Cybersecurity Analyst
SAIC · Austin, TX · 1 wk ago
Information TechnologyFull-time
About the role
SAIC is seeking a senior network security analyst to join our team supporting a major state & local government customer. This on-site role acts as both an Armis Centrix tool administrator and a SOC Tier 3 analyst, with potential involvement in Security Incident Response Team operations. The position supports dedicated work functions for a state government agency and reports to the Security Director.
Responsibilities
- Own and manage baseline configurations, policies, and front-end operations for Armis.
- Collaborate with Armis as a vendor for architecture and engineering implementation concerns.
- Perform network security, cybersecurity defense & analysis, incident response, threat analysis, exploitation analysis, vulnerability analysis, and incident investigations.
- Monitor systems for abnormal events using COTS/GOTS applications, ticketing systems, lab systems, forensic applications, and custom tools, techniques, and procedures (TTPs).
- Determine if events qualify as incidents and assess whether they result from malicious or suspicious actions by threat actors.
- Utilize threat intelligence to identify if incidents are part of a named campaign and determine appropriate response levels or contribute new intelligence to threat intelligence teams.
- Obtain information and evidence for legal proceedings, government counterparts, HR investigations, or management actions.
- Restore affected systems to secure baseline configurations in coordination with system owners.
- Coordinate with contracted vendors for incident control.
- Research, evaluate, and recommend new security tools, techniques, and technologies.
- Support cyber metrics development, maintenance, and reporting for managed tools.
- Provide briefings to senior staff and state government agency executives.
Requirements
- BS Degree and five (5) years or more experience; Masters and three (3) years or more experience; or PhD with 0 years related experience.
- Complete understanding and wide application of technical principles, theories, and concepts in the cybersecurity field.
- Ability to receive assignments as objectives and establish goals to meet outlined objectives.
- General knowledge of related IT disciplines.
- Must be a US Citizen able to pass and maintain a CJIS Criminal Justice background investigation.
Qualifications
- Security+ or higher certification.
- Armis 201 or higher class certification.
- Experience providing technical solutions to complex problems requiring analysis of identifiable factors.
- Independent development of approaches to solutions with work reviewed for adequacy.
- Good judgment in selecting methods and techniques for obtaining solutions.
- Contribution to the completion of specific programs and projects within government contracting.
Preferred Experience
- ITIL v4 certification (Foundation or above).
- CEH, GCIH, BTL2, CASP, or GSP certifications.
Schedule
Full-Time, Day Shift