Talent.com
CareFirst BlueCross BlueShield
Lead Cyber Security Analyst (Remote)CareFirst BlueCross BlueShield • Owings Mills, MD
Lead Cyber Security Analyst (Remote)

Lead Cyber Security Analyst (Remote)

CareFirst BlueCross BlueShield • Owings Mills, MD
30+ days ago
Job type
  • Full-time
  • Remote
Job description

PURPOSE:

The Lead CyberSecurity Analyst is responsible for the monitoring, detection, and analysis of security threats against the distributed enterprise network. The selected candidate should have proven experience and the ability to leverage Computer Network Defense/Blue Team (CND) analyst toolsets to detect and respond to Cyber security incidents. This role conducts research and documents threats and their behavior; provides recommendations for threat mitigation strategies; employs effective communications to clearly manage security incident response procedures; and performs routine event reporting including trend reporting and analysis.

PRINCIPLE ACCOUNTABILITIES: Under the direction of the Manager, CyberSecurity Monitoring, the incumbent is responsible for, but is not limited to, the following:

Duties and Responsibilities:

  • Monitor consoles and telemetry directly from a variety of security toolsets and from the SIEM.
  • Thoroughly investigate and document security events.
  • Audit and review system reports and security logs for unauthorized access, noncompliant activity, or access misuse.
  • Monitor and escalate incoming security requests and events of interest from different external and internal sources.
  • Follow standard operating procedures for detecting, classifying, and reporting incidents.
  • Develop or improve use cases to increase efficacy, performance, or outcomes for security monitoring.
  • Participate in incident response activities as necessary.
  • Triage (determine scope, severity, and priority) of events in Security Information and Event Management (SIEM) tool or within other security monitoring tools directly.
  • Research vulnerabilities in applications and systems. Provide recommendations for resolution and track remediation activities.
  • Traffic analysis (at the packet level) and reconstruction of network traffic to discover anomalies, trends, and patterns affecting the customer's networks.
  • Analyze firewall logs, Full Packet Capture (PCAP), IDS alerts, Anti-malware alerts, Host Intrusion Prevent System (HIPS), and server and application logs to investigate events and incidents for anomalous activity and produce reports of findings.
  • Coordinate with third party providers to ensure appropriate detections are built and deployed.
  • Coordinate with Threat Intelligence and Response Operations to enhance time to detection and response.

QUALIFICATION:

Required Education and Experience: Degree or equivalent experience: BA/BS in Information Technology, CyberSecurity, Networking, Information Security, MIS, Computer Science or related field.

Experience Level: Minimum 5 years of demonstrated work experience. (Additional experience may be substituted for educational requirement.)

Along with the basic qualifications, the candidate will need to have experience in the following areas:

  • Deployment, configuration and management of Endpoint Detection and Response (EDR/XDR) tools, such as CrowdStrike.
  • Experience managing Microsoft Defender for Endpoint.
  • Experience in a hybrid multi-cloud environment – Azure highly preferred.
  • Experienced in the application and usage of threat analysis models/frameworks such as the Cyber Kill Chain, MITRE ATT&CK, etc.
  • Advanced knowledge of threat Tactics, Techniques and Procedures (TTPs), especially in cloud environments and including SaaS services like M365.

Specialized training (preferred, but not required): Transitioning, maintaining, or using security technologies such as Security Incident and Event Management (SIEM), Endpoint protection, Data Loss Prevention, Forensic tools, Network Anomaly Detection, Packet Capture Analysis; Incident response principles or related technical domain that is applied in the context of a broader understanding of CSIRT and related systems and processes.

Licenses/Certifications: One or more of the following certifications are preferred but not required OR the ability to obtain one certification within 6 months.

GCIA (GIAC Certified Intrusion Analyst)

GMON (GIAC Continuous Monitoring)

GCIH (GIAC Certified Incident Handler)

CCFA (CrowdStrike Certified Falcon Administrator)

GSOC (GIAC Security Operations Certified

CCFR (CrowdStrike Certified Falcon Responder)

Microsoft Certified: Security Operations Analyst Associate

CCFH (CrowdStrike Certified Falcon Hunter)

Knowledge, Skills and Abilities (KSAs)

  • Must be able to effectively work in a fast-paced environment with frequently changing priorities, deadlines, and workloads that can be variable for long periods of time. Must be able to effectively communicate.
  • Incumbent must have a firm understanding of Information and/or Cyber Security principles. Must be able to adapt quickly to understand rapidly changing threat landscape in order to correctly scope and prioritize security events. The incumbent must also be able to achieve certification across multiple domains such as networking, security, development languages, etc.

Required skills:

  • Experience preventing, detecting, analyzing and responding to threats against sensitive information.
  • Experience triaging security, network and endpoint forensic analysis, threat hunting and vulnerability escalation.
  • Experience with security monitoring and reporting tools and conducting security investigations of incidents and events.
  • Critical thinking and analytical skills to develop enhanced workflows and use cases for next generation platforms and cloud technology.
  • Experience with analyzing large data sets and log files to find correlations and anomalies.
  • Ability to utilize native cloud security tools in Azure to design and implement continuous monitoring solutions.
  • Advanced knowledge and use of Splunk.

Preferred Skills:

  • Ability to script proficiently in either Python or PowerShell
  • Advanced knowledge and use of Linux
  • OSINT collection and analysis.

Department

Department:

Equal Employment Opportunity

CareFirst BlueCross BlueShield is an Equal Opportunity (EEO) employer. It is the policy of the Company to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

Create a job alert for this search

Lead Cyber Security Analyst (Remote) • Owings Mills, MD

Similar jobs

Sr Principal Industrial Security Analyst/CPSO

Northrop GrummanBaltimore, MD, United States
Full-time

Principal Industrial Security Analyst 4/Lead CPSO.At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today... Show more

 • Promoted

Computer Network Defense Analyst

National Security AgencySevern, MD, United States
Full-time

Computer Network Defense Analysts work in multiple organizations at NSA and are primarily responsible for finding vulnerabilities, delivering analyses, crafting mitigations, developing cybersecurit... Show more

 • Promoted

Security Task Lead

Spry MethodsLinthicum Heights, MD, United States
Full-time

Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions.We specialize in delivering integrated,... Show more

 • Promoted

VP, Technology (AI, Cyber & Compliance Platforms)

FutureFeedBaltimore, MD, United States
Full-time

FutureFeed is seeking a growth-stage technology leader to own and scale a portfolio of products focused on cybersecurity, compliance, and governance (GRC).This role will lead the development of Att... Show more

 • Promoted

Senior Analyst, Operational Risk Management (Hybrid)

TransamericaBaltimore, MD, United States
Full-time

Operational Risk Management Role.This new second line operational risk management role will support the day-to-day execution of the Investment Office, performing Transamerica Operational Risk Manag... Show more

 • Promoted

Portfolio Lead

RealmOneBaltimore, MD, United States
Full-time

Security Clearance Required: Security Clearance with appropriate Polygraph.The RealmOne TRIBE is looking for you! RealmOne was built on the principle that people matter first and foremost.We believ... Show more

 • Promoted

Systems/Business Analyst (Hybrid) - 28629

HII Mission Technologies divisionHanover, MD, United States
Full-time

Systems/Business Analyst (Hybrid).Enlighten is looking for an experienced Systems/Business Analyst to directly support the full spectrum of Product Management operations and IT systems development,... Show more

 • Promoted

Cyberspace Fires (Targets) Analyst

PeratonFort George G Meade, MD, United States
Full-time

Cyberspace Fires (Targets) Analyst.Peraton is seeking an experienced Cyberspace Fires (Targets) Analyst to join our USCYBERCOM team located in the Fort Meade, MD area.Assists in the coordination of... Show more

 • Promoted

Cybersecurity & Privacy Technology Manager

University System of Maryland OfficeBaltimore, MD, United States
Full-time

Cybersecurity & Privacy Technology Manager.The Cybersecurity & Privacy Technology Manager plays a key role in strengthening cybersecurity and privacy across the University System of Maryland (USM).... Show more

 • Promoted

VP - Cyber, Technology, and Information Risk Manager

Morgan StanleyBaltimore, MD, United States
Full-time

Morgan Stanley is seeking a risk professional to join the Cyber, Technology and Information Security (CTIS) Standards team within the Non-Financial Risk Organization in Alpharetta or Baltimore at t... Show more

 • Promoted

Principal Industrial Security Analyst

Northrop GrummanBaltimore, MD, United States
Full-time

Principal Industrial Security Analyst 3/CPSO.At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and... Show more

 • Promoted

Business Analyst for a Compliance & Risk Management 100% Remote

StaffingOwings Mills, MD, United States
Remote
Full-time

Business Analyst for a Compliance & Risk Management 100% Remote.The Compliance & Risk Management (CRM) Business Analyst is a pivotal mid-level technology analyst role within the CRM Department.Thi... Show more

 • Promoted

Advanced Cyber Threat Response & Forensics Lead/Manager

DeloitteBaltimore, MD, United States
Full-time

Cyber Defense And Resilience Team Member.Deloitte's Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilitie... Show more

 • Promoted

Senior Business Analyst Security Settlements and Platform Migration/ Baltimore, MD-12 months Contr

Suncap TechnologyBaltimore, MD, United States
Full-time

Senior Business Analyst Security Settlements and Platform Migration.Senior Business Analyst Security Settlements.We are seeking a skilled Business Analyst with expertise in security settlements w... Show more

 • Promoted

Lead Business Analyst - Remote / Telecommute

Cynet SystemsBaltimore, MD, United States
Remote
Full-time

The Lead Business Analyst is responsible for driving business analysis activities, gathering and validating requirements, and ensuring alignment between business needs and system solutions.This rol... Show more

 • Promoted

Defensive Cyber Operations (DCO) Mission Lead

Strategic Ventures Consulting GroupSevern, MD, United States
Full-time

Strategic Ventures Consulting Group (SVCG), LLC is a dynamic consulting firm specializing in technical and management solutions that address the most pressing challenges faced by government and com... Show more

 • Promoted

NAESOC/Industrial Security Analyst - Top Secret

ClearanceJobsElkridge, MD, United States
Full-time

Naesoc AnalystXcelerate Solutions is seeking a National Access Elsewhere Security Oversight Center (NAESOC) Analyst to support the Defense Counterintelligence and Security Agency's NAESOC in applyi... Show more

 • Promoted

Digital Network Exploitation Analyst's (DNEA) Level 1-4

SentarFort George G Meade, MD, United States
Full-time

Digital Network Exploitation Analyst's (DNEA).Sentar is seeking Digital Network Exploitation Analyst's (DNEA) in Ft.Evaluate target opportunities using all source data to understand and map target ... Show more

 • Promoted

Cyberspace Policy Analyst Remote / Hybrid, TS / SCI

Booz Allen HamiltonSevern, MD, United States
Remote
Full-time

A leading defense contractor in Fort Meade is seeking a Cyberspace Policy Analyst to support USCYBERCOM by analyzing doctrine and policy.The ideal candidate will have over 5 years of relevant exper... Show more

 • Promoted

Cyberspace Operations Analyst with Security Clearance

HII Mission TechnologiesSevern, MD, United States
Full-time

Requisition Number:26315 Required Travel:0 - 10% Employment Type:Full Time/Salaried/Exempt Anticipated Salary Range:- $85,000.Security Clearance:TS/SCI with Poly Level of Experience:Mid This opport... Show more