ARSIEM logo

Incident Handler Tier I

ARSIEM

Monterey, CAJobNo compensation foundTracked 1mo agoSeen in employer's feed 1w ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Monterey, CA
Work Authorization
US work authorization required

Requirements

Credentials this posting asks for.

Sec+CompTIA CySA+EC-Council CEHGIAC GCIAMicrosoft AZ 900Palo Alto Networks PCCETSplunk Core Certified Advanced Power UserSecret clearanceBachelor's degree

Job overview

ARSIEM is hiring an Incident Handler Tier I. ARSIEM Corporation is seeking a motivated Incident Handler Tier I to join their team in Monterey, CA. This role offers on-the-job training in cybersecurity incident response processes, procedures, and remediation practices. The successful candidate will work in a Cyber Security Operations Center (CSOC) and gain experience with various cyber tools, supporting government clients.

Key focus areas include Use the SIEM tool to receive security alerts, perform initial investigations, and provide damage assessments based on findings, Review the latest alerts/events from various sensors to determine relevancy and urgency, and Enrich incidents with open source and/or other sources of information to handle incidents accurately.

Successful candidates bring 1+ Year Professional Experience In IP Network Planning And Management, UNIX/Linux System Administration, Windows Administration, Software Engineering Or Development, Bachelor's Degree In Computer Science, Engineering, Information Technology, Cybersecurity, Or Related Field, and Sec+. Important skills include IP Network Planning And Management, UNIX/Linux System Administration, Windows Administration, Software Engineering, Software Development, and SIEM. Preferred (not required): Endpoint Protection, Network Access Controller, Cloud Security, and Vulnerability Management.

Skills & qualifications

RequiredNice to have

Skills

IP Network Planning and ManagementUNIX/Linux System AdministrationWindows AdministrationSoftware EngineeringSoftware DevelopmentSIEMEndpoint ProtectionNetwork Access ControllerCloud SecurityVulnerability ManagementSecurity AlertsInitial InvestigationsDamage AssessmentsTicketing SystemMitigationsEvidence IntegrityCSOC Standard Operating ProceduresNational StandardsNetwork Activity MonitoringMalware ProtectionRestrict/Prevent External DevicesSpam FiltersNetwork Access ControllersACLsVulnerabilitiesAssociated AttacksThreat HuntingMalware-Related ActivityFeedbackTechniques and ProceduresDetecting Host and Network-Based IntrusionsIncident Handling TasksSecurity Monitoring ToolsIDSFirewallAccess Control Lists

Qualifications

1+ Year Professional Experience in IP Network Planning and Management, UNIX/Linux System Administration, Windows Administration, Software Engineering or DevelopmentBachelor's Degree in Computer Science, Engineering, Information Technology, Cybersecurity, or Related FieldSec+Active Secret ClearanceUS CitizenCompTIA CySA+EC-Council CEHGIAC GCIAMicrosoft AZ 900Palo Alto Networks PCCETSplunk Core Certified Advanced Power User

Full job description

About ARSIEM Corporation

At ARSIEM Corporation we are committed to fostering a proven and trusted partnership with our government clients. We provide support to multiple agencies across the United States Government. ARSIEM has an experienced workforce of qualified professionals committed to providing the best possible support.

As demand increases, ARSIEM continues to provide reliable and cutting-edge technical solutions at the best value to our clients. That means a career packed with opportunities to grow and the ability to have an impact on every client you work with.

ARSIEM is looking for a motivated individual for an Incident Handler Tier 1 position offering on-the-job training (JOT) on cybersecurity incident response processes, procedures, and remediation practices. This is a great opportunity to work in a Cyber Security Operations Center (CSOC) and gain experience with cyber tools such as SIEM, Endpoint Protection, Network Access Controller, Cloud security, Vulnerability scanning, and additional proof of concept technologies. This position will support one of our government clients in Monterey, CA.

Responsibilities

  • Use the SIEM tool to receive security alerts, perform initial investigations, and provide damage assessments based on findings

  • Review the latest alerts/events from various sensors to determine relevancy and urgency.

  • Enrich incidents with open source and/or other sources of information to handle incidents accurately.

  • Appropriately document all alerts/incidents in the approved ticketing system.

  • Analyze and request, recommend, or implement mitigations.

  • Preserve evidence integrity according to CSOC standard operating procedures or national standards.

  • Monitor network activity using cybersecurity tools to protect against malware. (Endpoint protection, restrict/prevent external devices, spam filters, Network access controllers, ACLs)

  • Recognize and categorize types of vulnerabilities and associated attacks (threat hunting and sharing)

  • Use CSOC security tools to Identify, capture, contain, and report on malware-related activity

  • Provide feedback to improve techniques and procedures used for detecting host and network-based intrusions

  • Learn and follow procedures and make recommendations as needed to fine-tune these processes

  • Execute incident handling tasks as delegated by senior peers and CSOC leadership

  • Handle other tasks that a Tier 1 level of experience and talent can complete.

  • Under supervision, may manage and configure security monitoring tools (SIEM, IDS, Firewall, Access Control Lists, etc.) to mitigate existing threats/vulnerabilities.

Minimum Qualifications

  • Minimum of one (1) year of professional experience in MORE THAN ONE of the following: IP network planning and management, UNIX/Linux system administration, Windows administration, software engineering or development; AND/OR a bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, OR related field.

  • Certification: Sec

    • Must obtain one of the following certificates within 6 months of hire date: CompTIA CySA+, EC-Council CEH, GIAC GCIA, Microsoft AZ 900, Palo Alto Networks PCCET, Splunk Core Certified Advanced Power User

The ARSIEM pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other laws.

Benefits:

For an overview of our benefits, please visit our benefits tab.

https://www.arsiem.com/careers/

Original Posting Date:

2024-11-15

Clearance Requirement : This position requires an active Secret clearance. You must be a U.S. citizen for consideration.

Candidate Referral : Do you know someone who would be GREAT at this role? If you do, ARSIEM has a way for you to earn a bonus through our referral program for persons presenting NEW (not in our resume database) candidates who are successfully placed on one of our projects. The bonus for this position is $3,500, and the referrer is eligible to receive the sum for any applicant we place within 12 months of referral. The bonus is paid after the referred employee reaches 6 months of employment.

ARSIEM is proud to be an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other federally protected class.

You've read the whole posting — now see how you match it.