Security Analyst - Tier 1
CVP (Customer Value Partners) · Kansas City, MO · 2 wk ago
Full-time
CVP is an award-winning healthcare and next-gen technology consulting firm recognized for excellence and innovation in the solutions we provide to clients across healthcare, national security, and the public sector.
About the role
We are seeking a Security Analyst to join our team of experts tasked with securing the critical networks and systems our clients depend on. This is a hybrid position with onsite work two days a week in Kansas City, Missouri and remote work three days a week.
Responsibilities
- Perform cybersecurity activities as part of a team in an organization’s 24x7 Security Operations Center (SOC).
- Use data collected from a variety of cyber defense tools (e.g., intrusion detection system (IDS) alerts, firewalls, network traffic logs, Security Incident and Event Management (SIEM)) to analyze events for mitigating threats.
- Work with stakeholders to resolve computer security incidents and vulnerability compliance.
- Conduct vulnerability scans and recognize vulnerabilities in security systems.
- Apply cybersecurity and privacy principles to organizational requirements (confidentiality, integrity, availability, authentication, non-repudiation).
- Apply techniques for detecting host and network-based intrusions using intrusion detection technologies.
- Interpret information collected by network tools (e.g., Nslookup, Ping, and Traceroute).
- Characterize and analyze network traffic to identify anomalous activity and potential threats.
- Coordinate with SOC team and cyber defense staff to validate network alerts.
- Document and escalate incidents, including event history, status, and potential impact.
- Perform event correlation using information from various sources to gain situational awareness.
- Provide daily summary reports of network events and activity relevant to cyber defense practices.
- Receive and analyze network alerts to determine possible causes.
- Provide timely detection, identification, and alerting of possible attacks, anomalous activities, and misuse.
- Use cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity.
- Examine network topologies to understand data flows.
- Identify and analyze anomalies in network traffic using metadata (e.g., CENTAUR).
- Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools.
- Isolate and remove malware.
- Identify applications and operating systems of network devices based on network traffic.
- Notify designated managers, cyber incident responders, and stakeholders of suspected cyber incidents.
- Detect host and network-based intrusions via intrusion detection technologies (e.g., Snort).
- Recognize and categorize types of vulnerabilities and associated attacks.
- Monitor security events involving high-value assets.
- Conduct computer network defense (CND) triage, including:
- Determine scope, urgency, and potential impact.
- Identify specific vulnerabilities.
- Recommend remediation actions.
- Prepare reports on incident findings for appropriate agencies.
- Maintain appropriate technical and procedural documentation.
- Document all investigative activity in tracking/ticketing systems.
- Follow up with support teams on actions until completion.
- Build and maintain client and stakeholder relationships.
- Complete projects, tasks, and deliverables on time and with quality.
Requirements
- One (1) year of related technical professional experience.
- Security+ certification.
- Must be eligible to obtain a Public Trust government security clearance.
- Strong analytical, troubleshooting, and problem-solving skills for cybersecurity.
- Excellent communication skills, both written and oral.
- Knowledge of NIST and FISMA guidelines preferred.
- 4-year college degree in Computer Science or related field preferred.
Skills
- Previous experience with Microsoft Defender for Endpoint (ATP), Tanium, and Splunk (desired).
Schedule
Day shift, hybrid (onsite two days a week in Kansas City, Missouri and remote three days a week).