Cybersecurity Operations Specialist -SIEM Services (Evergreen)

General Dynamics Information Technology, Inc.

St. Louis (MO)

On-site

USD 128,000 - 173,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical plan with HSA
Dental plan
Vision plan
401(k) with company match
Flexible work weeks
Paid time off

Job summary

General Dynamics Information Technology, Inc. is seeking a Cybersecurity Operations Specialist to join the Cybersecurity Data Analysis Services team in At Louis, MO.

The role involves designing, building, testing, configuring, operating, and refreshing the SIEM and analytics platforms to protect government networks. The candidate will maintain 99.99% service availability, develop SIEM rules, and coordinate with government management for urgent maintenance actions, while ensuring compliance with

Qualifications

  • Active TS/SCI clearance.
  • US Citizenship required.
  • 6+ years of related experience.
  • DoD 8570.01-M IAT Level II and CSSP Infrastructure Support certs.

Responsibilities

  • Maintain system availability to 99.99%.
  • Provide preventative and corrective maintenance for SIEM services.
  • Configure assets per government standards and tools.
  • Develop and maintain SIEM use cases and rules.
  • Document changes and manage incident response actions.

Skills

SIEM experience
Alert rules
ArcSight
ElasticSearch
Kibana
Linux (RHEL)
TA knowledge
Event flow troubleshooting
DoDIN/IC/DoD knowledge
Active TS/SCI Clearance

Education

DoD 8570.01-M IAT Level II
CSSP Infrastructure Support

Tools

ArcSight
Kibana

Job description

Type of Requisition: Pipeline Clearance Level Must Currently Possess: Top Secret/SCI Clearance Level Must Be Able to Obtain: Top Secret SCI + Polygraph Public Trust/Other Required: None Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Analytics, ArcSight SIEM, ElasticSearch, Kibana Certifications: None Experience: 6 + years of related experience US Citizenship Required: Yes

Job Description:

GDIT is seeking a motivated, career and customer-oriented Cybersecurity Operations Specialist to perform on our Cybersecurity Data Analysis Services team in At Louis, MO. The team member shall provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) capability (i.e. Enterprise Audit), long-term analytics platform, log aggregation platform, and the cyber threat intelligence capability, signature development and deployment, and reputation management services. This includes the onboarding of all new and existing IT resources, and ensuring the correct routing of all audit events to mission partners in accordance with Intelligence Community Standards (ICS) 500-27.

Job Duties Include:
  • Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability.
  • This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software
  • Maintain system availability and reliability with a threshold of 99.99%
  • Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation
  • Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes.
  • This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform
  • Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management
  • Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions
  • Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.
  • Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost)
  • Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NCE laws, directives, orders, polices, guidance, procedures etc.
  • Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list.
  • This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN – Joint Incident Management System, DoD CIO – DoD Scorecard/Get to Green reporting, IC CIO – Cybersecurity Performance Evaluation Model reporting, etc.)
  • Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions
  • Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services
Required Skills:
  • SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)
  • Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules
  • Create SIEM playbooks
  • Linux (RHEL) Expert (administration and engineering)
  • Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives
  • Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events
  • Creation of ArcSight rules based on use cases of malicious events
  • Tuning and aggregation of queries and filters
  • Skilled in troubleshooting event flow through Enterprise Audit infrastructure
  • Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools
  • Active TS/SCI Clearance
  • DoW 8570.01-M IAT Level II and CSSP Infrastructure Support certifications 6+ years
  • Experience with SIEM and Development Projects 6+ years
  • Experience with SIEM support for projects and technical exchange meetings 6+ years
  • Experience developing and maintaining enterprise audit projects
Desired Skills:
  • Kibana Data Analytics

The likely salary range for this position is $128,039 - $173,229. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours: 40 Travel Required: None Telecommuting Options: Onsite Work Location: USA MO St. Louis Additional Work Locations:

Total Rewards at GDIT:
  • The benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.
  • To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
  • We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Opportunity Owned From working with technologies like AI, cyber and cloud to careers in intelligence and health, we offer endless opportunities to apply your expertise to create a safer, smarter world.

For more information about GDIT's Privacy Policy, click here: Privacy Policy | GDIT

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Operations Specialist -SIEM Services (Evergreen)
Cybersecurity Operations Specialist -SIEM Services (Evergreen)

General Dynamics Information Technology, Inc. • Springfield (VA)

On-site
USD 128,000 - 173,000
Cybersecurity Operations Specialist -SIEM Services (Evergreen)
Cybersecurity Operations Specialist -SIEM Services (Evergreen)

General Dynamics Corporation • Springfield (VA)

On-site
USD 128,000 - 173,000
CSSP DCO Analyst
CSSP DCO Analyst

General Dynamics Information Technology, Inc. • Bellevue Second IV Precinct (NE)

On-site
USD 98,000 - 117,000
Health benefits
401K with company match
Educational Assistance
Cyber Intrusion Detection System Administrator - TS/SCI with Polygraph
Cyber Intrusion Detection System Administrator - TS/SCI with Polygraph

General Dynamics Information Technology, Inc. • Reston (VA)

On-site
USD 149,000 - 201,000
Growth opportunities
Internal mobility team
Comprehensive benefits & 401K
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

General Dynamics Information Technology, Inc. • Springfield (VA)

On-site
USD 164,000 - 209,000
ISSO - TS/SCI w/Polygraph
ISSO - TS/SCI w/Polygraph

General Dynamics Information Technology, Inc. • Bethesda (MD)

On-site
USD 152,000 - 207,000
Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Corporation • Bossier City (LA)

On-site
USD 146,200 - 197,800
Growth opportunities
Internal mobility team
Competitive benefits
Cyber Security Analyst Senior Advisor
Cyber Security Analyst Senior Advisor

General Dynamics Information Technology, Inc. • Tampa (FL)

On-site
USD 110,000 - 150,000
401K with company match
Health and wellness packages
Internal mobility
+3
Information Security Director
Information Security Director

General Dynamics Information Technology, Inc. • Bellevue Second IV Precinct (NE)

On-site
USD 170,000 - 205,000
Health benefits
401(k)
Education assistance
+2
CSSP DCO Analyst
CSSP DCO Analyst

General Dynamics Information Technology • Omaha (NE)

On-site
USD 87,000 - 117,000
Health benefits (Medical/Dental/Vision
401K with company match
Educational Assistance and eLearning
+2