Lemont, IL Hybrid Contract

Delan Associates, Inc is hiring a Cybersecurity Analyst

Requirements

  • 1-3 years in a SOC, cybersecurity 'blue team', or closely related role.
  • Strong grasp of TCP/IP, OSI model, and common protocols (HTTP, DNS, SMTP).
  • Windows/Linux/macOS fundamentals; Active Directory/Azure AD concepts; basic cloud logging.
  • Experience with at least one SIEM and one EDR/XDR platform.
  • Experience with ticketing/case management.
  • Ability to craft queries using common languages; comfort with regex, JSON and APIs; basic scripting in Python/PowerShell/Bash.
  • Excellent analytical, problem-solving, and communication skills both with stakeholders, peers, and internal customers; able to operate under pressure in a shift or on-call environment.

Nice to Have

  • 3-5 years relevant experience including investigations, data analysis, and detection tuning.
  • Comfort using Splunk Processing Language (SPL), CrowdStrike EDR, and ServiceNow.
  • Experience with SOAR tools and automation development.
  • Experience using identity security/management tools (e.g., Entra ID, Active Directory, Shibboleth, CrowdStrike Identity Protection).
  • Cloud security experience (e.g., CloudTrail/GuardDuty, Azure Defender/M365, GCP Security Command Center).
  • Basic forensics skills and network analysis fundamentals (host triage, timelines, artifact analysis, packet/PCAP review).
  • Understanding of the Cybersecurity Framework (CSF) and NIST 800-53 controls.

Work Arrangement

Hybrid

Additional Information

  • Experience in system and network administration.
  • Staying up to date with the latest cybersecurity threats, vulnerabilities, and best practices.
  • Strong analytical and problem-solving skills.
  • Meticulous attention to detail to ensure thorough assessments and accurate reporting.
  • Excellent written and verbal communication skills to effectively convey findings and recommendations to technical and non-technical stakeholders.
  • Ability to work collaboratively with other cybersecurity professionals, IT staff, and external vendors.
  • Considerable knowledge/experience of assessing security controls.
  • Experience and skill in conducting audits or reviews of technical systems.
  • Experience working in a government environment.
  • Experience working in a distributed IT environment.
  • Ability to qualify for HSPD-12 card for use in two-factor authentication.
  • Able to work both independently and as a contributing member of a small technical team
  • Able to disseminate knowledge to current staff.
  • Company will supply a government-furnished laptop, PIV Card, and PIV Card reader.
  • The contractor shall adhere to all policies and procedures of the ANL Computer Protection Program, must not bypass any procedures established to protect data, applications, hardware, or communications at ANL, must maintain a work environment that will satisfy audit, privacy, and protection requirements, and must report any findings of inadequacies to the technical contact and the BIS Computer Protection Program Representative.
  • Working remotely outside of scheduled times requires supervisor approval prior to performing that remote work.
  • While working remotely, just like when onsite, all scheduled meetings must be attended (using approved remote communication tools).
  • The candidate must be available for consultation during all scheduled work time, reachable by email, phone, chat, or other approved means.
  • Performance will be monitored to determine productivity for remote work at least matches that when onsite. If performance and deliverables decline, remote work may be suspended.
  • Should a situation arise that requires the candidate to be onsite while scheduled to work remotely, accommodation will be made to reschedule the remote work, if desired.
  • The remote work privilege may be revoked at any time at the discretion of Argonne.
  • A flexible work schedule may also be possible if the schedule is agreed to by the candidate and approved by the supervisor and sponsor.
  • Should the laboratory close operations due to weather or other circumstances, remote work is preferred.
  • The candidate must track their remote work schedule into the CSPO absence calendar and be approved by CSPO supervisor.
Required Skills
at least one SIEMone EDR/XDR platfoticketing/case management.SOAR toolsautomation development.identity security/management tools at least one SIEMone EDR/XDR platfoticketing/case management.SOAR toolsautomation development.identity security/management tools
Need to work legally in Thailand?

Work permits without the paperwork nightmare

Thai immigration rules are strict and easy to get wrong. SVBL handles the bureaucracy — correct visa type, proper documentation, timely submissions. You focus on your work.

Right visa type for your situation
Document preparation & submission
Deadline tracking & renewals
Direct liaison with immigration
Talk to an expert
10+ years experience
About company
Delan Associates, Inc

Delan Associates, Inc. (DAI) is a professional services and engineering provider established in 2002.

  • Engineering, Training, Management Services and Solutions Provider since 2002
  • Fiscally Stable-Conservative Management Team
  • SBA Certified Small Disadvantaged Business

We specialize in Engineering Services, Training Services, General Support and Management Services, and Specialized Manufacturing.

Founded on Integrity, Loyalty, and Dedication to the Customer.

All jobs at Delan Associates, Inc Visit website
Job Details
Department Cyber Security Program Office (CSPO)
Category security
Posted 8 months ago