Senior Security Analyst/Engineer

Full Time
United States
Posted
Job description
Overview:
Exclusively focused on the Government, Kearney & Company provides financial services, including auditing, consulting, and technology services. Our commitment to our employees and clients as well as to dedication and trust, critical values to our Firm, have led to Kearney’s recognition as one of the leading accounting firms in the country. Based on our employees’ feedback, we are also consistently rated a Best Place to Work. Employment at Kearney means a flexible, collaborative, and open-minded work environment. We hope it is your “first easy decision.” Learn more at www.kearneyco.com/careers.

COVID Policy: Prospective and/or new Kearney team members will be required to comply with any Federal, State, or local guidance related to COVID-19. Although Kearney’s company policy does not mandate vaccinations at this time, Kearney will follow all guidance, which is subject to change. Client site requirements, if different or stricter, will take precedence over Kearney policy. Vaccination status may be requested prior to first day of employment. Prospective or new team members may seek a religious or medical exemption to any current guidance applicable to Kearney that mandates vaccination during the Onboarding process. Additional questions may be directed to a member of Human Resources at 703-931-5600.
Responsibilities:

Kearney & Company is looking for a Senior Security Analyst to join a dedicated Security Operations team responsible for monitoring, managing, operating, deploying, and continuously improving cybersecurity controls and associated technology solutions in client environments. As part of the SOC team, you will work with cross-functional teams that may include IT teams, operational staff, external vendors, third parties, and business partners to identify and address issues. Kearney and Company encourages all employees to learn and grow as professionals at a very aggressive pace. The ideal candidate has a passion for information security, excellent analytical and communication skills, a strong foundation in information security concepts, and a solid understanding of networking and systems technologies.


The Senior Security Analyst is responsible for:
  • Initial triage of security events using established procedures, tools and monitoring platforms including, but not limited to:
    • Firewalls and network devices
    • Servers and workstations
    • Web proxies
    • Intrusion detection and prevention systems (IDS/IPS)
    • Anti-malware systems
    • Security Incident and Event Management systems (SIEM)
    • Data Loss Prevention systems (DLP)
    • Advanced Endpoint Detection and Response systems (EDR)
  • External communications from outside entities, users, phone calls, emailsSupervise and manages mid and junior staff
  • Conduct research on new threats and recommend implementation of preventive measures
  • Develop security policies and procedures
  • Install and maintain security software and hardware
  • Monitor computer networks for unauthorized access or use of network resources
  • Perform risk assessments of current security measures to identify potential vulnerabilities
  • Perform threat hunting activities
  • Assist senior members of the SOC with analyzing and responding to potential security incidents
  • Maintain situational awareness of emerging cyber trends by reviewing open-source reports for recent vulnerabilities, malware, and other threats that have the potential to impact our clients
  • Document threat campaign(s) techniques, lateral movements and extract indicators of compromise (IOCs)
  • Manage the Security monitoring tools, set up dashboards and alerts
  • Expected to stay current on security industry trends, new threats and attack techniques, mitigation techniques, and emerging security technologies
  • Conduct security research and intelligence gathering on emerging threats and exploits
  • Participate on shift-transition calls to ensure all open cases and tasks are properly managed and addressed
  • Periodic reporting of metrics and corresponding analysis for client review and strategic information security program adjustments and planning
  • Maintenance and management of various security technology platforms
Qualifications:
  • Highly motivated to work in information security
  • Bachelor’s degree in Information Technology or related field
  • 7+ years of experience
  • Any of the following certifications: CEH, Security+, OSCP, CISSP, CISM, GSOC, GCFA
  • Candidate must be a US citizen and able to obtain agency suitability
  • Customer oriented & professional
  • Strong verbal and written communication skills
  • Ability to understand and correlate data from multiple sources, not limited to user authentication events, windows security event logs, syslog, NetFlow/PCAP data, DHCP logs, DNS logs, intrusion detections alerts, proxy logs, packet captures, and firewall events.
  • Knowledge of various security
  • methodologies and processes, and technical security solutions a plus
  • Understanding of how both Windows, Linux and network platforms are compromised a plus
  • Experience with any of the following is a plus
    • Elasticsearch
    • Palo Alto Cortex XSOAR
    • Confluent
    • Apache Kafka
    • Microsoft Defender for Endpoint (MDE)
    • Kusto Query Language (KQL)
  • Regular expression creation experience to support dynamic security event analysis.
  • Solid understanding of IP networking fundamentals, including IPv4, TCP/IP, LAN/WAN design theory, static and dynamic routing protocols, NAT, ACLs, etc.
  • Solid Understanding of TCP/IP, the OSI Model, and underlying Protocols.
  • Scripting language skills in Python or PowerShell are a plus
  • Understanding of cyber forensics concepts including malware, hunt, etc.
  • Understanding how to interpret vulnerability and penetration scan results
  • Configuration and knowledge of design and implementation concepts of firewall, VPN, IPS, vulnerability management platforms, and other security technologies is desirable
  • Competency with Microsoft Operating Systems, including server and workstation and AD engineering and administration capabilities, is desirable
The expected salary range for this position is between $100,000 and $150,000. This range is representative of base pay only and does not include straight time pay for hours worked over 40 per week, company contributions towards paid benefits, and/or bonuses. Actual compensation (meeting or exceeding the range) will be determined based on specific experience, education, work location, clearance level, and other factors permitted by law. This position is eligible for bonuses (when applicable).

We also offer a competitive benefits package that includes:
  • Medical, Dental, Vision, Life, AD&D, and Disability Insurance
  • 401(k) Retirement Plan and 529 Education Savings Plan
  • Flexible Spending & Health Savings Account
  • Accident, Critical Illness, Hospital Indemnity Insurances
  • Legal Insurance and Pet Insurance
  • Employee Assistance Program, fitness and wellness benefits, and other firm benefits.
  • Paid holidays, vacation, and sick time

#LI-MA1
KCO1701
EEO Notice:
Applicants have rights under Federal Employment Laws

EEO Notice

Work location is subject to change based on client requirements.

Kearney & Company is an Equal Opportunity Employer and will consider all qualified applicants without regard to race, color, creed, genetic information, religion, national origin, ethnicity, gender; gender identity, sexual orientation, pregnancy, childbirth or related medical condition, age, disability or handicap, servicemember status, relationship or association with a protected veteran, and any other category protected by Federal, state, or local law. Click here to learn more.

If you would like to request a reasonable accommodation, regarding accessibility of our website, a modification or adjustment of the job application or interview process due to a disability, please call 703-236-2391 or email accommodations@kearneyco.com. Please be advised that this contact information is for accommodation requests only and cannot be used to inquire about the status of an application.

Family and Medical Leave Act (FMLA)

FMLA is designed to help employees balance their work and family responsibilities by allowing them to take reasonable unpaid leave for certain family and medical reasons. Kearney & Company provides eligible employees with up to 12 weeks of unpaid, job-protected leave per year. Military family leave is available for up to 26 weeks under FMLA. Click here to learn more.

Employee Polygraph Protection Act (EPPA)

The EPPA prohibits most private employers from using lie detector tests either for pre-employment screening or during the course of employment. Kearney & Company adheres all provisions of the EPPA. Click here to learn more.

caravetterealestate.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, caravetterealestate.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, caravetterealestate.com is the ideal place to find your next job.

Intrested in this job?

Related Jobs

All Related Listed jobs