Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
CF
Coalfire Federal
SOC Analyst - Secret Clearance Required (Denver, Colorado)
Career Insights for Security Operations Center Analyst
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Colorado data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Security Operations Center Analyst monitors and analyzes security events and instances within an organization's IT infrastructure. Responds to real-time cybersecurity threats, configuring and deploying security infrastructures, and monitoring of ongoing security issues.
$97,514 / year median in Colorado
Job Description
About Coalfire Coalfire Federal is a market leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing and a full suite of cyber engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with leading cloud and technology providers including Amazon, Microsoft, IBM, Google and Oracle and Federal agencies. Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the United States and Europe and is committed to making the world a safer place by solving our clients' toughest security challenges. But that's not who we are - that's just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference. We're currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to support our on-site team. Location Details This is a full time on site position with our Coalfire Federal team supporting a government customer. Open to local candidates residing in Denver, Colorado to report to on client site location. What you'll do Monitors and analyzes for potential threat activity. Provides real-time alerting and monitoring by capturing, indexing, and correlating data in a searchable repository to generate graphs, reports, alerts and visualizations. Provides metrics, diagnoses security problems. Provides engineering support, operations, and maintenance of security tools. Utilizes Security, Information, and Event Monitoring (SIEM) tools to identify security events and incidents to evaluate the effectiveness of current security measures. Maintains Tenable Security Center administrator responsibilities, routine maintenance of the front end including but not limited to user accounts, scan polices, and reports. Conducts daily and ad-hoc vulnerability scanning on networks and systems. Prepares reports of metrics for vulnerability management that is briefed to senior leadership to convey network security status. Participates and contributes to weekly meetings with O&M team to discuss vulnerability patch management status. Tracks, maintains, and verifies findings. Promote timely remediation before due date and/or work with stakeholders on extension request. Conducts
DISA STIG
baseline configuration scanning of hardware and network devices and manually reviews CAT I and CAT II items that cannot be checked via automated scan. Monitors incoming events and maintain Audit Log Management using Splunk Tool. Validates hardware and software inventory for a portfolio of systems. Uses advanced analytic tools to determine presence of emerging threat patterns and vulnerabilities. Utilizes in-depth operational and technical knowledge of security concepts to provide technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation. Provides technical evaluations of customer systems and assists with making security improvements. Conducts product evaluations, and recommends products, technologies and upgrades to improve the customer's security posture. Conducts testing and audit log reviews. What you'll bring In addition to the duties listed above, utilizes the following cyber tools or equivalents:- Splunk Enterprise Security
- Q-Audit
ICS-500-27
Splunk application- Tenable Nessus Security Center
- Cylance
- Extrahop
- Burp Suite Education Completed Bachelor's degree from an accredited university, preferably in an IT related field.