Cyber Security Analyst
Current
Sterling, Virginia, United States
- Monitoring cybersecurity threat detection systems.
- Monitoring agency systems and daily log events to identify potential security threats. Sources include, but not limited to, sensor alert logs, firewall logs, content filtering logs, and Security Event Manager.
- Collecting, analyzing and reporting threat information.
- Responding to alerts and reports of suspicious cyber events.
- Reviewing all incoming alerts, investigating, and ticketing all identified potential security threats using agency incident response-ticketing platform.
- Initiates daily SOC tool checks, using alert triage & analysis to operate efficiently amongst monitor logs in Splunk ES and IBM QRadar (SIEM Security Information Event Management) to solutions, and provide.