Job Overview:
Pay Range $59.70/hr - $63.70/hr
Requirement/Must Have:
- 2+ Years of Experience with Security Monitoring and Incident Response.
- 2+ Years of Experience with MITRE ATT&CK framework.
- 2+ Years of Experience with dashboard creation and reporting.
Responsibilities:
- Continuously review and correlate security event data across SIEM, EDR, IDS/IPS, and threat intelligence sources to identify complex attack patterns, emerging threats, and security incidents.
- Perform deep-dive analysis of suspicious activity, validate incidents, determine root cause and impact, and escalate critical incidents with detailed context to Tier 3 as required.
- Create detailed incident reports, timelines, and post-incident summaries; contribute to lessons-learned documentation and recommendations for remediation and preventative measures.
- Investigate user-reported phishing, malware infections, and potential policy violations; advise users and internal/external teams on containment and recovery actions.
- Recommend updates to SOC playbooks and workflows based on real-world investigations, fine-tune detection rules, alert thresholds, and correlation logic to reduce false positives and improve threat coverage.
- Collaborate with engineering teams to ensure monitoring tools are properly configured and tuned.
- Integrate new threat intelligence feeds into workflows.
- Serve as a customer-facing SME, demonstrating capabilities and resolving issues.
- Document processes, runbooks, and troubleshooting steps related to SOC operations.
- Coordinate with engineering, SOC, and agency staff as needed to meet goals.
- Other duties as needed.
Nice to Have:
- Experience with the Palo Alto Cortex XSIAM/XDR platform.
- Knowledge of Linux, network administration, and network design.
- Experience in administration of firewalls, VPN technology, Active Directory, Intrusion Detection/Prevention systems.
Qualification And Education:
- Associate’s degree in an information technology or information security related field.
- Four years of relevant work experience may be substituted in lieu of education.
- CISSP, CISA, CISO or equivalent advanced security certification is preferred.
- Additional relevant certifications (e.g., CEH, OSCP, GPEN) are preferred.
- Vendor certifications related to information security are preferred.
Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading staffing and recruiting powerhouse. Proudly recognized as a nationally and locally certified diversity firm, Cynet delivers agile, scalable talent solutions across industries. With an active footprint in all 50 U.S. states and Canada, we support thousands of consultants through our expansive, high-performing recruitment engine operating across North America and Asia—ensuring speed, quality, and consistency in every hire.