Cybersecurity Analysts with Active TS/SCI clearance
Job Description
APR Consulting, Inc. supports a world-leading aerospace innovator in Tampa by sourcing a Cybersecurity Analyst with an active TS/SCI clearance. This role centers on Splunk SIEM operations and HBSS/Trellix endpoint protection within a high-security environment, operating on a Panama 12-hour shift schedule under a contract of three months or longer. The position is onsite in Tampa and demands a solid background in security analytics and SIEM administration.
Responsibilities
- Create and optimize Splunk queries to extract, analyze, and visualize security data from diverse sources.
- Apply Splunk SPL to generate actionable insights for proactive threat detection and response.
- Design user-friendly Splunk dashboards and reports for security operations, management, and auditors.
- Provide real-time visibility into security events, trends, and key performance indicators.
- Configure and fine-tune Splunk deployments, including data inputs, parsing, field extractions, and enrichment pipelines.
- Ensure continuous availability and optimal performance of Splunk indexes, search heads, and forwarders.
- Leverage Splunk Enterprise Security to develop and implement security use cases, correlation searches, and notable events.
- Monitor security-related alerts and incidents to identify and prioritize threats.
- Utilize Trellix Endpoint Security Solutions (HBSS) to detect and counter known threats.
- Collaborate with IT, network, and application teams to integrate Splunk with various platforms and systems.
- Provide technical guidance on security best practices and design effective controls.
- Investigate security incidents using Splunk for forensic analysis, perform root cause analysis, and conduct post-incident reviews.
- Document Splunk configurations, procedures, and security findings; prepare comprehensive reports.
- Communicate technical information effectively to non-technical stakeholders.
- Stay current with cybersecurity threats, vulnerabilities, and industry best practices; pursue ongoing Splunk training and certifications.
- Apply solid SIEM concepts and troubleshoot Splunk configurations and performance issues.
- Collaborate with cross-functional teams to investigate incidents and provide insights to improve security posture.
Requirements
- US Citizen required
- Current/active DoD TS/SCI clearance
- DoD 8570 Certification for IAT Level II or higher prior to start date
- Bachelor’s degree with 2 years of experience
- Experience with a Security Information and Event Management (SIEM) tool
- Ability to collaborate with other teams to investigate security incidents and improve security posture
- Working knowledge of network security controls such as routers, switches, firewalls and network access controls
- Working knowledge of Linux and Windows operating systems
- Knowledge of vulnerabilities, threat detection, encryption, and security audits
- Willing to work a Panama schedule that includes 12-hour shifts
Technologies
- Splunk
- Splunk SPL (Search Processing Language)
- Splunk Enterprise Security
- Trellix Endpoint Security Solutions (HBSS)
Location
Tampa, FL 33609 (Onsite)
Pay Rate
$62.10/hr on W2 (DOE)
Duration
3 months or longer
Schedule
Panama schedule that includes 12-hour shifts, with a three-day weekend every other week and rotation from days to nights approximately every 12 weeks.
About Our Client
The client is a world leader and premier aerospace innovator, employing over 100,000 professionals delivering advanced products and technologies. The organization has earned numerous awards and recognitions and supports ongoing growth and development for its staff.
About APR
Since 1980 APR Consulting, Inc. has provided professional recruiting and contingent workforce solutions to a diverse mix of clients, industries, and skill sets nationwide.