Talent.com
CareFirst BlueCross BlueShield
Lead Cyber Security Analyst (Remote)CareFirst BlueCross BlueShield • Owings Mills, MD
Lead Cyber Security Analyst (Remote)

Lead Cyber Security Analyst (Remote)

CareFirst BlueCross BlueShield • Owings Mills, MD
30+ days ago
Job type
  • Full-time
  • Remote
Job description

PURPOSE:

The Lead CyberSecurity Analyst is responsible for the monitoring, detection, and analysis of security threats against the distributed enterprise network. The selected candidate should have proven experience and the ability to leverage Computer Network Defense/Blue Team (CND) analyst toolsets to detect and respond to Cyber security incidents. This role conducts research and documents threats and their behavior; provides recommendations for threat mitigation strategies; employs effective communications to clearly manage security incident response procedures; and performs routine event reporting including trend reporting and analysis.

PRINCIPLE ACCOUNTABILITIES: Under the direction of the Manager, CyberSecurity Monitoring, the incumbent is responsible for, but is not limited to, the following:

Duties and Responsibilities:

  • Monitor consoles and telemetry directly from a variety of security toolsets and from the SIEM.
  • Thoroughly investigate and document security events.
  • Audit and review system reports and security logs for unauthorized access, noncompliant activity, or access misuse.
  • Monitor and escalate incoming security requests and events of interest from different external and internal sources.
  • Follow standard operating procedures for detecting, classifying, and reporting incidents.
  • Develop or improve use cases to increase efficacy, performance, or outcomes for security monitoring.
  • Participate in incident response activities as necessary.
  • Triage (determine scope, severity, and priority) of events in Security Information and Event Management (SIEM) tool or within other security monitoring tools directly.
  • Research vulnerabilities in applications and systems. Provide recommendations for resolution and track remediation activities.
  • Traffic analysis (at the packet level) and reconstruction of network traffic to discover anomalies, trends, and patterns affecting the customer's networks.
  • Analyze firewall logs, Full Packet Capture (PCAP), IDS alerts, Anti-malware alerts, Host Intrusion Prevent System (HIPS), and server and application logs to investigate events and incidents for anomalous activity and produce reports of findings.
  • Coordinate with third party providers to ensure appropriate detections are built and deployed.
  • Coordinate with Threat Intelligence and Response Operations to enhance time to detection and response.

QUALIFICATION:

Required Education and Experience: Degree or equivalent experience: BA/BS in Information Technology, CyberSecurity, Networking, Information Security, MIS, Computer Science or related field.

Experience Level: Minimum 5 years of demonstrated work experience. (Additional experience may be substituted for educational requirement.)

Along with the basic qualifications, the candidate will need to have experience in the following areas:

  • Deployment, configuration and management of Endpoint Detection and Response (EDR/XDR) tools, such as CrowdStrike.
  • Experience managing Microsoft Defender for Endpoint.
  • Experience in a hybrid multi-cloud environment – Azure highly preferred.
  • Experienced in the application and usage of threat analysis models/frameworks such as the Cyber Kill Chain, MITRE ATT&CK, etc.
  • Advanced knowledge of threat Tactics, Techniques and Procedures (TTPs), especially in cloud environments and including SaaS services like M365.

Specialized training (preferred, but not required): Transitioning, maintaining, or using security technologies such as Security Incident and Event Management (SIEM), Endpoint protection, Data Loss Prevention, Forensic tools, Network Anomaly Detection, Packet Capture Analysis; Incident response principles or related technical domain that is applied in the context of a broader understanding of CSIRT and related systems and processes.

Licenses/Certifications: One or more of the following certifications are preferred but not required OR the ability to obtain one certification within 6 months.

GCIA (GIAC Certified Intrusion Analyst)

GMON (GIAC Continuous Monitoring)

GCIH (GIAC Certified Incident Handler)

CCFA (CrowdStrike Certified Falcon Administrator)

GSOC (GIAC Security Operations Certified

CCFR (CrowdStrike Certified Falcon Responder)

Microsoft Certified: Security Operations Analyst Associate

CCFH (CrowdStrike Certified Falcon Hunter)

Knowledge, Skills and Abilities (KSAs)

  • Must be able to effectively work in a fast-paced environment with frequently changing priorities, deadlines, and workloads that can be variable for long periods of time. Must be able to effectively communicate.
  • Incumbent must have a firm understanding of Information and/or Cyber Security principles. Must be able to adapt quickly to understand rapidly changing threat landscape in order to correctly scope and prioritize security events. The incumbent must also be able to achieve certification across multiple domains such as networking, security, development languages, etc.

Required skills:

  • Experience preventing, detecting, analyzing and responding to threats against sensitive information.
  • Experience triaging security, network and endpoint forensic analysis, threat hunting and vulnerability escalation.
  • Experience with security monitoring and reporting tools and conducting security investigations of incidents and events.
  • Critical thinking and analytical skills to develop enhanced workflows and use cases for next generation platforms and cloud technology.
  • Experience with analyzing large data sets and log files to find correlations and anomalies.
  • Ability to utilize native cloud security tools in Azure to design and implement continuous monitoring solutions.
  • Advanced knowledge and use of Splunk.

Preferred Skills:

  • Ability to script proficiently in either Python or PowerShell
  • Advanced knowledge and use of Linux
  • OSINT collection and analysis.

Department

Department:

Equal Employment Opportunity

CareFirst BlueCross BlueShield is an Equal Opportunity (EEO) employer. It is the policy of the Company to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

Create a job alert for this search

Lead Cyber Security Analyst (Remote) • Owings Mills, MD

Similar jobs

Associate Compliance Analyst

BrooksourceOwings Mills, MD, United States
Full-time

Owings Mill, MD (3 days in office per week).Depending on Experience – 40hr/week).We seek to hire an Associate Compliance Analyst to support our client’s Cybersecurity & Compliance organization.This... Show more

 • Promoted

Target Digital Network Analyst (TDNA)

GIGATEC EngineeringAnnapolis Junction, MD, US
Full-time
Quick Apply

Perks and Benefits 100% Paid Healthcare 10% 401k in every paycheck 100% Fully Vested!!!.NOTE  – Our positions require a  Top Secret clearance , as well as the favorable  comple... Show more

Computer Network Defense Analyst

National Security AgencySevern, MD, United States
Full-time

Computer Network Defense Analysts work in multiple organizations at NSA and are primarily responsible for finding vulnerabilities, delivering analyses, crafting mitigations, developing cybersecurit... Show more

 • Promoted

Joint Cybersecurity Analyst

Axelon Services CorporationArnold, MD, US
Full-time

Title: Cybersecurity Analyst (Remote) Location: Remote-first flexibility with opportunities for long-term career growth Job Description: Client is seeking a Joint Cybersecurity Analyst to support t... Show more

 • Promoted

Lead Security Consultant - Security Assessments

Jensen HughesBaltimore, MD, United States
Full-time

Lead Security Consultant - Security Assessments.Jensen Hughes is seeking a Security Lead Consultant to deliver trusted security and risk management advisory services to a select portfolio of client... Show more

 • Promoted

35F Intelligence Analyst

Army National GuardTowson, MD
Part-time

On the battlefield, success depends on accurate and timely intel.As an Army National Guard Intelligence Analyst, you will play a key role in the interpretation and exploitation of information gathe... Show more

 • Promoted

Investment Risk Senior Analyst

Franklin ResourcesBaltimore, MD, United States
Full-time

Investment Risk Management Team Member.At Franklin Templeton, we're advancing our industry forward by developing new and innovative ways to help our clients achieve their investment goals.Our dynam... Show more

 • Promoted

Compliance Analyst

ManTechFort George G Meade, MD, United States
Full-time

Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security, providing advanced solutions to government intelligence agencies.Since 1968, we've been s... Show more

 • Promoted

Senior Cybersecurity Engineer / Site Lead

PROVATOHR INCLinthicum Heights, MD, US
Full-time
Quick Apply

Senior Cybersecurity Engineer / Site Lead Job Title:.Senior Cybersecurity Engineer / Site Lead Location:  Linthicum Heights, MD — 100% onsite Clearance:  Active Top Secret required;... Show more

Target Digital Network Analyst- ALL Levels

Hoplite Solutions LLCFort Meade, MD, US
Full-time
Quick Apply

Hoplite Solutions is seeking Target Digital Network Analysts (TDNAs) to support core Intelligence Community (IC) missions at multiple locations to include  Maryland.As a TDNA, you will be... Show more

Senior Cyber Threat Planning

PD IncMD, US
Full-time
Quick Apply

Senior Cyber Threat Planning Location:  Fort Meade, MD 20755 Clearance Level: Active Secret Clearance Job Type: Full-Time PD Inc International is seeking an experienced and mission-driven Seni... Show more

Cyber Security Analyst

Leidos IncFort Meade, MD, US
Full-time

This position will support the DISA GSM-O II Task Number 07 (TN07).GSM-O II provides network operations and cyber defense support to the Defense Information Systems Agency (DISA) in support of the ... Show more

 • Promoted • New!

Threat Analyst

Independent SoftwareFort Meade, MD, US
Full-time
Quick Apply

As a Threat Analyst at Independent Software, you will analyze and assess potential risks to missions, personnel, and facilities by leveraging data from multiple systems and information sources.You ... Show more

Cyber Security Engineer

MaximusFort Meade, MD, United States
Full-time

Maximus is a trusted federal partner supporting mission‑critical programs across national security, defense, and public service delivery.Recent contract awards in cybersecurity and operational read... Show more

 • Promoted

Industrial Security Specialist

iQuasar LLCHanover, MD, United States
Full-time

Industrial Security Specialist/h2piQuasar is seeking to fill an Industrial Security Specialist position for our customer in Hanover, MD.At iQuasar, we strive to provide the next generation of cutti... Show more

 • Promoted

Intrusion Analyst, Level 3

Independent SoftwareAnnapolis Junction, MD, US
Full-time
Quick Apply

At Independent Software, as an Intrusion Analyst Level 3, you will support mission-critical cybersecurity operations by analyzing digital network data to identify, assess, and respond to unauthoriz... Show more

VP, Technology (AI, Cyber & Compliance Platforms)

FutureFeedBaltimore, MD, US
Full-time

FutureFeed is seeking a growth-stage technology leader to own and scale a portfolio of products focused on cybersecurity, compliance, and governance (GRC).This role will lead the development of Att... Show more

Digital Network Exploitation Analyst (DNEA)

CTC GroupFort Meade, MD, US
Full-time
Quick Apply

Summary CTC Group is seeking Digital Network Exploitation Analysts (DNEA),  levels 1-4, evaluate target opportunities using all source data to understand and map target networks, and to assist... Show more

Cyberspace Policy Analyst Remote / Hybrid, TS / SCI

Booz Allen HamiltonSevern, MD, United States
Remote
Full-time

A leading defense contractor in Fort Meade is seeking a Cyberspace Policy Analyst to support USCYBERCOM by analyzing doctrine and policy.The ideal candidate will have over 5 years of relevant exper... Show more

 • Promoted

INDUSTRIAL SECURITY SPECIALIST (TRADITIONAL REVIEWER)

US Department of WarFort George G Meade, MD, United States
Full-time

Industrial Security Specialist (Traditional Reviewer).As an Industrial Security Specialist (Traditional Reviewer) you will be responsible for the following duties:.Conduct security compliance revie... Show more