SOC Lead
Company: KeyLogic
Location: Sterling
Posted on: March 16, 2023
|
|
Job Description:
KeyLogic is supporting a U.S. Government customer on a large
mission critical development and sustainment program to design,
build, deliver, and operate a network operations environment;
including introducing new cyber capabilities to address emerging
threats. KeyLogic is seeking a Security Operations Center Lead.
The SOC Lead will lead a team of security engineers with extensive
technical experience in enterprise data networks, systems
engineering and architecture, security monitoring, capacity
planning, systems engineering, cloud infrastructure, and
troubleshooting. The team's primary mission is to manage SOC and
incident response teams by delivering and operating critical
network threat detection and forensics services. The services
include IDS/IPS, SIEM, case management, and packet capture.
Responsibilities Include:
* Plans, directs, and coordinates the Security Operations Center
for the program.
* Work closely with technical leadership (government / program /
management)
* Develop and present performance reports and metrics
* Develop and meet performance management requirements
* Provide technical leadership for an engineering team of cloud
security specialists.
* Consult with cloud team and leadership to set the direction for
security monitoring and threat detection.
* Ensure the successful integration of cloud logging and security
monitoring services with SIEM.
* Direct the development and implementation ofrules/signatures in
SIEM, and other monitoring platforms, to detect and alert on
suspicious activity in Raytheon's public cloud environments.
* Direct the deployment and management of cloud logging and
security monitoring services for AWS and Azure Cloud
environments.
* Provide guidance and direction on operations for cloud-based
Cyber Defense systems and services
* Support cloud-related service migrations to AWS or Azure.
* Provide guidance on system administration of Cloud based
automation tools.
* Direct the development of Infrastructure-as-Code playbooks (e.g.
Terraform)
* Ensure testing and evaluation of new cloud services.
* Direct a team on Incident Response / security investigations in
cloud environments.
* Ensures proper implementation of required government policy
(i.e., NISPOM, DCID 6/3, ICD, NIST) and others leading team to
ensure compliance across all activities
Required Skills:
* U.S. Citizenship
* Active Secret clearance. Must be able to obtain a TS/SCI
clearance
* Must be able to obtain DHS Suitability
* 4+ years management in SOC environments in both personnel and
technology to include all aspects of personnel management including
hiring, performance management, training/compliance, annual salary
planning and all other dimensions.
* 10+ years of directly relevant experience
* Minimum 3 years of professional experience working with AWS &
Azure infrastructure and services in a security focused role.
* Advanced knowledge of AWS & Azure architectural concepts.
* Experience developing and implementing SIEM threat detection
rules.
* Demonstrated experience administering Linux based systems.
* Excellent written and oral communication skills
Desired Skills:
* Information Security and IT certifications: Cisco, Red Hat, AWS,
etc.
* Experience administering cyber security tools such as Firewalls,
SIEM, and PCAP
* Experience with security log analysis.
* Experience working on a Computer Incident Response Team
(CIRT)
* Previous experience working in a Security Operations Center
(SOC)
* Virtualization technologies, e.g. VMWare, HyperV, etc.
* Automation and IaC tooling, e.g. Ansible, Terraform, etc.
* Scripting in Python or Perl
* "Big Data" Analysis systems, e.g. Splunk, ELK, etc.
* Understanding of Project Management and SDLC methodologies,
especially Agile.
* Experience with CNAPP
Required Education:
* Bachelor's Degree in systems engineering, a related specialized
area or field.
* Two years of related work experience may be substituted for each
year of degree level education.
Desired Certifications:
* GIAC, CISSP
Keywords: KeyLogic, Sterling , SOC Lead, Other , Sterling, Virginia
Click
here to apply!
|