordinate and implement tasks for cybersecurity incident response.
  • Document analysis and response activities in authorized systems.
  • Develop incident investigation reports for stakeholders.

Skills

Cyber Security
Incident Response
Digital Media Analysis
Malware Analysis
Triage of Incidents

Education

Bachelor’s degree in Cyber Security

Job description

Abile Group has an exciting and challenging opportunity for a CSOS Analyst – Tier 3 on a contract providing Network and Cybersecurity services supporting an Intelligence Community customer. The role involves coordinating and implementing tasks, performing analysis, and building documentation for incident response across multiple networks and security domains worldwide.

Responsibilities
  • Coordinate and implement tasks, performing analysis, and building/documenting response activities required during cyber security incident response, including containment measures such as IP blocks, domain blocks, and disabling user accounts at the direction of the Government.
  • Coordinate with the Security and Installations Directorate (SI) Office of Counterintelligence (SIC), Insider Threat Office (SIII), and other law‑enforcement and counter‑intelligence personnel to perform advanced investigation and triage of incidents.
  • Collaborate with appropriate authorities to produce security incident reports.
  • Classify incidents and events.
  • Coordinate with other contracts, organizations, activities, and services to ensure incidents are properly reported, contained, erased, de‑conflicted with blue/red team activity, or recovered.
  • Build timelines, documents, briefings, and other products to inform stakeholders of incident response actions, analysis, and impact of adversary activity and blue‑force response actions.
  • Document actions taken and analysis in the authorized ticketing system with sufficient detail for systematic reconstruction.
  • Develop, and when approved by the Government, generate and update reports in JIMS, ICMS, and other authorized reporting systems.
  • Maintain, sustain, and when properly authorized, execute custom scripts, tools, and capabilities to collect and analyze data and respond to incidents/events.
  • Perform digital media analysis on host, server, and network data, including volatile and non‑volatile memory or system artifact collection and analysis.
  • Develop and identify indicators of compromise to communicate to Cybersecurity stakeholders and other Contract Services.
  • Provide adversary attribution and perform malware analysis and signature development.
  • Coordinate with CSOC Tier 1 and 2 services to remediate discrepancies and provide recommendations to prevent reoccurrence.
  • Serve as a C‑IRT member as required and operate under the direct control of the Government C‑IRT Commander.
  • Develop and coordinate courses of action with Government and contract stakeholders, and, when authorized, execute Defensive Cyberspace Operations‑Internal Defensive Measures on NGA networks and systems.
  • Develop, document, and provide incident investigation reports to the Government within 30 days of C‑IRT stand‑down, including adversary and friendly forces activity, host and network analysis, timelines, and recommendations for corrective actions, TTP changes, and other appropriate improvements.
  • Conduct quality‑control reviews of a percentage of closed CSOC Tier 2 tickets each week to ensure proper analysis, categorization, documentation, and notification.
Clearance Required

TS/SCI with ability to obtain a CI Polygraph.

Degree and Years of Experience

Bachelor’s degree and/or 6 years of experience in Cyber Security (CSOS).

Required Certifications
  • DoDD 8140.01 and DoD 8570.01‑M IAT Level II and CSSP Incident Responder.
Desired Skills/Certifications
  • Master’s degree.
  • IAT Level III.
Required Skills
  • Provide input to and coordinate with all applicable stakeholders to develop and deliver the daily CSOC Significant Activity Report, the daily CSOC Operations Update, and the Weekly CSOC Status Report.
  • Develop and coordinate courses of action with various Government and contract stakeholders, and when properly authorized, execute Defensive Cyberspace Operations‑Internal Defensive Measures on NGA networks and systems.
  • When properly authorized, execute custom scripts, tools, and capabilities to collect and analyze data and respond to incidents/events.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CSOC Tier 3 Cyber Engineer
CSOC Tier 3 Cyber Engineer

General Dynamics Information Technology • Springfield (VA)

On-site
USD 120,000 - 160,000
CSOC Tier 3 Cyber Engineer
CSOC Tier 3 Cyber Engineer

General Dynamics - IT • Springfield (VA)

On-site
USD 110,000 - 140,000
Cyber Security Operations Specialist III - Tier 3
Cyber Security Operations Specialist III - Tier 3

CACI International Inc • Springfield (VA)

On-site
USD 86,000 - 182,000
CSOC Analyst - Tier 3 Shift 1
CSOC Analyst - Tier 3 Shift 1

Abile Group, Inc • Springfield (VA)

On-site
USD 120,000 - 170,000
Cyber Security Operations Specialist - Tier 2
Cyber Security Operations Specialist - Tier 2

D2 Technical Services • Springfield (VA)

On-site
USD 90,000 - 95,000
Health/Dental/Vision
401(k) match
Accrued PTO
+1
Cybersecurity Operations Specialist 720
Cybersecurity Operations Specialist 720

(EDO) Entertainment Data Oracle, Inc. • St. Louis (MO)

On-site
USD 110,000 - 150,000
Flexible work environment
401(k) matching
Paid training and tuition
Cyber Security Operations Specialist II - CSOC Tier 2
Cyber Security Operations Specialist II - CSOC Tier 2

RISA • Springfield (VA)

On-site
USD 75,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth retirement savings plans
Paid Time Off
+1
CSOC Tier 3 Analyst - Incident Response Lead
CSOC Tier 3 Analyst - Incident Response Lead

Abile Group, Inc • Springfield (VA)

On-site
USD 120,000 - 170,000
Cyber Security Operations Specialist III - Tier 3
Cyber Security Operations Specialist III - Tier 3

CACI International Inc • St. Louis (MO)

On-site
USD 75,000 - 158,000
Cyber Security Operations Specialist III - Tier 3
Cyber Security Operations Specialist III - Tier 3

CACI • Springfield (VA)

On-site
USD 75,000 - 158,000