SOC Analyst
About the program
Waterleaf International, an engineering, cybersecurity and science-based defense and networking contractor, is seeking a full-time SOC Analyst. Waterleaf hires, trains and promotes the best and brightest for upward mobility and the opportunity to grow and succeed. We offer excellent benefits (Medical/Dental/PTO/Tuition) and more.Waterleaf offers a forward leaning culture – that means our focus and direction is on people, intellect, process and deliverables. Our people include employees, contractors, and customers, all of whom have inherent value and contributions to not only our mission in defending our country but to the community we each live in. We support professional and individual growth and provide dynamic, fascinating, and supportive work environments. Talk to us about the ability to have great financial and personal gains in a thriving and vital environment.
What you'll do
Understand and apply analyst responsibilities for all Cyberleaf customer tiersUnderstand the Direct Customer and MSP Customer differences and how those differences affect analyst customer engagementExhibit capacity to rapidly learn and apply the SOP for the main Cyberleaf analyst workspaceIdentify an alertUsing initial alert indicators conduct follow-on cross-correlation analysis in Splunk SIEM or a variety of Endpoint Detection and Response productsConduct delegated remediation actions to isolate and eradicate the threatEngage in bilateral communication with customers to inform, validate, and action the alertConduct additional customer-approved remediation actions if pre-approved actions fail to achieve the effectUse company Standard Operating Procedures (SOP) and runbooks to respond within the SLA timelinesCommunicate with Direct customers or Managed Service Providers to explain the nature and impact of relevant alerts, request clarification on documented activityContribute to Direct Customers’ IT points of contact or their Managed Service Providers’ efforts to remediate the alert as a technical resource to monitor customers’ Cybersecurity needs.Document all actions taken to remediate a ticket in the main Cyberleaf analyst workspaceContribute to runbook and SOP documentation based on discovered best practices, lessons learned discoveries, or feature/capability upgradesDevelop and implement Splunk queries as part of investigations into suspicious and malicious cyber activity.Contribute to development and testing of new capabilities, signatures, or features as requested by the Development TeamOther job duties, as assigned.
Eligibility
Associates of Science in Computer Science, CyberSecurity or equivalent industry or government work experience required.CompTia Network+ and Security+ certificationsMust have working knowledge of Splunk and Splunk ES.Proficiency in Microsoft Office tools;Understanding of and competency with industry-leading ticketing systems.
Good to know
Remote opportunity