Digital Forensics SOC Analyst Job at Connvertex Technologies Inc., Crownsville, MD

VmdaanFwNXB4eVRsN3pMMFRJWmVxa3o1U0E9PQ==
  • Connvertex Technologies Inc.
  • Crownsville, MD

Job Description

Position: Digital Forensics SOC Analyst

Duties and Responsibilities:

  • Report to Director of Security Operations or his/her designee
  • Provide SOC Analyst Tier 3 escalation support
  • Plan, initiate, and conduct investigations for cybersecurity incidents response efforts
  • Perform forensic examinations on compromised systems
  • Understand and use forensic tools and techniques for cybersecurity incidents
  • Create forensic root cause and scope of impact analysis reports
  • Contribute to technical briefings on the details of forensics exams and report
  • Provide support in conducting malware analysis of attacker tools
  • Stay current on incident response and digital forensics skills, best practices, and tools
  • Train SOC analysts on usage of SIEM tools (Splunk), and basic event analysis
  • Develop rules and tune SIEM and related tools to streamline the event analysis done by the SOC
  • Assist developing new processes and procedures for SOC monitoring
  • Monitor networks for threats from external and internal sources
  • Analyze network traffic of compromised systems and networks
  • Correlate actionable security events from various sources
  • Review threat data and develop custom detection signatures
  • Gather and analyze threat intelligence data and conduct threat hunting
  • Understand cybersecurity attacks and tactics, techniques, and procedures (TTPs) associated with advanced threats
  • Communicate clearly with Government counterparts, and SOC customers
  • Development and implementation and operational and technical incident response processes, procedure, guidance, and standards
  • Ability to work outside of regular business hours, the role may require on-call support after regular business hours or weekends.

Minimum Qualifications:

  • Hands-on experience with security monitoring and SIEMs tools - Splunk Enterprise Security is preferred
  • Demonstrated working knowledge of cyber forensics and incident handling best practice processes, procedures, standards, and techniques
  • Hands-on experience with forensics image capture tools i.e., FTK Imager, MAGNET ACQUIRE
  • Hands-on experience with system image/file system/registry forensics tools i.e., Encase, FTK, X-Ways, Magnet AXIOM, Sleuthkit, Access Data Registry Viewer, Registry Recon, or other)
  • Hands-on experience with PCAP analysis tools i.e., Wireshark, TCP Dump, Network Miner, Xplico, or other
  • Hands-on experience with memory forensics tools i.e., BlackLight, Volatility, SANS SIFT, Magnet RAM Capture, or FireEye Memoryze, CrowdStrike Crowd Response
  • Hands-on experience with Endpoint Detection & Response solutions - Tanium Threat Response, McAfee or other

Desired Skills/Certifications:

  • Practical hands-on experience with static in malware analysis
  • Hands-on experience with malware anti-forensics, obfuscation, packing techniques
  • Hands-on experience with malware Analysis - Miscellaneous dynamic & static analysis tools (IDA Pro, Ghidra, OllyDBG, WinHex, HexEdit, HexDump, PeSTudio, REMux, OLEDUMP)
  • Hands-on experience with Custom Signature Creation - YARA
  • Scripting/Programming experience - Python, Perl, C, C++, Go
  • Highly desired industry certifications include Certified Forensics Computer Examiner (CFCE), Computer Hacking Forensic Investigator (CHFI), GIAC Certified Forensic Examiner (GCFE), Certified Computer Examiner (CCE)
  • Relevant industry certifications such as Certified Ethical Hacker (CEH), GIAC Reverse Engineering Malware (GREM), Certified Reverse Engineering Analyst (CREA) etc.

Educational and Years of Experience: Bachelor s degree from an accredited college or university with a major in Computer Science, Information Systems, Engineering or related scientific or technical discipline and 4+ years of experience. Associate degree and/or cyber courses/certifications or 5 years of experience in directly related fields may be substituted in lieu of bachelor s degree

Job Tags

Weekend work,

Similar Jobs

Facets

Community Development Advocate Job at Facets

 ...position is located in either our Annandale or Centreville location. FACETS is hiring a mission-driven Education and Community Development Advocate (ECD). The ECD Advocate works within the Education and Community Development (ECD) department, which assesses the needs... 

PERFECT PATCH ASPHALT

Class A Lowboy Tandem Dump Truck Driver Job Job at PERFECT PATCH ASPHALT

Class A Lowboy Tandem Dump Truck Driver JobApplicants must be able to transport paving equipment or haul material with a tandem dump truck. Plenty of hours. Must have clean current MVR. New trucks to drive. In business for over 40 years. Please stop by our office at... 

MDE Logistics

CDL-A Truck Driver Owner Operator Job at MDE Logistics

 ...days out ~ Owner Operators and Company Drivers welcome ~ Driver earning $2000-$3000 weekly...  ...Requirements: ~12 months Class A Verifiable experience required and 6 months...  ...experience . ~ Must possess a valid Class A CDL ~ Must be able to pass a pre-employment... 

The Brydon Group

Brydon CEO in Residence (2025 Cohort) Job at The Brydon Group

 ...At the Brydon Group , we accelerate the trajectory of outstanding mid-career operators who want to become CEOs and build and grow industry-leading platforms with private equity support, resources and capital. Brydon CEO-in-Residence (CIR) Program: Brydon selects... 

City Cast

Producer, Austin Job at City Cast

 ...City Cast is hiring a Producer for our daily local podcast in Austin, Texas. Were looking for a versatile and inventive Producer who cares deeply about local news and culture, and is excited about the opportunity to use podcasting to help people feel more connected to...