يؤدي محلل إدارة ArcSight (الاسم الوظيفي المقترح هندسة المعلومات الأمنية وإدارة الأحداث (SIEM)) دعم التشغيل والصيانة (O&M) لبيئة SIEM الخاصة بالجيش. يوفر أعضاء فريق SIEM الدعم الإداري لنظامي Red Hat Enterprise Linux وMicrosoft Windows Server، مع ضمان كفاءة إدخال البيانات وتخزينها واسترجاعها وتحليلها عبر منظمتنا. يقدم النصح والمساعدة للعملاء بشأن متطلبات إعدادات الأمن. تساعد المهندسون في متطلبات إطار إدارة المخاطر (RMF). البرنامج: OMDAC-SWACA يوفر هذا المنصب سكنًا ومواصلات مدفوعدين من قبل الشركة، ومكافأة إكمال وبرنامج تعويض الرسوم الدراسية! يجب أن تستوفي جميع متطلبات البلد المضيف للعمل قانونيًا في بلد الاستضافة بما في ذلك، لكن لا تقتصر على، القدرة على الحصول والمحافظة على تأشيرة البلد المضيف ورخصة قيادة البلد المضيف لتكون مؤهلاً لهذا المنصب.
المسؤوليات
- المسؤول عن التنفيذ والإدارة وحل المشكلات لمنتجات SIEM بما في ذلك Elasticsearch وKibana وBeats & Logstash (ELK).
- تنظيم المستودعات الخاصة بمعلومات التكوين وتطوير آليات لتسجيل وتتبع تغييرات تكوين الشبكة.
- فهم وتحليل ومراقبة الامتثال لسياسات الأمن السيبراني.
- مراجعة وتحديث تكتيكات وأساليب وإجراءات الأمن السيبراني (TTPs) وإجراءات التشغيل القياسية (SOPs).
- المسؤول عن التثبيت والإدارة والتشغيل لأنظمة Red Hat Enterprise Linux وMicrosoft Windows Server، وConfluent Kafka وDocker وLogStash وZookeeper ومنتجات SIEM المرتبطة الأخرى.
- القدرة على استكشاف مشاكل الخوادم ومعدات البنية التحتية.
- القدرة على تقييم متطلبات الشبكات وتقديم الحلول.
- حضور الاجتماعات المنتظمة أو عقدها لإبقاء جميع الأطراف على اطلاع بالتغييرات في الشبكة وأنظمة الاتصالات/البيانات والتحسينات وتقدم المشروع حسب الحاجة.
- القدرة على اتخاذ قرارات دقيقة ومستقلة تحت الضغط.
- خبرة في بيئة تركز على خدمة العملاء.
- مهارات تنظيمية وبشرية مكتوبة وشفوية ممتازة.
- القدرة على الأداء بشكل مريح في بيئة عمل سريعة الوتيرة وتلزم بالموعد النهائي.
- القدرة على تنفيذ العديد من المهام المعقدة بنجاح في وقت واحد
- أداء واجبات وتكليفات أخرى كما هو مُحدد.
الملف المرغوب فيه للمرشح
المؤهلات
- إذن أمني: يتطلب وجود تصريح سري نشط
- التعليم / الشهادات: يمكن استبدال سنة من الخبرة ذات الصلة بسنة واحدة من التعليم إذا كان الدرجة مطلوبة. مطلوب شهادة الثانوية العامة أو GED، وبعض الجامعي مفضل.
- هذا المنصب يتطلب من المرشحين الالتزام بـ DoD 8570.01M. جميع المرشحين مطلوب منهم الحفاظ على شهادة أساسية واحدة على الأقل وشهادة بيئة حوسبية (CE) واحدة. لا يمكن استخدام الشهادات الأساسية أيضًا كشهادة بيئة حوسبة (CE). الشهادات المصرح بها لهذا اللقب مذكورة فيما يلي:
- الأساسي: CompTIA: CASP+ ce: ممارس أمني متقدم
CompTIA: SecurityX ce GIAC: GCED: المدافع المؤسسي المعتمد
GIAC: GCIH: مُعالج الحوادث المعتمد
GIAC: GICSP: محترف الأمن السيبراني الصناعي
GIAC: GSEC: أساسيات الأمن
ISACA: CISA: مُدقق نظم المعلومات المعتمد
ISC2: CISSP (أو Associate): محترف الأمن المعلوماتي المعتمد
ISC2: SSCP: ممارس أمان النظم المعتمد - بيئة الحوسبة (CE): مايكروسوفت: 365 معتمد: مسؤول المؤسسة المحترف
مايكروسوفت: 365 معتمد: مسؤول المراسلة المعتمد
مايكروسوفت: 365 معتمد: مسؤول الأمان المعتمد
مايكروسوفت: معتمد: مسؤول Azure الإداري المعتمد
مايكروسوفت: معتمد: مسؤول قاعدة بيانات Azure المعتمد
مايكروسوفت: معتمد: مهندس أمان Azure المعتمد
مايكروسوفت: معتمد: مهندس حلول Azure المعتمد
مايكروسوفت: معتمد: مسؤول الهوية والوصول المعتمد
مايكروسوفت: معتمد: مسؤول حماية المعلومات المعتمد
مايكروسوفت: معتمد: محلل عمليات الأمن المعتمد
مايكروسوفت: MCSE: سحابة ومنصة بنية تحتية
مايكروسوفت: MCSE: بنية أساسية أساسية
مايكروسوفت: MCSE: إدارة وتحليلات البيانات
مايكروسوفت: MCSE: حلول الإنتاجية - الخبرة: يمكن استبدال سنة من الدراسة الأكاديمية المرتبطة فوق مستوى المدرسة الثانوية بسنة واحدة من الخبرة حتى الحد الأقصى لشهادة البكالوريوس لمدة أربع سنوات في تخصص هندسة البرمجيات أو أنظمة معلومات الأعمال مقابل ثلاث سنوات من الخبرة العامة.
- يتطلب الحد الأدنى من خمس (5) سنوات من الخبرة في العمل الإداري والتقني، والتي تُظهر القدرة والكفاءة اللازمة لأداء العمل التقني والتحليلي الذي يتضمن أنظمة إدارة المعلومات. منصات تشمل مزيجاً من: Elastic Kibana Red Hat Linux Microsoft Windows وقواعد البيانات العلائقية.
- خبرة مع شركة تركّز على خدمة العملاء.
- المهارات والتقنيات المستخدمة: الكفاءة في إدارة واستكشاف SIEM منصات، بما في ذلك Elasticsearch وKibana وBeats وLogstash والمكوّنات ذات الصلة من ELK Stack.
- الكفاءة في دعم Red Hat Enterprise Linux وMicrosoft Windows Server في بيئة SIEM أو أمنيّة مؤسسية.
- معرفة عملية بـ Confluent Kafka وDocker وZookeeper وLogstash والتقنيات المرتبطة بإدخال البيانات أو خطوط الأنابيب.
- القدرة على مراقبة والتحقق من صحة واستكشاف أخطاء إدخال السجلات، وتحليلها، وفهرستها، والاحتفاظ بها، والبحث عبر مصادر بيانات SIEM.
- القدرة على تنظيم وتوثيق والحفاظ على مستودعات التكوين وتتبع تغييرات الشبكة أو النظام.
- معرفة بسياسات الأمن السيبراني وTTPs وSOPs والوثائق الامتثالية لدعم متطلبات الأمن التشغيلي.
- الإلمام بمتطلبات إطار إدارة المخاطر (RMF) والوثائق الداعمة.
- الكفاءة في استخدام أدوات الإنتاجية من مايكروسوفت، ومايكروسوفت فيزيو، ServiceNow، وبرامج عميل البريد الإلكتروني، وتطبيقات التنقل المؤسسي.
- القدرة على استكشاف الخوادم ومعدات البنية التحتية ومشاكل تدفق البيانات في بيئة تشغيلية سريعة.
- مهارات تحليلية وتنظيمية وبشرية مكتوبة وشفوية قوية.
The ArcSight Management Analyst (proposed title change Security Information and Event Management (SIEM) Engineer) performs operation and maintenance (O&M) support of the Army SIEM (Security Information and Event Management) environment. SIEM team members provide administrative support of Red Hat Enterprise Linux and Microsoft Windows Server operating systems, assuring efficient data intake, storage, retrieval, and analysis procedures across our organization. Advises and assists customers with security configuration requirements. Engineers assist with the Risk Management Framework (RMF) requirements. Program: OMDAC-SWACA This position offers company-paid housing and transportation, a completion bonus and tuition reimbursement program! You must satisfy all host country requirements to legally work in the host country to include but not limited to the ability to obtain and maintain a host nation visa and host nation driver s license in order to be qualified for this position.
Responsibilities
- Responsible for implementation, administration, and troubleshooting of SIEM products including Elasticsearch, Kibana, Beats & Logstash (ELK).
- Organize repositories for configuration information and develop mechanisms to record and track network configuration changes.
- Interpret, analyze, and monitor for compliance with Cyber Security policies.
- Review and update Cyber Security tactics, techniques and procedures (TTPs) and Standard Operating Procedures (SOPs).
- Responsible for installation, administration, and operation of Red Hat Enterprise Linux, Microsoft Windows Server operating systems, Confluent Kafka, Docker, LogStash, Zookeeper and other associated SIEM products.
- Ability to troubleshoot servers and infrastructure equipment.
- Ability to assess networking requirements and provide solutions.
- Attend and or conduct regular meetings to keep all parties appraised of network and communications/data systems changes, improvements, and project progression as required.
- Ability to make accurate and independent decisions under pressure.
- Experience with a customer service-oriented environment.
- Excellent organizational, interpersonal, written, and verbal communication skills.
- Ability to perform comfortably in a fast-paced, deadline-oriented work environment.
- Ability to successfully execute many complex tasks simultaneously
- Performs other duties and assignments assigned.
Desired Candidate Profile
Qualifications
- Security Clearance: Requires an active Secret Clearance
- Education / Certifications: One-year related experience can be substituted for one year of education if the degree is required. High School diploma or GED required, some college preferred.
- This position requires candidates to adhere to DoD 8570.01M. All candidates are required to maintain at least one (1) baseline certification and one (1) computing environment (CE) certification. Baseline certifications cannot also be used as a Computing Environment (CE) certification. The authorized certifications for this job title are listed as follows:
- Baseline: CompTIA: CASP+ ce: Advanced Security Practitioner CompTIA: SecurityX ce GIAC: GCED: Certified Enterprise Defender GIAC: GCIH: Certified Incident Handler GIAC: GICSP: Industrial Cyber Security Professional GIAC: GSEC: Security Essentials ISACA: CISA: Certified Information Systems Auditor ISC2: CISSP (or Associate): Certified Information Systems Security Professional ISC2: SSCP: Systems Security Certified Practitioner
- Computing Environment (CE): Microsoft: 365 Certified: Enterprise Administrator Expert Microsoft: 365 Certified: Messaging Administrator Associate Microsoft: 365 Certified: Security Administrator Associate Microsoft: Certified: Azure Administrator Associate Microsoft: Certified: Azure Database Administrator Associate Microsoft: Certified: Azure Security Engineer Associate Microsoft: Certified: Azure Solutions Architect Expert Microsoft: Certified: Identity and Access Administrator Associate Microsoft: Certified: Information Protection Administrator Associate Microsoft: Certified: Security Operations Analyst Associate Microsoft: MCSE: Cloud Platform and Infrastructure Microsoft: MCSE: Core Infrastructure Microsoft: MCSE: Database Management and Analytics Microsoft: MCSE: Productivity Solutions Expert Microsoft: MCSE: Server Infrastructure 2016 Microsoft: MCSM: Certified Solutions Master (Any) Red Hat: RHCA: Certified Architect (Any) Red Hat: RHCE: Certified Engineer Red Hat: RHCSA: Certified System Administrator
- Experience: One year of related academic study above the high school level may be substituted for one year of experience up to a maximum of a 4-year bachelor's degree in a Software Engineering or Business Information Systems discipline for three years general experience.
- Requires a minimum of seven (5) years of experience in administrative, technical work, which demonstrates the ability and aptitude required to perform technical and analytical work involving information management systems. Platforms including a combination of the following: Elastic Kibana Red Hat Linux Microsoft Windows and relational databases.
- Experience with a customer service-oriented company.
- Skills & Technology Used: Proficiency administering and troubleshooting SIEM platforms, including Elasticsearch, Kibana, Beats, Logstash, and related ELK Stack components.
- Proficiency supporting Red Hat Enterprise Linux and Microsoft Windows Server operating systems in a SIEM or enterprise security environment.
- Working knowledge of Confluent Kafka, Docker, Zookeeper, Logstash, and related data ingestion or pipeline technologies.
- Ability to monitor, validate, and troubleshoot log ingestion, parsing, indexing, retention, and search performance across SIEM data sources.
- Ability to organize, document, and maintain configuration repositories and track network or system configuration changes.
- Knowledge of cybersecurity policies, TTPs, SOPs, and compliance documentation in support of operational security requirements.
- Familiarity with Risk Management Framework (RMF) requirements and supporting artifacts.
- Proficiency using Microsoft productivity tools, Microsoft Visio, ServiceNow, email client software, and corporate mobility applications.
- Ability to troubleshoot servers, infrastructure equipment, and data flow issues in a fast-paced operational environment.
- Strong analytical, organizational, interpersonal, written, and verbal communication skills.