SMX is seeking a Data Analyst to design, develop, and implement data-driven solutions to enhance cybersecurity operations, leveraging data analytics, visualization, and observability techniques to improve threat detection, incident response, and security posture.
Requirements
- Thorough understanding of cybersecurity principles, best practices, and emerging threats.
- Proficiency in vulnerability scanning and cybersecurity tools, including Tenable.
- Security Information and Event Management (SIEM) systems: Splunk, Elastic, Logstash, Kibana (ELK)
- Data broker technologies: Cribl, Confluent
- Operating Systems Security Events: Windows, Linux
- Networking protocols: TCP/IP, DNS, DHCP, HTTP/HTTPS
- Cybersecurity tools and technologies: IDS/IPS, firewalls, host based security, threat intelligence platforms, vulnerability management tools
Responsibilities
- Generate detailed automated reports on identified vulnerabilities, outlining their severity, potential impact, and recommended remediation steps.
- Design and develop data pipelines and architectures to ingest, process, and analyze large datasets from various cybersecurity sources.
- Develop and implement data visualization and dashboarding solutions to provide real-time insights and situational awareness to cybersecurity analysts and stakeholders.
- Implement machine learning and anomaly detection models to identify potential security threats and improve incident response.
- Collaborate with cybersecurity teams to integrate data-driven solutions with existing security tools and systems.
- Stay updated on the latest threat intelligence, new vulnerabilities, and mitigation strategies.
- Ensure compliance with DoD, Army, and IC regulations, task orders, bulletins, and standards related to vulnerability management.
Other
- Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work.
- Meet DoD 8140 / 8570.01-M requirements for a privileged user on a TS/SCI information system before commencing work.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field OR 10+ Years experience with Enterprise SIEM Data Observability and Reporting (Splunk/Elastic)
- Ability to convey technical findings clearly and succinctly to both technical and non-technical audiences.
- Adept at collaborating with IT, security, and cross-functional teams to ensure timely and effective vulnerability remediation.