CybersecurityJobs.io
← Back to all jobs

Job Description

Join SAIC supporting the County of Orange Security Operations Center (SOC). This hybrid role in Santa Ana, CA combines day-to-day SOC operations with opportunities to investigate alerts, tune detection coverage, and improve security controls through automation, threat intelligence, and vulnerability management. You will help protect networks and systems while contributing briefings to senior staff as part of a 7/24/365 operations environment.

Responsibilities

  • Proactively monitor security events across networks and systems and support continuous SOC functions.
  • Identify, investigate, and report on potential security incidents, including response-related support activities.
  • Mentor and guide T1 SOC Analysts.
  • Support risk and vulnerability assessment at the network, system, and application level.
  • Contribute to cyber metrics development, maintenance, and reporting.
  • Support cyber threat intelligence development and reporting.
  • Identify, develop, and implement automation tasks to improve SOC workflows.
  • Develop, recommend, and implement security controls, and help formulate operational risk mitigations while assisting security awareness programs.
  • Research, evaluate, and recommend new security tools, techniques, and technologies aligned with IT security strategy.
  • Use COTS/GOTS and custom tools and processes to scan, identify, contain, mitigate, and remediate vulnerabilities and intrusions.
  • Assist with implementation of required government policy (including NIST) and recommend process tailoring.
  • Perform analyses to validate established security requirements and recommend additional safeguards.
  • Periodically review system audits and monitor corrective actions until they are closed.
  • Provide briefings to senior staff on a routine basis.

Requirements

  • Bachelor’s degree in a related field and 2 years of related experience required; 4 years of related experience is highly preferred. Additional experience may be substituted in lieu of education.
  • Preferred certifications: CySA+, SecurityX+, GIAC Security Essentials (GSEC), or similar industry certifications.
  • Ability to pass the LiveScan background check, CSS Department review, and Probation Department review.
  • Ability to pass a Drug Screen.
  • Programming languages including Python, C++, and JavaScript.
  • Experience with SIEM technologies, including analyzing security alerts via Sentinel SIEM (experience with other SIEM tools acceptable).
  • Knowledge of IDS/IPS, Firewalls, and Anti-Virus/Anti-Malware technologies.
  • Incident Response and Vulnerability Management experience.
  • Demonstrated response, exposure to, and partial or full ownership of Security Incidents.
  • Knowledge of the full Incident Response cycle: Identification, Protection, Detection, Response, Recover.
  • Adherence to SOC Standard Operating Procedures.

Technology Stack

  • Python, C++, JavaScript
  • Security Information and Event Management (SIEM) technologies
  • Sentinel SIEM
  • IDS/IPS, Firewalls
  • Anti-Virus/Anti-Malware technologies
  • COTS/GOTS

Shift and Location Notes

  • Because the SOC operates 7/24/365, working during some holidays is expected.
  • The SOC uses a hybrid shift model with some days onsite and some days remote.
  • Shift rotation is expected based on operational needs; remaining on the same shift is not guaranteed, and reasonable notice time will be provided before changes.

Target salary range: $80,001 - $120,000 per year.

Similar Jobs