Cyber Security Engineer
Cyber Forensics
Cyber Security
Cyber Security Associate
Cybersecurity Tools
Data Security
Engineer
Facilities Management
Forensics
Host Forensics
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Analysis
Log Management
Network Forensics
Packet Analysis
Risk Management
Security
Security Information And Event Management
Security Monitoring
Security Operations
Security Testing
Splunk
Splunk Siem
Job Description
Support the Cyber Security Operations Center (CSOC) Incident Response team at Lawrence Livermore National Laboratory in a hybrid role focused on detection, response, and continuous improvement.
Responsibilities
- Protect enterprise systems and information by promptly responding to security threats and incidents, both individually and as part of a team.
- Proactively hunt for cyber threats and drive identification, containment, and eradication actions while supporting recovery efforts.
- Analyze LLNL intrusion detection systems.
- Provide security monitoring and incident response support, including troubleshooting and resolution of issues.
- Create and manage processes, systems, and tools with a high degree of responsibility.
- Act as an incident response technical point of contact and coordinate with internal and external stakeholders.
- Conduct technical assessments, document actions and findings, and provide remediation recommendations.
- Promote and support plans that advance diversity, equity, and inclusion within the program.
- Manage multiple complex parallel tasks and competing priorities while meeting deadlines and leveraging team member skills.
- Develop advanced methods, tools, and procedures to improve incident response capabilities and automate complex tasks.
- Mentor and provide technical guidance to team members on incident response best practices and procedures.
- Perform other duties as assigned.
Requirements
- Ability to obtain and maintain a US DOE Q-level security clearance, which requires U.S. Citizenship.
- Bachelor’s degree in Computer Science, Computer Engineering, or related field, or an equivalent combination of education and related experience.
- Broad experience with SIEM, log aggregation, packet analysis, or other cybersecurity tools.
- Experience conducting host forensics, network forensics, log analysis, or malware analysis for incident response investigations.
- Proficient written and verbal communication and strong interpersonal skills for collaboration in a multi-disciplinary environment and interaction with all levels of management and staff.
- Ability to manage concurrent technical tasks with conflicting priorities, work independently, and shift focus when necessary.
- Ability to work off-hours and on-call to respond to incidents (intermittently, either as-needed or as part of a rotation).
- Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management.
- Significant experience with log analysis, event correlation, or incident management procedures.
- Advanced ability to provide innovative approaches and apply new technologies to tasks and projects that may not be well defined.
Technologies
- SIEM, log aggregation, packet analysis, host forensics, network forensics, log analysis, malware analysis
- AWS, Azure
- C, C#, Python, Java, PowerShell, PHP
- CISSP, CISM, GIAC
Benefits
- Flexible benefits package
- 401(k)
- Relocation Assistance
- Education Reimbursement Program
- Flexible schedules (depending on project needs)
Additional Qualifications (SES.3 level)
- Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management.
- Significant experience with log analysis, event correlation, or incident management procedures.
- Advanced ability to provide innovative approaches and apply new technologies to tasks and projects that may not be well defined.
Qualifications We Desire
- Master’s degree in Computer Science, Computer Engineering, or a related field, or equivalent level of knowledge.
- Significant incident response experience, including cloud services such as AWS/Azure, and experience leading teams.
- Experience with programming or scripting languages: C, C#, Python, Java, PowerShell, PHP.
- Current industry specific certifications, including but not limited to: CISSP, CISM, GIAC.
Pay Range
- $146,340 - $222,564 annually
- $146,340 - $185,544 at the SES.2 level
- $175,530 - $222,564 at the SES.3 level
- Final placement in the salary range is based on competencies, education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs.
Position Information
- Flexible Term appointment for a definite period not to exceed six years.
- If the final candidate is a Career Indefinite employee, Career Indefinite status may be maintained (should funding allow).
Security Clearance
- Requires a Department of Energy (DOE) Q-level clearance.
- If selected, the employer initiates a Federal background investigation to determine eligibility for access to classified information or matter.
- All L or Q cleared employees are subject to random drug testing.
- Q-level clearance requires U.S. citizenship.
Pre-Employment Drug Test
- External applicants selected must pass a post-offer, pre-employment drug test.
- Testing includes marijuana use due to Federal law requirements for a Federal Contractor.
Wireless and Medical Devices
- Depending on job duties, you may be required to work in a Limited Area where personal and/or laboratory mobile devices are not permitted.
- Includes, but is not limited to: cell phones, tablets, fitness devices, wireless headphones, and other Bluetooth/wireless enabled devices.
- Sensitive Compartmented Information Facilities require separate approval.
- Hearing aids without wireless capabilities or wireless that has been disabled are allowed in Limited Areas, Secure Space, and Transit/Buffer Space within buildings.
Location: Livermore, CA (Hybrid) #LI-Hybrid