Junior Security Analyst (Secret Clearance Required)

Deloitte

3.5

(197)

Baltimore, MD

Why you should apply for a job to Deloitte:

  • 75% say women are treated fairly and equally to men
  • 90% say the CEO supports gender diversity
  • Ratings are based on anonymous reviews by Fairygodboss members.
  • Up to 16 weeks of paid time off to bond with a child as a result of birth or placement for adoption and/or to care for a family member.
  • Encore is a paid, program that eases the transition back into the workforce.
  • #165057

    Position summary

    clients as well as public higher education institutions, our team of more than 15,000 professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

    At Deloitte, we believe cyber is about starting things-not stopping them-and enabling the freedom to create a more secure future. Cyber Strategy, Defense and Response (SDR) focuses on helping federal clients design and implement transformational enterprise security programs with an emphasis on defending against, recovering from, and mitigating major cyberattacks. If you're seeking a career that increases cyber awareness, utilizes risk management programs, and develops strategies for cyber defense and response, then the Cyber SDR offering at Deloitte is for you.

    Required skills:

    • A minimum of a Bachelor's degree or equivalent experience required.

    • Must possess an active Secret Security Clearance

    • 1+ years of experience working in a Security Operations Center (SOC) or Network Operations Center (NOC) environment performing security event monitoring and analysis

    • Working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks.

    • To support the 24x7x365 requirements of cyber operations there are four (4) available shift schedules:
      Shift 1 - Sun, Mon, Tue - 6 AM to 6 PM
      Shift 2 - Sun, Mon, Tue - 6 PM to 6 AM
      Shift 3 - Thu, Fri, Sat - 6 AM to 6 PM
      Shift 4 - Thu, Fri, Say - 6 PM to 6 AM
      The morning/evening shifts will rotate personnel every other Wed to work 8 hours which will equal 80 hours over 2 weeks.

    • Must possess a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.)

    • Must be capable of analyzing security logs and events from the following types of devices such as, but not limited to: Firewalls (FWs), Intrusion Detection Sensors/Intrusion Prevention Sensors (IDS/IPS), Host-based Intrusion Detection System/ Host-based Intrusion Prevention System (HIDS/HIPS), proxy/web filter, vulnerability scans, routers, router Internet Protocol (IP) accounting systems (i.e., Cisco NetFlow), Virtual Private Network (VPN) gateways/concentrators, server event logs, e-mail and host anti-virus, desktop security monitoring agents, anti-virus servers, IP services (i.e. Domain Name System (DNS) Services, Dynamic Host Configuration Protocol (DHCP), network address translation devices, MDM (e.g. cellphones), Public Key Infrastructure (PKI), and cloud security infrastructure (e.g. Amazon Web Services (AWS), Azure, Oracle, Salesforce, etc.)

    Preferred Skills:

    • Certification: Security+, GIAC Security Essentials (GSEC) or equivalent certification is desired
    • Experience with Splunk query language
    • Experience with IDS/IPS/firewall/security configurations and signature development
    • Experience with PCAP analysis
    • Experience with Tanium threat response
    • Ability and prior experience with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes the identification of malicious code present within a computer system as well identification of malicious activities that are present within a computer system and/or enterprise network
    • Experience working with a ticket management system to collect, document and maintain information pertinent to security investigations and incidents
    • Excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings
    • Experience in monitoring the operational status of monitoring components and escalating and reporting outages of the components
    • Conceptual understanding of Windows Active Directory is also desired
    • Experience working with various event logging systems and must be proficient in the review of security event log analysis. Previous experience with SIEM platforms that perform log collection, analysis, correlation, and alerting is also preferred
    • Experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment
    • Experience in collecting and maintaining information pertinent to security; investigations and incidents in a format that supports analysis, situational awareness reporting, and law enforcement investigation efforts

    Why you should apply for a job to Deloitte:

  • 75% say women are treated fairly and equally to men
  • 90% say the CEO supports gender diversity
  • Ratings are based on anonymous reviews by Fairygodboss members.
  • Up to 16 weeks of paid time off to bond with a child as a result of birth or placement for adoption and/or to care for a family member.
  • Encore is a paid, program that eases the transition back into the workforce.