Job Description
Key Role:
Apply an advanced understanding of monitoring, analyzing, detecting, and responding to cyber threat events and incidents in information systems and networks. Contribute to an integrated, dynamic cyber defense and leverage cybersecurity solutions to deliver cybersecurity operational services, including intrusion detection and prevention, situational awareness of network intrusions, security events, data spillage, and incident response actions. Provide leadership and mentoring for junior employees, contribute to the development of innovative principles and ideas, work on unusually complex problems, and provide solutions that are highly creative. Act as the leader on large programs and projects that affect the organization's long-term goals and objectives, lead investigations that form part of a wider diverse team of analysts, and conduct event detection, incident triage, incident handling, and remediation. Handle major, high-impact incidents, generate clear, concise recommendations, and coordinate activities and professional communications across a range of stakeholders. Work closely with security teams to develop, tune, automate, and enhance network and host-based security devices, support the SOC with managing the response to cyber intrusions, perform extensive network and host triage, maintain strict chain-of-custody protocols, analyze documentation and reports, and perform remediation, as required.
Basic Qualifications:
- 3+ years of experience with providing cyber incident response as part of a Computer Incident Response Team (CIRT), Computer Emergency Response Team (CERT), Computer Security Incident Response Center (CSIRC), or Security Operations Center (SOC)
- Experience with best practices, security tools, and techniques used by Cybersecurity teams
- Experience with performing host-based analysis of Windows, Linux, and Mac
- Experience with analyzing data from a variety of security tools and sources, including IDS alerts, firewall logs, weblogs, and network traffic logs to identify IOCs or malicious TTPs
- Ability to review alerts to determine relevancy and urgency and provide feedback and tuning recommendations
- Ability to identify, detect, respond, and mitigate sophisticated threats to the enterprise environment
- Top Secret clearance
- Associate's degree
- CySA+ Certification
Additional Qualifications:
- Experience with forensics tools, FTK, Encase, Wireshark, or SIFT
- Experience with creating custom Splunk dashboards and queries
- Experience with using Microsoft Excel
- Ability to discover and support new analytic methods for detecting threats
- Ability to be self-driven, work independently, and handle multiple tasks concurrently
- Ability to create reports for leadership
- Possession of excellent oral and written communication skills
- IAM Level III or IAT Level III Certification
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $93,300.00 to $212,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees.Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
- If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
- If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.
EEO Commitment
We’re an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change – no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.