Cyber Security Tools Specialist Job at Evolver Federal, Reston, VA

YWRmUWUrUHMramh6N3FqMjEzTlhLMGRZb3c9PQ==
  • Evolver Federal
  • Reston, VA

Job Description

Evolver Federal is seeking a Cyber Security Tools Specialist to join our team responsible for operating and maintaining security configurations and applications in support of cyber threat intelligence and SOC operations, ensuring 24x7 availability for our federal customer. This is a fully remote role.

Responsibilities Include:

  • Develop and deploy new security intelligence tools, as well as support device and/or content research.
  • Develop and maintain detection rules in security tools.
  • Maintain, patch, operate and support the incident response tools.
  • Architect, deploy, test, maintain, patch, and operate any new tools supporting intelligence and security operations.
  • Provide system administration using configuration management tools to manage systems.
  • Manage and tune signature sets to maximize true positives and minimize false positives.
  • Document all tool tuning activities.
  • Responsible for contributing to daily operational update meetings and unscheduled situational update briefings for client leaders as needed.
  • Ability to analyze reports and provide technical recommendations for remediation security gaps.
  • Analyze reports to understand threat campaign techniques and lateral movements and extract indicators of compromise (IOCs).
  • Reference applicable departmental and operating administration policies in work products.
  • Recommend sound remediation and recovery strategies and suggest defensive policy enhancements and information technology procedures.
  • Provide forensic and network analysis to support risk-based decisions.
  • Able to work in an Agile Environment.
  • Perform threat detection and trend analysis. Understand and convey of the lifecycle of the network threats, attack vectors, and network vulnerability exploitation.

Basic Qualifications:

  • Bachelor's Degree or 4 additional years of applicable experience.
  • 3+ years of experience in systems administration / engineering.
  • 3 + years experience with Cyber Security tools such as: Trellix, Cisco Stealthwatch, VMRay, Teramind, Gurucul, AWS CloudWatch, Swimlane, Tenable, Malware Information Sharing Platform (MISP), Splunk, Sumo Logic.
  • 3+ years of experience with scripting languages such as JavaScript, Python, Perl, Groovy, Rudy, Bash, PowerShell, etc.
  • 3+ years of experience writing Splunk & Sumo Logic queries to create complex dashboards.
  • 3 + years or experience implementing the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework.
  • 3+ years of development/Scripting experience with tools such as Python, Bash, PowerShell, Rest API, Splunk.
  • 3 + years of experience with information security devices, including firewalls and intrusion detection and prevention systems, and applications, including security information management tools, such as Splunk and Sumo Logic.
  • 3+ years of experience with signatures, tactics, techniques, and procedures (TTP) associated with cyber threats and actors.
  • Must be a US Citizen.
  • Must be able to obtain a federal agency-specific clearance prior to starting.
  • Must have or be able to obtain a DoD Top Secret Clearance.
  • Must have and maintain at least two (2) active certifications, such as Network+CE, Security+CE, CASP, GSEC, GSLC, CISSP, CEH, CISM, or CISA

Preferred Qualifications

  • 4+ years of experience in systems administration / engineering.
  • 4 + years experience with Cyber Security tools such as Trellix, Cisco Stealthwatch, VMRay, Teramind, Gurucul, AWS CloudWatch, Swimlane, Tenable, Malware Information Sharing Platform (MISP), Splunk, Sumo Logic.
  • 4+ years of experience with scripting languages such as JavaScript, Python, Perl, Groovy, Rudy, Bash, PowerShell, etc.
  • 4+ years of experience writing Splunk and Sumo Logic queries to create complex dashboards.
  • 4 + years or experience implementing the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework.
  • 4+ years of development/Scripting experience with tools such as Python, Bash, PowerShell, Rest API, Splunk and Sumo Logic.
  • 4 + years of experience with information security devices, including firewalls and intrusion detection and prevention systems, and applications, including security information management tools, such as Splunk or Sumo Logic.
  • 4+ years of experience with signatures, tactics, techniques, and procedures (TTP) associated with cyber threats and actors.
  • Have an active DoD Top Secret Clearance.

Evolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law.

Job Posted by ApplicantPro

Job Tags

Full time, Remote job,

Similar Jobs

AID Performance Physical Therapy

Physical Therapist (Sports/Ortho) — Mentorship Track (New Grads Welcome) Job at AID Performance Physical Therapy

 ...Physical Therapist (Sports/Ortho) Mentorship Track (New Grads Welcome) AID Performance Physical Therapy | Ashburn, VA Salary: $76,000$100,000 + bonus potential | Full-time AID Performance Physical Therapy is hiring a Physical Therapist for our orthopedic and... 

Care Lync

Security Analyst - Tier 1 Job at Care Lync

 ...Role Overview Care Lync is hiring a Cybersecurity Analyst (Tier 1) to support day-to-day security operations, monitor threats, respond to alerts, and help maintain a strong security posture. This is a hands-on early-career role designed for someone who wants to... 

Headhunter Insider

Internal Medicine Physician Job at Headhunter Insider

 ...Internal Medicine Physician Compensation: Starting at $215K per year + Bonuses Job Type: Monday - Friday, 8am-5pm, full time and in person. Our client a well established healthcare system in Columbus, GA is seeking a Internal Medicine Physician to add to there... 

GFL Environmental

CDL Vacuum Truck Operator Job at GFL Environmental

 ...The Vacuum Truck Operator will work with the Vacuum Truck Services team to provide exceptional service to our clients. Services provided...  ..., confined space entry, spill cleanup, line flushing, power washing, water hauling, and loading and hauling of various fluids/ material... 

Palo Alto Networks

Finance Manager Job at Palo Alto Networks

 ...week to collaborate and thrive, together! Job Description Your Career Palo Alto Networks is looking for an experienced finance professional to join its FP&A team as a Finance Manager to help support Workplace Resources in the G&A organization.Were looking...