FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity operations, including threat hunting, incident response, and security monitoring using SIEM tools like Splunk. Possesses strong analytical skills for identifying and mitigating security threats while adhering to compliance standards such as NIST.
Highest-signal resume keywords
Cybersecurity ExperienceSIEM Platform ProficiencyIncident Response PlanningThreat Hunting TechniquesSecurity+ CE Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
SPL Query CreationNetwork Traffic AnalysisLog AnalysisDigital ForensicsAnomaly DetectionTCP/IP UnderstandingBoolean LogicEvent CorrelationSystem SecurityVulnerability Assessment
Soft Skills
Technical ExpertiseCommunication SkillsMentoringCollaborationProblem-Solving
Tools & Technologies
SplunkMicrosoft SentinelSIEM ToolsEDR ToolsFirewallIDSCloud SecurityOperating System HardeningScripting/CodingWAF Security Features
Certifications & Qualifications
Active SECRET Security ClearanceSecurity+ CESplunk Power User Certification
Industry Keywords
SOCCyber Incident ResponseNIST StandardsRMFHigh-Availability SystemsFederal Government EnvironmentCybersecurity FrameworksThreat VectorsRisk AssessmentConfiguration Standards
Tech Stack
Tools & technologiesCloudCyber SecurityLinuxSplunkTCP/IP
About the role
Key responsibilities & impact- Monitor and investigate security alerts and perform threat hunting
- Notify managers, cyber incident responders, and cybersecurity service provider personnel of suspected incidents
- Document event history, status, and potential impact according to the cyber incident response plan
- Analyze and characterize network traffic for anomalous activity and threats
- Create advanced ad hoc SPL queries
- Coordinate threat investigations, risk assessments, and forensic analysis with internal and external teams
- Review host, network traffic, firewall, and IDS logs for potential security threats
- Use SIEM and EDR tools to monitor the operational environment
- Develop and document configuration standards, policies, and procedures for securing system infrastructure
- Advise management and team members on technology risks and mitigation strategies
- Provide technical expertise and thought leadership to multiple management levels
- Prepare investigation, incident, and security activity reports
- Identify and classify attack tactics and techniques
- Recommend and implement system performance, security, and reliability enhancements
- Build and refine SOC processes and procedures and document work in SOPs
- Train and mentor junior SOC team members
- Plan and execute SOC-related projects and initiatives
Requirements
What you’ll need- Bachelor’s degree and 2 years of experience, or Associate’s degree and 4 years of experience, or high school diploma/equivalent and 6 years of experience
- U.S. citizenship
- Active SECRET security clearance
- 2+ years of cybersecurity, SOC, or systems security experience in a federal government environment supporting business-critical, high-availability systems
- 2+ years of SOC or cybersecurity-related experience
- Experience working with a SIEM platform, preferably Splunk
- Experience using Splunk dashboards and Microsoft Sentinel for security monitoring and analysis
- Experience querying and analyzing security data, including SPL, with working understanding of data types, conditions, and regular expressions
- Working knowledge of system, network, and application security threats and vulnerabilities
- Understanding of Boolean logic and event correlation
- Experience identifying logging and monitoring gaps and supporting efforts to improve security monitoring
- Working knowledge of cybersecurity incidents, anomaly analysis, log analysis, digital forensics, and common threat vectors
- Understanding of TCP/IP, UDP, network ports, protocols, and traffic flow
- Security+ CE or other DoD 8570 IAT Level II certification
- Familiarity with cybersecurity frameworks and specifications, including RMF and NIST standards such as NIST SP 800-53
- Preferred: Splunk data normalization, Splunk Power User certification or higher, MITRE ATT&CK, cloud security, system administration, networking, operating system hardening, Linux, Windows, storage troubleshooting, scripting/coding, and WAF security features
Benefits
Comp & perks- Overtime eligibility
- Shift differential
- Discretionary bonus
- Fully remote work arrangement
- Occasional onsite meetings, training sessions, or customer support activities
