Logo
Clearance Jobs

Cybersecurity Analyst Watch Floor Operations

Clearance Jobs, Huntsville, Alabama, United States, 35801

Save Job

Cybersecurity Analyst/Watch Floor Operations

Supports the cybersecurity watch floor, playing a crucial role in a government agency's cybersecurity defense strategy. Operating around the clock, 24/7, 365 days a year, this dynamic team ensures the timely detection and resolution of potential security incidents, thereby minimizing the impact of cyber threats on the organization. Comprising of skilled security professionals, the watch floor team is responsible for actively detecting, monitoring, preventing, and analyzing real-time cybersecurity information, events, and threats. Serving as the operational hub, the watch floor plays a critical role in safeguarding the confidentiality, integrity, and availability of the organization's information assets. Activities and responsibilities include: Monitor cybersecurity dashboards and alerts on a 24/7/365 watch floor Analyze security events to identify suspicious behavior or potential incidents Escalate and coordinate response efforts for active threats Maintain situational awareness of current threats and vulnerabilities Assist in tuning and improving alerting thresholds in SIEM tools Create and maintain standard operating procedures (SOPs) Participate in cybersecurity drills and incident response exercises Collaborate with intelligence and threat analysis teams to enhance detection capabilities Document incidents and contribute to after-action reviews and reports Provide input on improving cybersecurity architecture and tooling Skills required include: Cybersecurity & Threat Intelligence Real-time threat monitoring and incident detection Security information and event management (SIEM) expertise Knowledge of threat actors, tactics, techniques, and procedures (TTPs) Familiarity with threat intelligence feeds and correlation Security Operations & Incident Response Incident triage and escalation procedures Conducting forensic analysis and evidence collection Threat hunting and anomaly detection Root cause analysis and post-incident reporting Technical & Analytical Proficiency Network traffic analysis and packet capture interpretation Endpoint detection and response (EDR) tools and techniques Log analysis (system, application, network, firewall) Knowledge of intrusion detection/prevention systems (IDS/IPS) Scripting or automation with Python, PowerShell, or Bash (bonus) Security Frameworks & Compliance Familiarity with frameworks such as NIST, MITRE ATT&CK, or ISO 27001 Understanding of government cybersecurity regulations and FISMA compliance Communication & Collaboration Clear written and verbal communication for incident reports and briefings Coordinating with cross-functional teams and stakeholders Ability to communicate technical risks and impact to non-technical leadership Required qualifications include: Bachelor's degree, preferably in an IT-related field 10+ years of experience in IT with a minimum of 4 years in Cybersecurity Active TS Clearance Experience with Splunk Enterprise Security Preferred qualifications and competencies include: Experience with Microsoft Sentinel Related certifications Work environment and physical demands: Location: Huntsville, Alabama Remote or In-Person: On site Type of environment: Office Noise level: Medium Work schedule: Schedule is day shift Monday - Friday. Amount of Travel: Less than 10% Work authorization/security clearance: Active Top Secret Clearance Required Other information: This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Equal employment opportunity: In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information, or any other characteristic protected by law.