Please mention DailyRemote when applying
SAIC has an opening for a Cybersecurity Ops Associate. This position can be worked remotely for the right candidate. This position will be for third shift (10pm – 8am) and either Sunday – Wednesday OR Wednesday – Saturday.
The Cybersecurity Ops Associate role is responsible for monitoring and analysis of identified security events in support of the real-time 24/7/365 Enterprise Security Operations Center's Detection & Response team’s monitoring capability. The Cybersecurity Ops Associate will perform daily operations utilizing a SIEM and monitoring events from multiple sources including but not limited to firewall logs, system logs, network and host-based intrusion detection systems, applications, databases, cloud infrastructure, and other security information monitoring tools. The associate will work as part of the ESOC team to ensure that our information assets are protected from unauthorized access or alterations and will help in the detection, analysis, and mitigation of potential threats.
Job Duties:
Responds and reacts to events in the SAIC monitored environment and escalates for further analysis as needed.
Continuously monitor security event systems by utilizing the Enterprise Security Operation Center’s security information and event management (SIEM) tool.
Provide initial response and support to potential intrusion or security breach alerts.
Collect and compile historical data on security incidents for trend analysis and security measures improvement.
Assist in containment measures during an incident to prevent further unauthorized access or data loss.
Investigate and approve/deny IP/URL block requests.
Contribute to the development of signature patterns based on known or anticipated threats to enhance detection capabilities.
Provide feedback on signature tuning for better detection of anomalies.
Create and maintain incident tickets as needed.
PCAP Analysis and correlation of events.
Determining urgency and potential impact.
Assist with analysis of actions taken by malicious actors to determine initial infection vectors as well as establish a timeline of activity and any data loss associated with incidents.
Develop and maintain security documentation including SOPs, incident reports, and policies.
Communicate and escalate issues and alerts as required by process or management.
Additional responsibilities including the support of various Enterprise Security Operations Center activities.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Others
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“ I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!