Montana Veteran Jobs

facebook youtube linkedin
Mobile Montana Labor & Industry Mobile Logo

Job Information

State of Montana Incident Response SOAR Specialist - Hybrid (66713) in Helena, Montana

Why live in Helena, Montana? · Helena is surrounded by rolling hills and lofty mountains and is tucked below the Continental Divide. · It is a relatively quiet place to call home where small-town living collides with outdoor adventure. · Helena has a rich history and was originally founded as a gold camp during the Montana gold rush. · Learn more about moving to and/or living in Helena, Montanahere.* * Why should you keep reading and consider working here? We know you have other work options, but we ask you to consider working with us at the State of Montana Department of Administration in theState Information Technology Services Division (SITSD). Our mission to provide shared IT services to support the needs of the state and citizens of Montana. We offer an innovative and collaborative work environment where employees are valued and supported. In addition, our employees have the opportunity to be involved in some of the most exciting and innovative IT projects and initiatives in development within Montana state government. (You can learn more about SITSDhere.) What is this career opportunity? * The Office of Security Services’ mission is to protect citizen’s data. We embrace cybersecurity standards, guidelines, best practices, and the NIST Cybersecurity Framework to achieve our core functions. This position is responsible for performing entry to intermediate level incident response investigations as well as administration of our Security Orchestration and Automation Response (SOAR) platform. Some additional responsibilities include, but are not limited to: · Develops SOAR playbooks to automate manual security processes (Detection, Analysis, Containment, Eradication, and Recovery). · Assists investigations of security incidents for the enterprise. *NICE Cybersecurity Workforce Framework Categories and Specialty Areas Applicable to This Role Protect and Defend – Incident Response Investigates, analyzes, and responds to cyber incidents within the network environment or enclave. Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Investigates and analyzes all relevant response activities. What are we looking for?__ Education and Experience: // /Required for the first day of work, including alternatives:/ · Bachelor’s degree in Information Security or Technology, and 2 years’ experience working in a SOAR platform. · Proficiency in one of more of the following languages: PowerShell, Bash, Java, Python, C, C , or C# · Certification in GCIH or GPYC or the ability to attain certification within 12 months of hire. · Alternate combinations of education and experience and certifications will be considered on a case-by-case basis. / / /Preferred:/ · GCFA, GCIH, GPYC, or other incident response or SOAR certifications PCSAE a plus;// · Experience with basic incident response investigations.// · Experience in building automation playbooks in SOAR platforms.// * * Competencies:// /Knowledge of:/ · Comprehensive understanding of the cybersecurity threat landscape, incident response strategies and effective mitigation techniques. · Cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks). · Working knowledge of Splunk and other SIEMS products and processes. · Strong understanding of security architecture, tool integration, API development and automation. · Knowledge using Python and other scripting languages for the purpose of automating security operations and incident response processes (PowerShell, Bash, Java, Python, C, C , and C#). /Ability to:/ · Protect a network against malware. (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters). · Use security event correlation tools. · Develop and document SOAR standard operating procedures. · Mentor junior team members, empowering growth within the cybersecurity team. · Ability to analyze complex security scenarios and develop effective, automated responses. Does this sound like you? Please tell us how and why by submitting yourresume andcover letter. /(Please Note: You do not need to complete the “work experience” or the “education & certifications” portion of the application process in our recruiting system. You only need to upload the requested documentation.)/ What can you expect from us in return for your hard work? Ø Lookhereto see the additional benefits! They include: o Work/life Balance o Health Coverage o Retirement plans o Paid Vacation and Sick Leave and Holidays o And more… Ø Public Service Loan Forgiveness (PSLF) –Employmentwith the State of Montana may qualify you to receive student loan forgiveness under the PSLF. Lookhereto learn more and see if you may qualify! * * Other important information to be aware of. * This position requires the successful completion of a criminal background check. * Only online applications are accepted. By applying online, you are able to receive updates and monitor the status of your application. *Title: *Incident Response SOAR Specialist - Hybrid (66713) Location: Helena Requisition ID: 24141562

DirectEmployers