The Role
Administers Armis Centrix and performs Tier 3 SOC cybersecurity operations for a state government customer. Responsibilities include network security monitoring, incident investigation and response, threat and vulnerability analysis, forensic evidence collection, incident containment, secure system restoration, threat intelligence analysis, tool configuration, vendor coordination, metrics reporting, and executive briefings.
Summary Generated by Built In
Science Applications International Corporation (SAIC) is seeking a senior network security analyst to join our team supporting a major state & local government customer. This position reports to the Security Director. This is an on-site role to act as an analyst and tool admin for Armis.
Essential duties of this position include:
- Hybrid role as an Armis Centrix tool admin and SOC Tier 3, with the potential to be required to support Security Incident Response Team operations.
- Supports dedicated work functions for state government agency.
- Own and manage baseline configurations, policies, and implementation of front-end operations for Armis.
- Work with Armis as a vendor for architecture and engineering implementation concerns.
- Performs network security, cybersecurity defense & analysis, incident response, threat analysis, exploitation analysis, vulnerability analysis, and incident investigations.
- Work is performed in a State Agency managed Security Operations Center (SOC).
- Duties are primarily categorized as Tool Admin and Analyst, Incident Investigation and Response, Security Operations, Incident Management, or similar roles.
- Utilizes COTS/GOTS applications, ticketing systems, lab systems, forensic applications, and/or custom tools, techniques, and procedures (TTPs) to monitor systems for abnormal events and determine if events are to be deemed an incident.
- Determines if incidents are due to malicious or suspicious actions by one or more threat actors.
- Utilizes threat intelligence to determine if the incident is part of a named campaign to determine appropriate levels of response, or provide new intelligence based on investigative actions to threat intelligence teams, organizations, and/or external parties.
- Obtains information and evidence for legal proceedings or to provide to government counterparts for possible military, law enforcement, and/or counter-intelligence response actions/activities, Human Resources investigations, and/or management action.
- Works with system owners to restore affected systems to secure baseline configurations.
- Coordinates with contracted vendors for incident control.
- Researches, evaluates, and recommends new security tools, techniques, and technologies.
- Supports cyber metrics development, maintenance, and reporting for managed tools.
- Provides briefings to senior staff and/or state government agencies executive staff.
Required Education and Qualifications:
- BS Degree and five (5) years or more experience; Masters and three (3) years or more experience; PhD and 0 years related experience.
- Complete understanding and wide application of technical principles, theories, and concepts in the cybersecurity field.
- Ability to receive assignments in the form of objectives and establish goals to meet outlined objectives.
- General knowledge of related IT disciplines.
- Candidates must be a US Citizen and be able to pass a CJIS Criminal Justice background investigation and maintain CJIS clearance throughout employment term.
Required Experience:
- Providing technical solutions to a wide range of difficult problems requiring the analysis of identifiable factors.
- Independent determination and development of approaches to solutions with work reviewed upon completion for adequacy in meeting objectives.
- Demonstrating good judgment in selecting methods and techniques for obtaining solutions.
- Contributing to the completion of specific programs and projects within the government contracting space.
- Security+ or higher certifications.
Preferred Experience:
- ITIL v4 certification preferred (Foundation or above).
- CEH, GCIH, BTL2, CASP, or GSP.
- Providing technical solutions to a wide range of difficult problems requiring the analysis of identifiable factors.
- Independent determination and development of approaches to solutions with work reviewed upon completion for adequacy in meeting objectives.
- Demonstrating good judgment in selecting methods and techniques for obtaining solutions.
- Contributing to the completion of specific programs and projects.
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
Skills Required
- Bachelor’s degree and five or more years of experience, or a master’s degree and three or more years of experience, or a PhD with zero years of related experience.
- Broad technical knowledge of cybersecurity principles, theories, and concepts.
- Ability to develop approaches and solutions to difficult technical problems independently.
- Experience providing technical solutions to complex cybersecurity problems.
- Experience contributing to programs and projects in the government contracting space.
- Security+ or higher certification.
- U.S. citizenship.
- Ability to pass and maintain a CJIS criminal justice background investigation and clearance.
- ITIL v4 certification, Foundation or above.
- CEH, GCIH, BTL2, CASP, or GSP certification.
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Spectrum San Diego is a high tech security innovator, specializing in ultra-low-dose X-ray screening systems.









