
Threat Management Specialist – Tier 2
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Virginia.
• Conduct in-depth incident investigations by correlating data from multiple sources to ascertain if critical systems or datasets are impacted.
• Manage incidents in accordance with established playbooks and standard operating procedures (SOPs).
• Provide recommendations for remediation actions.
• Offer insights and analyses on utilizing AI, machine learning, and SOAR capabilities to enhance CSOC efficiency and precision.
• Identify cybersecurity issues that necessitate mitigating controls.
• Analyze network traffic to detect attempts related to exploits or intrusions.
• Suggest detection mechanisms for exploit and intrusion attempts.
• Deliver subject matter expertise on network-based attacks, network traffic analysis, and intrusion methodologies.
• Escalate issues needing further investigation to Threat Management team members.
• Implement operational processes that support responses to identified security incidents.
• Utilize AI/ML-driven tools and techniques to detect anomalies, automate incident triage, and enhance threat intelligence.
• Conduct and analyze threat intelligence to evaluate risk and adapt defenses using ML-enhanced tools.
• Oversee email security with Proofpoint, monitor threats, and respond to attacks.
• Configure Splunk for log analysis, create alerts, and investigate security incidents.
• Set up FirePower for network monitoring, analyze traffic patterns, and apply security measures.
• Deploy SentinelOne agents, monitor alerts, and perform security assessments.
• Monitor, review, and respond to security alerts and incidents across various platforms including Microsoft Defender for Cloud Apps, Defender for Endpoint, Defender XDR, Defender for Office 365, Azure Entra ID, and Google Cloud Security Command Center.
• Execute threat detection and analysis, investigate suspicious activities, coordinate incident responses, and implement remedial actions.
• Adjust security policies and maintain visibility into cloud and endpoint environments.
• Contribute to the continuous enhancement of the organization’s security posture.
• Keep abreast of cybersecurity trends, threat actors, and AI/ML research.
• Identify and support automation use cases, including the application of AI/ML to bolster SOC capabilities.
• Collaborate across Operations to enhance SOC functionalities through automation and AI.
• Minimum of 3 years of relevant experience.
• Bachelor’s degree in Computer Science, Information Technology, or a related field, or an additional 4 years of pertinent work experience in lieu of a relevant college degree.
• At least 3 years of IT security experience, with some exposure to AI/ML projects.
• Over 2 years of experience in network traffic analysis.
• Availability to work Monday through Friday, from 11:00 PM to 7:30 AM ET.
• Strong understanding of Boolean Logic, TCP/IP fundamentals, network-level exploits, threat management, control frameworks, and risk management techniques.
• In-depth knowledge of IDS/IPS technologies, trends, vendors, processes, and methodologies.
• Comprehensive understanding of IDS/IPS architectures and implementations.
• Profound knowledge of IDS/IPS signatures, content creation, signature characteristics, as well as signature-based and anomaly-based analysis and detection.
• Experience with cloud security solutions (AWS, Azure, GCP).
• Practical experience in cybersecurity automation, such as SOAR platforms.
• Proficiency with machine learning frameworks for developing, training, and deploying models for anomaly detection, threat intelligence, and behavioral analysis in cybersecurity contexts.
• Skills in data analysis and feature engineering, including preprocessing and transforming large datasets from logs and network traffic.
• Awareness of AI/ML techniques in cybersecurity, encompassing automated threat detection, incident response automation, and predictive analytics.
• Experience in recognizing and implementing automation use cases.
• Capability to obtain and maintain a Public Trust clearance, including passing government background screening with detailed forms and fingerprinting.
• U.S. residency for the duration required under the USPS security clearance process.
• 401K with company matching contributions.
• Comprehensive health and wellness packages.
• An internal mobility team focused on assisting you in managing your career.
• Opportunities for professional growth, including support for paid education and certifications.
• Access to cutting-edge technology for learning purposes.
• Paid vacation and holidays.
• Medical plan options, including some with Health Savings Accounts.
• Options for dental plans.
• Vision plan availability.
• Full flexible work weeks when possible.
• Paid time off plans that cover vacation, sick leave, personal time, parental leave, military leave, bereavement leave, and jury duty leave.
• Ten paid holidays each year.
• Paid Family Leave of up to 160 hours in a rolling 12-month period for eligible employees.
• Short-term and long-term disability benefits.
• Life insurance coverage.
• Accidental death and dismemberment insurance.
• Personal accident insurance.
• Critical illness insurance.
• Business travel and accident insurance.
Datavant
HarmonyCares
Delta Group
Empower
Get handpicked remote jobs straight to your inbox weekly.