Job Description
Key Role:
Join our Security Operations Center (SOC) team as an experienced Cyber Analytics Developer. Support the development of custom analytics using machine learning, AI, or statistical modeling to detect advanced threats and anomalies. Evaluate and enhance analytics regularly based on threat intelligence and security operations findings. Design, build, and maintain analytic content that helps detect, monitor, and respond to cybersecurity threats. Collaborate with analysts to develop meaningful analytics that can be utilized by the client. Integrate advanced analytics into threat detection processes enabling adaptive defenses and predictive threat modeling. Develop custom analytics, dashboards, and detections to identify sophisticated attack patterns targeting applications and systems. Establish a dynamic knowledge base of analytics and historical analysis, ensuring analysts have access to content for better decision-making. Be able to fine tune alerts to reduce false positives and improve accuracy. Develop adaptive incident response models using AI-powered or similar technologies for behavioral analytics and make recommendations on how to provide better predictive incident analysis. Create detection logic, playbooks, and dashboards that enable proactive threat detection. Create dashboards for SOC analysts to monitor threats in real time. Build executive-level reports on detection coverage and SOC effectiveness. Provide visibility into attack campaigns, trends, and threat actor behaviors. Help the SOC with improved threat visibility across the enterprise and reduce analyst fatigue from false positives. Work with threat and research teams to develop playbooks to automate repetitive security tasks. Create scripts such as Python, PowerShell, and SQL, to process and enrich security data. Integrate threat intel feeds such as IOCs, IOBs, and YARA rules. Translate adversary TTPs into hunt queries and detection logic. Support cyber threat hunters with enriched analytics.
Basic Qualifications:
- 10+ years of experience developing cyber analytics
- Experience with the development of custom detection rules such as queries, correlation rules, and alerts, in SIEMs, including behavioral analytics based on attacker TTPs
- Experience using statistical and machine learning models to spot anomalies or rare events
- Experience with customizable dashboards such as Splunk and MISP, as well as visualization tools such as Tableau, Power BI, or AWS or Azure Cloud dashboards
- Ability to perform data analytics and threat modeling by analyzing log sources such as network, endpoint, cloud, and identity, to determine what data can be used for detection
- Secret clearance
- Bachelor’s degree
Additional Qualifications:
- Experience working in a SOC or cyber operations environment
- Ability to write succinct briefings, presentations, and reports to convey analysis, threat trends, threat actor profiles, indicator bulletins, vulnerability details, and defensive strategies to varied audiences
- CISSP, GCTH, GCTI, GCIH, CEH, OSCP, or equivalent Certification
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,800.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity Statement
As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
- If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
- If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.