GovCIO is seeking a CSOC Classified Support Engineer to support federal cyber defense missions. In this role, you will monitor classified networks, analyze security alerts, investigate potential intrusions, and coordinate rapid incident response within a 24x7 Cyber Security Operations Center. You'll tune SIEM and security tools, create playbooks, document findings, and collaborate with engineers and analysts to strengthen defenses. Working in a mission-driven, fast-paced environment, you'll leverage modern security technologies while growing your skills through training, mentorship, and impactful national security projects.
Responsibilities
- Monitor classified networks and systems for security events and anomalies in a 24x7 CSOC environment.
- Analyze and triage security alerts, identifying true positives and prioritizing incidents by impact and risk.
- Execute incident response activities, including containment, eradication, and recovery, following established playbooks.
- Configure, tune, and maintain SIEM and related security tools to improve detection quality and reduce noise.
- Conduct threat hunting and log analysis to identify indicators of compromise and emerging attack patterns.
- Collaborate with system and network engineers to remediate vulnerabilities and strengthen security controls.
- Develop and maintain security documentation, incident reports, and standard operating procedures.
- Support compliance with federal security policies and standards for classified environments.
- Participate in on-call rotations and shift work as needed to support 24x7 operations.
- Engage in continuous learning, training, and knowledge sharing to stay current on cyber threats and defense techniques.
Required Skills
- Security operations monitoring
- SIEM tools (e.g., Splunk, QRadar)
- Intrusion detection and prevention (IDS/IPS)
- Incident response and containment
- Threat hunting and analysis
- Network security and TCP/IPEndpoint detection and response (EDR)
- Vulnerability management
- Log analysis and correlation
- Security documentation and reporting