SMX is seeking to enhance cybersecurity operations by designing, developing, and implementing data-driven solutions to improve threat detection, incident response, and security posture.
Requirements
- Thorough understanding of cybersecurity principles, best practices, and emerging threats.
- Proficiency in vulnerability scanning and cybersecurity tools, including Tenable.
- Security Information and Event Management (SIEM) systems: Splunk, Elastic, Logstash, Kibana (ELK)
- Data broker technologies: Cribl, Confluent
- Operating Systems Security Events: Windows, Linux
- Networking protocols: TCP/IP, DNS, DHCP, HTTP/HTTPS
- Cybersecurity tools and technologies: IDS/IPS, firewalls, host based security, threat intelligence platforms, vulnerability management tools
Responsibilities
- Generate detailed automated reports on identified vulnerabilities, outlining their severity, potential impact, and recommended remediation steps.
- Design and develop data pipelines and architectures to ingest, process, and analyze large datasets from various cybersecurity sources.
- Develop and implement data visualization and dashboarding solutions to provide real-time insights and situational awareness to cybersecurity analysts and stakeholders.
- Collaborate with cybersecurity teams to integrate data-driven solutions with existing security tools and systems.
- Implement machine learning and anomaly detection models to identify potential security threats and improve incident response.
- Develop and maintain data quality and integrity.
- Stay up-to-date with emerging threats and trends in cybersecurity and data science.
Other
- Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work.
- Meet DoD 8140 / 8570.01-M requirements for a privileged user on a TS/SCI information system before commencing work.
- CISSP, CISM, or equivalent certification.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field OR 10+ Years experience with Enterprise SIEM Data Observability and Reporting (Splunk/Elastic)
- Ability to convey technical findings clearly and succinctly to both technical and non-technical audiences.