Job Description
Job Title
Security Operations Specialist
The U.S. Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) plays a critical role in safeguarding our national security.
We are dedicated to preventing, identifying, containing, and eradicating cyber threats to CBP networks through advanced monitoring, intrusion detection, and protective security services.
CBP SOC is chargeable with ensuring the overall security of our Enterprise-wide information systems, and diligently investigates and reports any suspected or confirmed security violations.
Key Responsibilities:
• Develop, test, and maintain automation scripts and workflows in the SOAR platform.
• Design and implement efficient, reusable Python code.
• Debug and address technical issues throughout all stages of the Software Development Life Cycle (SDLC).
• Integrate the SOAR platform with other security tools and APIs to facilitate automated workflows.
• Work collaboratively with System Administrators, Engineers, and Information System Security Officers (ISSOs) to provision service accounts and manage permissions.
• Contribute to the development and improvement of Security Operations processes, including creating and modifying Standard Operating Procedures (SOPs), Playbooks, and Work Instructions.
• Measure and analyze the effectiveness of process improvements and automation efforts through metrics and KPIs.
Basic Qualifications:
• Bachelor's degree in a related discipline or equivalent experience, with 8 to 12 years of professional experience; or 6 to 10 years with a Master's degree.
• Expertise in Python programming.
• Familiarity with SOAP/REST APIs, JSON, HTML/CSS, JavaScript, and XML.
• Experience with SOAR platforms such as Swimlane, Phantom, or Demisto.
• Background as a SOC Analyst or Incident Responder.
• Proficient in drafting SOC SOPs, playbooks, and process documents.
• Knowledge of Splunk Search Processing Language (SPL) or Elastic Domain Specific Language (DSL).
• Understanding of networking concepts, including routers, firewalls, DNS, DHCP, subnetting, VPNs, and Web Proxies.
• Must be a U.S. Citizen.
Preferred Qualifications:
• At least 2 years of experience as a SOC Analyst or Incident Responder.
Responsibilities
- CBP SOC is chargeable with ensuring the overall security of our Enterprise-wide information systems, and diligently investigates and reports any suspected or confirmed security violations
- Develop, test, and maintain automation scripts and workflows in the SOAR platform
- Design and implement efficient, reusable Python code
- Debug and address technical issues throughout all stages of the Software Development Life Cycle (SDLC)
- Integrate the SOAR platform with other security tools and APIs to facilitate automated workflows
- Work collaboratively with System Administrators, Engineers, and Information System Security Officers (ISSOs) to provision service accounts and manage permissions
- Contribute to the development and improvement of Security Operations processes, including creating and modifying Standard Operating Procedures (SOPs), Playbooks, and Work Instructions
- Measure and analyze the effectiveness of process improvements and automation efforts through metrics and KPIs
Requirements
- Bachelor's degree in a related discipline or equivalent experience, with 8 to 12 years of professional experience; or 6 to 10 years with a Master's degree
- Expertise in Python programming
- Familiarity with SOAP/REST APIs, JSON, HTML/CSS, JavaScript, and XML
- Experience with SOAR platforms such as Swimlane, Phantom, or Demisto
- Background as a SOC Analyst or Incident Responder
- Proficient in drafting SOC SOPs, playbooks, and process documents
- Knowledge of Splunk Search Processing Language (SPL) or Elastic Domain Specific Language (DSL)
- Understanding of networking concepts, including routers, firewalls, DNS, DHCP, subnetting, VPNs, and Web Proxies
- Must be a U.S. Citizen