Home
/
Comprehensive
/
Cyber Security Operations Engineer
Cyber Security Operations Engineer-February 2024
Virtual
Feb 19, 2025
About Cyber Security Operations Engineer

  Overview BigBear.ai is seeking a Cybersecurity Operations Engineer to support our team as we enhance our cybersecurity posture. As a member of our team, you'll keep an eye on the evolving threat landscape, staying ahead of emerging threats that may target our company, customers, and vendors. To excel in the Security Operations team, you must be curious, passionate, and willing to spend long hours learning about systems, security tools, and evolving threat actor methodologies. As the last line of defense, you will play a vital role in upholding the overall security stance of businesses by reviewing events that occur within the security stack, pinpointing vulnerabilities, escalating incidents, and advising or deploying mitigation tactics. You will conduct research to understand our technological footprint, the potential pathways attackers could traverse to compromise our systems and develop detection strategies to ensure we quickly identify malicious activity. Tooling and automation will be key to success as we scale our business to meet the dynamic demands of our customers. We are a small team of geographically dispersed high performers. While prior experience working remotely isn't required, you must perform well given a high level of independence and autonomy while collaborating asynchronously within and across teams. This role is 100% remote but may require occasional travel to the DC metropolitan area. What you will do Monitor substantial amounts of data from various sources. Investigate, document, and report on any information security (InfoSec) issues as well as emerging trends. Conduct threat and vulnerability analysis. Assist with the implementation, operationalization, or optimization of projects in support of the cybersecurity program. Conduct network and system vulnerability assessments using appropriate security tools to identify and address potential threats. Follow and establish security monitoring and response procedures and processes for monitoring system security events and measuring compliance with organizational security policies and procedures. Ensure the success of the vulnerability management program by triaging security risks and working with system owners to mitigate findings in accordance with SLAs. Work closely with the GRC team on the development and implementation of standards, operating procedures, and controls. You will also coordinate and document exemptions to established security controls. Assists with external information security audits for regulatory compliance and assessments such as penetration testing. Other duties as assigned. What you need to have Clearance not initially required, however, must be clearable to SECRET. Experience: 5+ years of experience in a SOC, with demonstrable experience using security tools such as: Security Information and Event Management (SIEM) solutions, firewalls, vulnerability scanners, SOAR, and EDR/MDR technology. Minimum 3-5 years of experience with log integration and analysis. Experience operating within NIST 800-171, NIST-800-53, CMMC or equivalent cybersecurity frameworks. Technical skills: You must possess the ability to quickly analyze large amounts of information and identify patterns that may signify potential security incidents. Firm grasp of anomaly identification, incident response, and threat mitigation. Must be familiar with MITRE ATT&CK and Cyber Kill Chain methodologies. Proficient understanding of Information technology systems and processes, network infrastructure, data architecture, data processes, and protocols. Working knowledge of Operating System security Ability to break down complex detection logic, and to explain to others how the detection works, the theory behind it, and what to do when the alert is triggered. Understanding of which logs are available and useful for: Linux (Production Workloads), Mac, Windows AWS, GCP, and Azure Soft Skills: Excellent written and oral communication skills. Must be able to clearly communicate risks at both strategic and tactical level. Must work well under pressure. Cybersecurity incidents don’t just happen from 9-5 so you must be flexible with your schedule. You must have the maturity and experience to recognize when an incident is critical and must be escalated. What we'd like you to have Scripting skills in Python, PowerShell, Bash, SQL, or Perl. ServiceNow IT Operations Zscaler or other SASE solution Cloud Security expertise Cloud Workload Forensics - Memory and Storage collection and analysis Understanding of legal holds, chain of custody and other IR activities Understand how to develop rules utilizing hypothesis driven detection research leveraging tools such as: YARA rules Python Athena, SQL, Presto etc. Threat Intelligence Services and OSINT About BigBear.ai BigBear.ai delivers AI-powered analytics and cyber engineering solutions to support mission-critical operations and decision-making in complex, real-world environments. BigBear.ai’s customers, which include the US Intelligence Community, Department of Defense, the US Federal Government, as well as customers in manufacturing, healthcare, commercial space, and other sectors, rely on BigBear.ai’s solutions to see and shape their world through reliable, predictive insights and goal-oriented advice. Headquartered in Columbia, Maryland, BigBear.ai is a global, public company traded on the NYSE under the symbol BBAI. For more information, please visit: http://bigbear.ai/ and follow BigBear.ai on Twitter: @BigBearai.

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Pharmacy Technician
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced
Data Configuration Engineer (Associate Manager)
By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Taked
Help Desk Analyst I
Description This on-site position in Bedford MA, requires US Citizenship and the ability to obtain a DoD Security Clearance. Description: The Information Technology Support Specialist is responsible
BSWH- Food Service Worker
Job Description The Food Service Worker will assist the manager with food/meal preparation; maintain cash receipts and meal records. Assist manager in completing daily reports. Maintain high standard
Store Protection Specialist
Our values start with our people, join a team that values you! We are the nation’s largest off-price retailer with over 2,000 stores, and a strong track record of success and growth. Our focus has al
Server
Live Your Passion. Add Your Magic. At Montage International, we are doing something different, something exciting and it takes passionate people to bring our vision to life. We have built a culture t
Early Morning Stock Associate
Our values start with our people, join a team that values you! We are the nation’s largest off-price retailer with over 2,000 stores, and a strong track record of success and growth. Our focus has al
Food Preparation Workers
Cook. 8 temp/full-time positions w/ J.C. Beach Havn Tvrn LLC DBA Buckalws Restaurnt frm 4/1/24-10/31/24. Prepare/seasn/& cook dishs like soups/salads/meats/vegetbles/&/or desserts in
Warehouse Technician
Overview Our business is real estate, but our organization is so much more than bricks and mortar, beautiful buildings and well-managed properties. Our business is about people who need a place to ca
Quality Engineer
::: {align=center} ::: ::: {align=center} ::: Quality Engineer (Job ID: 1042-226)   ::: {align=center}*Cincinnati Incorporated *is a privately owned industrial machine manufacturer that has been a st
Copyright 2023-2025 - www.zdrecruit.com All Rights Reserved