Military Ocean Terminal Concord, Concord, California
Location of PositionConcord, California, United States
Work ArrangementOn Site: 100%
Position TypeFull-Time/Regular
Clearance Required?Ability to Qualify
Level of Clearance RequiredSecret
Position Funded?Yes
General Summary:
Performs system monitoring and analysis support for the detection of cyber incidents and provides recommendations on how to correct findings.
Principal Duties and Responsibilities (*Essential Functions): Submits and tracks all service tickets submitted internally and externally for Operational Technology (OT) systems.Monitors/logs SOC Request/CNOC actions and response.Assists in OT investigations of significant incidents and reporting.Provides timely acknowledgment of SOC service requests, problem identification, root cause analysis, escalation, resolution, and closure for all SOC service requests in accordance with SLAs and OLAs.Escalates OT cyber incidents that require further in-depth analysis to SOC Incident Analysis.Categorizes and prioritizes OT cyber events and other SOC service requests.Documents and tracks incidents in accordance with reporting procedure and archives historical OT SOC data.Provides situational awareness on OT cybersecurity-related issues impacting enterprise policies and procedures.Provides monitoring and analysis of OT SIEM events to identify potential security risks and vulnerabilities.Triages events and investigates to identify OT security incidents.Logs security incidents in the IT/OT ticketing system.Manages OT security incidents throughout their lifecycle to closure.Coordinates with other, remote technical teams to investigate, document, and resolve issues.Makes recommendations for ongoing tuning and updates to the SIEM system.Receives input from threat intelligence sources and analyzes events to identify threats and risks.Supports ad-hoc data and investigation requests.Conducts security and vulnerability scans as directed using established processes.Required ExperienceAssociate's or Bachelor's degree in related technical field or equivalent experience; minimum of 3 related certifications may be used in place of unrelated degree field.4-10 plus years of work-related experienceMust be able to obtain/maintain a Secret security clearance; US citizenship requiredAbility to work onsite dailyAbility to clearly present and communicate technical approaches and findingsFamiliarity with backup operations and processes for data protection, disaster recovery, and failover procedures (COOP/DR)Familiarity with MITRE Att&ck FrameworkStrong understanding of OSI model, network security concepts, security classification guides, and CJCSM 6510.01B concepts and activitiesPreferred QualificationsAdvanced degree preferredDoD experienceICS/OT penetration testing experienceSystem administration experience and IT certifications in Linux or Microsoft are a plusExperience with networking protocols, design (switches, routers, firewalls, etc.) and terminology, or network administration is a plus (Cisco, Juniper, Ubiquiti etc.)Understanding of the Purdue model, Industrial Control Systems, and Operational Technology is desiredApplicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. COLSA Corporation is an Equal Opportunity Employer, Minorities/Females/Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.
This position will be posted for a minimum of 3 business days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.
COLSA offers a comprehensive and customizable benefits program which includes Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, Accidental Death & Dismemberment, Supplemental Income Protection Programs, 401(k) with company match, Flexible Spending Accounts, Employee Assistance Program, Education & Certification Reimbursement, Employee Discount Program, Wellness Program, Paid Time Off and Holidays.
#J-18808-Ljbffr