CybersecurityJobs.io
← Back to all jobs

Job Description

Support the Cyber Security Operations Center (CSOC) Incident Response team at Lawrence Livermore National Laboratory in a hybrid role focused on detection, response, and continuous improvement.

Responsibilities

  • Protect enterprise systems and information by promptly responding to security threats and incidents, both individually and as part of a team.
  • Proactively hunt for cyber threats and drive identification, containment, and eradication actions while supporting recovery efforts.
  • Analyze LLNL intrusion detection systems.
  • Provide security monitoring and incident response support, including troubleshooting and resolution of issues.
  • Create and manage processes, systems, and tools with a high degree of responsibility.
  • Act as an incident response technical point of contact and coordinate with internal and external stakeholders.
  • Conduct technical assessments, document actions and findings, and provide remediation recommendations.
  • Promote and support plans that advance diversity, equity, and inclusion within the program.
  • Manage multiple complex parallel tasks and competing priorities while meeting deadlines and leveraging team member skills.
  • Develop advanced methods, tools, and procedures to improve incident response capabilities and automate complex tasks.
  • Mentor and provide technical guidance to team members on incident response best practices and procedures.
  • Perform other duties as assigned.

Requirements

  • Ability to obtain and maintain a US DOE Q-level security clearance, which requires U.S. Citizenship.
  • Bachelor’s degree in Computer Science, Computer Engineering, or related field, or an equivalent combination of education and related experience.
  • Broad experience with SIEM, log aggregation, packet analysis, or other cybersecurity tools.
  • Experience conducting host forensics, network forensics, log analysis, or malware analysis for incident response investigations.
  • Proficient written and verbal communication and strong interpersonal skills for collaboration in a multi-disciplinary environment and interaction with all levels of management and staff.
  • Ability to manage concurrent technical tasks with conflicting priorities, work independently, and shift focus when necessary.
  • Ability to work off-hours and on-call to respond to incidents (intermittently, either as-needed or as part of a rotation).
  • Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management.
  • Significant experience with log analysis, event correlation, or incident management procedures.
  • Advanced ability to provide innovative approaches and apply new technologies to tasks and projects that may not be well defined.

Technologies

  • SIEM, log aggregation, packet analysis, host forensics, network forensics, log analysis, malware analysis
  • AWS, Azure
  • C, C#, Python, Java, PowerShell, PHP
  • CISSP, CISM, GIAC

Benefits

  • Flexible benefits package
  • 401(k)
  • Relocation Assistance
  • Education Reimbursement Program
  • Flexible schedules (depending on project needs)

Additional Qualifications (SES.3 level)

  • Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management.
  • Significant experience with log analysis, event correlation, or incident management procedures.
  • Advanced ability to provide innovative approaches and apply new technologies to tasks and projects that may not be well defined.

Qualifications We Desire

  • Master’s degree in Computer Science, Computer Engineering, or a related field, or equivalent level of knowledge.
  • Significant incident response experience, including cloud services such as AWS/Azure, and experience leading teams.
  • Experience with programming or scripting languages: C, C#, Python, Java, PowerShell, PHP.
  • Current industry specific certifications, including but not limited to: CISSP, CISM, GIAC.

Pay Range

  • $146,340 - $222,564 annually
  • $146,340 - $185,544 at the SES.2 level
  • $175,530 - $222,564 at the SES.3 level
  • Final placement in the salary range is based on competencies, education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs.

Position Information

  • Flexible Term appointment for a definite period not to exceed six years.
  • If the final candidate is a Career Indefinite employee, Career Indefinite status may be maintained (should funding allow).

Security Clearance

  • Requires a Department of Energy (DOE) Q-level clearance.
  • If selected, the employer initiates a Federal background investigation to determine eligibility for access to classified information or matter.
  • All L or Q cleared employees are subject to random drug testing.
  • Q-level clearance requires U.S. citizenship.

Pre-Employment Drug Test

  • External applicants selected must pass a post-offer, pre-employment drug test.
  • Testing includes marijuana use due to Federal law requirements for a Federal Contractor.

Wireless and Medical Devices

  • Depending on job duties, you may be required to work in a Limited Area where personal and/or laboratory mobile devices are not permitted.
  • Includes, but is not limited to: cell phones, tablets, fitness devices, wireless headphones, and other Bluetooth/wireless enabled devices.
  • Sensitive Compartmented Information Facilities require separate approval.
  • Hearing aids without wireless capabilities or wireless that has been disabled are allowed in Limited Areas, Secure Space, and Transit/Buffer Space within buildings.

Location: Livermore, CA (Hybrid) #LI-Hybrid

Similar Jobs