Cyber Security Analyst (SOC) at Clark Creative Solutions San Diego, CA

Comunidade Metodista

San Diego (CA)

On-site

USD 110,000 - 150,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Clark Creative Solutions in San Diego, CA seeks a Cyber Security Analyst to join the SOC team. The role focuses on analysis of devices and networks, forensic review of Windows/Linux systems, and threat hunting across on-premises and cloud environments.

The ideal candidate will have multi-OS experience, familiarity with IOC patterns, and the ability to synthesize attack life cycles into comprehensive reports for technical and non-technical stakeholders.

Qualifications

  • 3+ years in security operations, analytical duties, host or network security analysis.
  • Experience with SIEM platforms and incident response processes.
  • Familiarity with DoD policies and procedures is a plus.

Responsibilities

  • Support SOC operations in monitoring, incident response, malware analysis, and threat hunting.
  • Develop analytics on SIEM to monitor security alerts and coordinate artifact collection.
  • Assess STIGs compliance and verify asset inventory.
  • Handle IVAM notifications and analyze network structures for risks.
  • Analyze network traffic and logs to identify malicious activity and triage incidents.
  • Produce formal reports for technical and non-technical audiences.

Skills

SOC operations
Threat hunting
Incident response
Log analysis
Forensics
Network security
Windows/Linux OS

Education

Bachelor's degree in CS/IS

Tools

Palo Alto
Elastic SIEM
Splunk
Cribl
VMware
Security Center

Job description

Cyber Security Analyst (SOC) job at Clark Creative Solutions. San Diego, CA. The Cyber Analyst team member is responsible for the analysis of all technology devices which may include Operational Technology (OT) and Industrial Control Systems (ICS) as well as on-premises and cloud enterprise networks. This includes analysis of device communication, forensic analysis of Windows or Linux systems and servers, timeline analysis of activity on these endpoints, user permission and authentication audits, log analysis, and malware identification/triage.

An ideal candidate for this position will be a proactive self-starter who has experience with system administration, Windows and Linux operating systems (OS) mechanics including filesystem structures, disk and memory forensics, cyber aware Operational Technology or Control Systems operators, commonly used mechanisms for maintaining security persistence, privilege escalation, and lateral data movement, operating system log analysis, and triaging suspicious file artifacts for unusual behavior. This role requires a familiarity with what routine OS activities and common software/user behavior looks like in the context of forensic artifacts or timelines. Analysts should also be familiar with common categories and formats of host-based indicators of compromise (IOCs) and how/where they can be leveraged to identify known-bad files/activity on an endpoint. Candidate will utilize the Cyber Kill Chain and synthesize the entire attack life cycle along with creating detailed reports on how impacts may or have occurred.

Responsibilities
  • Support SOC team in operating and performing duties in a Security Operations Center (SOC) to provide a secure environment that facilitates monitoring, incident response, malware analysis, and threat hunting activities.
  • Develop and utilize analytics on the security information and event management (SIEM) platform to monitor for security alerts and coordinate vulnerability assessments and artifact collection across servers and network devices.
  • Asses Security Technical Implementation Guides (STIGs) compliance and completion.
  • Utilize asset mapping tools to verify connected inventory.
  • Handle Information Assurance Vulnerability Management (IVAM) notifications.
  • Evaluate network structures and device configurations for security risks, offering recommendations based on best practices, and gather data to identify and respond to network intrusions.
  • Analyze network traffic and system logs to identify malicious activities, vulnerabilities exploited, and methods used, and develop processes to enhance SOC response and efficiency.
  • Conduct comprehensive technical analyses of computer evidence, research and integrate new security tools into the SOC, and synthesize findings into reports for both technical and non-technical audiences.
Qualifications (Journeyman level) At least 3 years, (Junior level) applicable 1 to 2 years of experience in security operations, demonstrating analytical duties and preforming host or network security analysis.

Proficient in analyzing cyber-attacks, with a deep understanding of attack classifications, stages, system/application vulnerabilities, and compliance with Department of Defense (DoD) policies and procedures.

Applied knowledge of network topologies, protocols (e.g., TCP/IP, ICMP, DNS, SSH, SMTP, SMB), and experience with tools like Palo Alto, Elastic SIEM, Cribl, Splunk, VMware, Security Center.

Capable of attack reconstruction based on network traffic, integrating Threat Intelligence, and familiar with MITRE ATT&CK framework, with the ability to collaborate effectively across multiple locations.

Desired Skill sets
  • Knowledge of Operational Technology (OT) or Industrial Control Systems (ICS)
  • Strong analytical and troubleshooting skills
  • Able to provide expert content development in Splunk Enterprise Security using tstats and data models
  • Understands how to utilize knowledge of latest threats and attack vectors to develop correlation rules for continuous monitoring on various security appliances
  • Experience in other tools and protocols as applicable such as Nessus, Endgame, CrowdStrike, Gray Noise, Shodan, Bacnet, MODBus, SCADA systems, and PCAP
  • Review logs to determine if relevant data is present to accelerate against data models to work with existing use cases
  • Familiar with the operations and functions of Nessus or security center management
  • Can assist and provide technical input to research, discover, implement hardware and software
  • Understands importance and fundamentals of logistics and evidence handling

Certified Ethical Hacker (CEH), GIAC Certified Incident Handler (GCIH), or relevant IT technology certification

Examples of other certifications include:
  • o Offensive Security Certified Professional (OSCP)
  • o GIAC Response and Industrial Defense (GRID)
  • o CERT Certified Computer Security Incident Handler
  • o ECC CEH (Electronic Commerce Council Certified Ethical Hacker)
  • o GCIH (GIAC Certified Incident Handler)
  • o GISF (GIAC Information Security Fundamentals)
  • o CISSP (Certified Information System Security Professional)

Additional certifications at an equivalent may also be considered.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center Analyst
Security Operations Center Analyst

Colossus Technologies Group • Springfield (MA)

Hybrid
USD 120,000 - 150,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Cyber Security Analyst
Cyber Security Analyst

Compunnel, Inc. • San Antonio (TX)

On-site
USD 85,000 - 110,000
Cyber Network Defense Analyst
Cyber Network Defense Analyst

Base One Technologies • Washington

On-site
USD 65,000 - 85,000
Security Operations Center (SOC) Analyst / Engineer
Security Operations Center (SOC) Analyst / Engineer

Zoho • United States

On-site
USD 110,000 - 160,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Cyber Network Defense Analyst
Cyber Network Defense Analyst

Base One Technologies • Springfield (MA), Northern (KY)

On-site
USD 55,000 - 85,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Cyber Security Analyst -
Cyber Security Analyst -

thehivecareers.co • Oregon (WI)

On-site
USD 75,000 - 95,000