وصف الوظيفة
نظرة عامة: تعمل V2X حول العالم على بناء حلول ذكية مدمجة بين البنية التحتية المادية والرقمية من الأساس إلى ساحة المعركة. نحن نجلب 120 عامًا من دعم المهمة بنجاح لتحسين الأمن وتسهيل اللوجستيات وتعزيز الجاهزية. مقترن بغاية مشتركة، تعمل شركتنا بقيمة 3.9 مليار دولار و16,000 موظف بجانب عملائنا هنا وفي الخارج لمعالجة تحدياتهم الأكثر تعقيدًا بنزاهة واحترام ومسؤولية واحترافية. يعمل محلل إدارة ArcSight (المسمى المقترح تغيير إلى مهندس أمن المعلومات وإدارة الأحداث - SIEM) في دعم التشغيل والصيانة لبيئة SIEM التابعة للجيش. يقدم أعضاء فريق SIEM الدعم الإداري لأنظمة تشغيل Red Hat Enterprise Linux وMicrosoft Windows Server، مع ضمان كفاءة إجراءات إدخال البيانات وتخزينها واسترجاعها وتحليلها عبر مؤسستنا. ينصح ويساعد العملاء بمطالبات التكوين الأمني. يساعد المهندسون في متطلبات إطار إدارة المخاطر RMF. البرنامج: OMDAC-SWACA يتيح هذا المنصب سكنًا ونقلًا مدفوعين من الشركة، ومكافأة إتمام وبرنامج سداد الرسوم الدراسية! يجب عليك استيفاء جميع متطلبات الدولة المضيفة للعمل بشكل قانوني في الدولة المضيفة بما في ذلك، على سبيل المثال لا الحصر، القدرة على الحصول على تأشيرة وطن مضيف وحصته رخصة قيادة وطن مضيف للّيُعتبر مؤهلًا لهذا المنصب. المسؤوليات + المسؤول عن تنفيذ، إدارة، واستكشاف أزمات منتجات SIEM بما في ذلك Elasticsearch وKibana وBeats & Logstash (ELK). + تنظيم المستودعات للمعلومات التكوينية وتطوير آليات لتسجيل وتتبع تغييرات تكوين الشبكة. + تفسير، تحليل، ومراقبة التوافق مع سياسات الأمن السيبراني. مراجعة وتحديث تكتيكات وتقنيات وإجراءات الأمن السيبراني (TTPs) وإجراءات التشغيل القياسية (SOPs). + المسؤول عن تثبيت إدارة وتشغيل Red Hat Enterprise Linux وMicrosoft Windows Server وأنظمة تشغيل أخرى، وConfluent Kafka، وDocker، وLogStash، وZookeeper وغيرها من منتجات SIEM المرتبطة. + القدرة على استكشاف أخطاء الخوادم ومعدات البنية التحتية. + القدرة على تقييم متطلبات الشبكات وتقديم حلول. + حضور الاجتماعات الدورية أو عقدها لإبقاء جميع الأطراف مطلعين على تغييرات الشبكة وأنظمة الاتصالات/البيانات والتحسينات وتقدم المشروع حسب المطلوب. + القدرة على اتخاذ قرارات دقيقة ومستقلة تحت الضغط. + خبرة في بيئة تتمحور حول خدمة العملاء. + مهارات تنظيمية ومهارات تواصل شفهية وكتابية ممتازة. + القدرة على الأداء بشكل مريح في بيئة عمل سريعة الإيقاع وتلتزم بالمواعيد. + القدرة على تنفيذ العديد من المهام المعقدة في وقت واحد بنجاح + أداء واجبات ومهام أخرى مكلف بها. المؤهلات + المؤهلات + تصريح أمني: + يتطلب تصريحًا سريًا نشطًا + التعليم / الشهادات: يمكن بدلاً من سنة واحدة من الخبرة التعليمية أن تُعوض سنة من التعليم إذا كان الدرجة مطلوبة. + شهادة الثانوية العامة أو GED مطلوبة، يفضل إكمال بعض الكلية. + هذا المنصب يتطلب من المرشحين الالتزام بـ DoD 8570.01M. يُطلب من جميع المرشحين الحفاظ على شهادة أساسية واحدة على الأقل وشهادة بيئة حوسبة CE واحدة على الأقل. لا يمكن استخدام شهادات الأساس كإحدى شهادات CE. + الشهادات الممنوحة لهذا اللقب كما يلي: + الأساس: + CompTIA: CASP+ ce: ممارس أمني متقدم + CompTIA: SecurityX ce + GIAC: GCED: مدافع المؤسسة المعتمد + GIAC: GCIH: متعامل حادث معتمد + GIAC: GICSP: محترف الأمن السيبراني الصناعي + GIAC: GSEC: أساسيات الأمن + ISACA: CISA: مُدقق أنظمة معلومات معتمد + ISC2: CISSP (أو مساعد): محترف أمني للمعلومات المعتمد + ISC2: SSCP: ممارس أمن الأنظمة المعتمَد + بيئة الحوسبة (CE): + Microsoft: 365 معتمد: مسؤول مؤسسي خبير + Microsoft: 365 معتمد: مساعد مدير الرسائل + Microsoft: 365 معتمد: مساعد مدير الأمن + Microsoft: معتمد: مساعد مدير Azure + Microsoft: معتمد: مساعد مدير قاعدة بيانات Azure + Microsoft: معتمد: مهندس أمان Azure + Microsoft: معتمد: معـمــد Architect Azure + Microsoft: معتمد: مساعد مدير الهوية والوصول + Microsoft: معتمد: مساعد مدير حماية المعلومات + Microsoft: معتمد: مساعد محلل عمليات الأمن + Microsoft: MCSE: سحاب البنية التحتية والمنصة + Microsoft: MCSE: بنية أساسية أساسية + Microsoft: MCSE: إدارة البيانات والتحليلات + Microsoft: MCSE: حلول الإنتاجية خبير + Microsoft: MCSE: بنية الخادم 2016 + Microsoft: MCSM: ماجستير الحلول المعتمد (أي) + Red Hat: RHCA: مهندس معماري معتمد (أي) + Red Hat: RHCE: مهندس معتمد + Red Hat: RHCSA: مدير نظام معتمد + الخبرة: يمكن استبدال سنة من الدراسة الأكاديمية المرتبطة بعد المدرسة الثانوية بسنة من الخبرة حتى الحد الأقصى لشهادة بكالوريوس لمدة أربع سنوات في تخصص هندسة البرمجيات أو نظم معلومات الأعمال لمدة ثلاث سنوات من الخبرة العامة. + يتطلب الحد الأدنى من سبع (5) سنوات من الخبرة في العمل الإداري والفني، وهو ما يُظهر القدرة والمَلَكة اللازمة لأداء عمل تقني وتحليلي يتضمن أنظمة إدارة المعلومات. + المنصات التي تشمل مزيجًا من التالي: + Elastic + Kibana + Red Hat Linux + Microsoft Windows وقواعد البيانات العلائقية. + خبرة مع شركة تعتمد على خدمة العملاء. + المهارات والتقنية المستخدمة: + الكفاءة في إدارة واستكشاف SIEM، بما في ذلك Elasticsearch وKibana وBeats وLogstash ومكونات ELK Stack ذات الصلة. + الكفاءة في دعم Red Hat Enterprise Linux وMicrosoft Windows Server في بيئة SIEM أو أمن المؤسسة. + معرفة عملية بـ Confluent Kafka وDocker وZookeeper وLogStash والتقنيات المرتبطة بإدخال البيانات أو خطوط المعالجة. + القدرة على رصد والتحقق من صحة وتTroubleshoot استلام السجلات، التحليل، الفهرسة، الاحتفاظ، وأداء البحث عبر مصادر بيانات SIEM. + القدرة على تنظيم وتوثيق وصيانة مستودعات التكوين وتتبع تغييرات الشبكة أو النظام. + معرفة بسياسات الأمن السيبراني وتكتيكات وطرق وتوثيق الامتثال دعم متطلبات الأمن التشغيلي. + الإلمام بمتطلبات إطار إدارة المخاطر RMF والمواد الداعمة. + الكفاءة في استخدام أدوات Microsoft الإنتاجية، وMicrosoft Visio، وServiceNow، وبرامج عميل البريد الإلكتروني وتطبيقات التنقل المؤسسي. + القدرة على استكشاف الخوادم ومعدات البنية التحتية ومشكلات تدفق البيانات في بيئة عمليات سريعة. + مهارات تحليلية وتنظيمية وتواصل بين الأشخاص مكتوبة وشفوية قوية. في V2X، نلتزم بشدة بمبدأ تكافؤ فرص العمل، بما في ذلك حماية المحاربين القدامى والأشخاص ذوي الإعاقة، وتعزيز مكان عمل شامل ومتعدد. نحن نضمن معاملة جميع الأفراد بالإنصاف والاحترام والكرامة، مع الاعتراف بالقوة الناتجة عن وجود قوة عاملة غنية بتجارب وآفاق ومهارات متنوعة. هذا الالتزام، المتوافق مع رؤيتنا وقيمنا الأساسية المتمثلة في النزاهة والاحترام والمسؤولية، يتيح لنا استغلال الاختلافات، وتشجيع الابتكار، وتوسيع نجاحنا في السوق العالمية، مما يمكّننا في نهاية المطاف من خدمة عملائنا بأفضل شكل ممكن.
Job description
Overview Working across the globe, V2X builds smart solutions designed to integrate physical and digital infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around a shared purpose, our $3.9B company and 16,000 people work alongside our clients, here and abroad, to tackle their most complex challenges with integrity, respect, responsibility, and professionalism. The ArcSight Management Analyst (proposed title change Security Information and Event Management (SIEM) Engineer) performs operation and maintenance (O&M) support of the Army SIEM (Security Information and Event Management) environment. SIEM team members provide administrative support of Red Hat Enterprise Linux and Microsoft Windows Server operating systems, assuring efficient data intake, storage, retrieval, and analysis procedures across our organization. Advises and assists customers with security configuration requirements. Engineers assist with the Risk Management Framework (RMF) requirements. Program: OMDAC-SWACA This position offers company-paid housing and transportation, a completion bonus and tuition reimbursement program! You must satisfy all host country requirements to legally work in the host country to include but not limited to the ability to obtain and maintain a host nation visa and host nation driver’s license in order to be qualified for this position. Responsibilities + Responsible for implementation, administration, and troubleshooting of SIEM products including Elasticsearch, Kibana, Beats & Logstash (ELK). + Organize repositories for configuration information and develop mechanisms to record and track network configuration changes. + Interpret, analyze, and monitor for compliance with Cyber Security policies. Review and update Cyber Security tactics, techniques, and procedures (TTPs) and Standard Operating Procedures (SOPs). + Responsible for installation, administration, and operation of Red Hat Enterprise Linux, Microsoft Windows Server operating systems, Confluent Kafka, Docker, LogStash, Zookeeper and other associated SIEM products. + Ability to troubleshoot servers and infrastructure equipment. + Ability to assess networking requirements and provide solutions. + Attend and or conduct regular meetings to keep all parties appraised of network and communications/data systems changes, improvements, and project progression as required. + Ability to make accurate and independent decisions under pressure. + Experience with a customer service-oriented environment. + Excellent organizational, interpersonal, written, and verbal communication skills. + Ability to perform comfortably in a fast-paced, deadline-oriented work environment. + Ability to successfully execute many complex tasks simultaneously + Performs other duties and assignments assigned. Qualifications + Qualifications + Security Clearance: + Requires an active Secret Clearance + Education / Certifications: One-year related experience can be substituted for one year of education if the degree is required. + High School diploma or GED required, some college preferred. + This position requires candidates to adhere to DoD 8570.01M. All candidates are required to maintain at least one (1) baseline certification and one (1) computing environment (CE) certification. Baseline certifications cannot also be used as a Computing Environment (CE) certification. + The authorized certifications for this job title are listed as follows: + Baseline: + CompTIA: CASP+ ce: Advanced Security Practitioner + CompTIA: SecurityX ce + GIAC: GCED: Certified Enterprise Defender + GIAC: GCIH: Certified Incident Handler + GIAC: GICSP: Industrial Cyber Security Professional + GIAC: GSEC: Security Essentials + ISACA: CISA: Certified Information Systems Auditor + ISC2: CISSP (or Associate): Certified Information Systems Security Professional + ISC2: SSCP: Systems Security Certified Practitioner + Computing Environment (CE): + Microsoft: 365 Certified: Enterprise Administrator Expert + Microsoft: 365 Certified: Messaging Administrator Associate + Microsoft: 365 Certified: Security Administrator Associate + Microsoft: Certified: Azure Administrator Associate + Microsoft: Certified: Azure Database Administrator Associate + Microsoft: Certified: Azure Security Engineer Associate + Microsoft: Certified: Azure Solutions Architect Expert + Microsoft: Certified: Identity and Access Administrator Associate + Microsoft: Certified: Information Protection Administrator Associate + Microsoft: Certified: Security Operations Analyst Associate + Microsoft: MCSE: Cloud Platform and Infrastructure + Microsoft: MCSE: Core Infrastructure + Microsoft: MCSE: Database Management and Analytics + Microsoft: MCSE: Productivity Solutions Expert + Microsoft: MCSE: Server Infrastructure 2016 + Microsoft: MCSM: Certified Solutions Master (Any) + Red Hat: RHCA: Certified Architect (Any) + Red Hat: RHCE: Certified Engineer + Red Hat: RHCSA: Certified System Administrator + Experience: One year of related academic study above the high school level may be substituted for one year of experience up to a maximum of a 4-year bachelor's degree in a Software Engineering or Business Information Systems discipline for three years general experience. + Requires a minimum of seven (5) years of experience in administrative, technical work, which demonstrates the ability and aptitude required to perform technical and analytical work involving information management systems. + Platforms including a combination of the following: + Elastic + Kibana + Red Hat Linux + Microsoft Windows and relational databases. + Experience with a customer service-oriented company. + Skills & Technology Used: + Proficiency administering and troubleshooting SIEM platforms, including Elasticsearch, Kibana, Beats, Logstash, and related ELK Stack components. + Proficiency supporting Red Hat Enterprise Linux and Microsoft Windows Server operating systems in a SIEM or enterprise security environment. + Working knowledge of Confluent Kafka, Docker, Zookeeper, Logstash, and related data ingestion or pipeline technologies. + Ability to monitor, validate, and troubleshoot log ingestion, parsing, indexing, retention, and search performance across SIEM data sources. + Ability to organize, document, and maintain configuration repositories and track network or system configuration changes. + Knowledge of cybersecurity policies, TTPs, SOPs, and compliance documentation in support of operational security requirements. + Familiarity with Risk Management Framework (RMF) requirements and supporting artifacts. + Proficiency using Microsoft productivity tools, Microsoft Visio, ServiceNow, email client software, and corporate mobility applications. + Ability to troubleshoot servers, infrastructure equipment, and data flow issues in a fast-paced operational environment. + Strong analytical, organizational, interpersonal, written, and verbal communication skills. At V2X, we are deeply committed to both equal employment opportunity, including protection for Veterans and individuals with disabilities, and fostering an inclusive and diverse workplace. We ensure all individuals are treated with fairness, respect, and dignity, recognizing the strength that comes from a workforce rich in diverse experiences, perspectives, and skills. This commitment, aligned with our core Vision and Values of Integrity, Respect, and Responsibility, allows us to leverage differences, encourage innovation, and expand our success in the global marketplace, ultimately enabling us to best serve our clients.