About the Role
<span><span><span><b><span><span><span>Job Description</span></span></span></b></span></span></span><br />
<span><span><span><span><span><span>We are seeking a <b>Cyber Security Analyst</b>. This position provides 24x7 cybersecurity monitoring and analysis services for Department of Defense networks above the SECRET level. This includes performing real-time cyber threat intelligence analysis, correlating actionable security events, performing network traffic analysis using raw packet data, and participating in the coordination of resources during the incident response process.</span></span></span></span></span></span>
<ul>
<li><span><span><span><span><span><span>Review DoD and open source intelligence for threats and to identify Indicators of Compromise (IOCs) and integrate those into sensors and SIEMs</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Utilize alerts from endpoints, IDS/IPS, netflow, and custom sensors to identify compromises on customer networks/endpoints</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Review massive log files, pivot between data sets, and correlate evidence for incident investigations</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Triage alerts to identify malicious actors on customer networks</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Report incidents to customers and USCYBERCOM</span></span></span></span></span></span></li>
</ul>
<span><span><span><b><span><span><span>Qualifications</span></span></span></b></span></span></span>
<ul>
<li><span><span><span><span><span><span>Bachelor's Degree and 4+ years of prior relevant experience; additional work experience or Cyber courses/certifications may be substituted in lieu of a degree.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>DoD 8570 IAT level II or higher certification such as CompTIA Security+ CE, ISC2 SSCP, SANS GSEC prior to starting.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>DoD 8570 CSSP-A level Certification such as CEH, CySA+, GCIA or other certification is required within 180 days of hire.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Demonstrated commitment to training, self-study and maintaining proficiency in the technical cyber security domain and an ability to think and work independently</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Bachelor's degree and less than 2+ years of prior relevant experience; additional work experience or Cyber courses/certifications may be substituted in lieu of degree.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Strong analytical and troubleshooting skills</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Willing to perform shift work</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Must be a US Citizen</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Must have an active DoD TOP Secret security w/ SCI clearance eligibility.</span></span></span></span></span></span></li>
</ul>
<span><span><span><b><span><span><span>Preferred Qualifications:</span></span></span></b></span></span></span>
<ul>
<li><span><span><span><span><span><span>CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Demonstrated hands-on experience analyzing high volumes of logs, network data (e.g. Netflow, Full Packet Capture), and other attack artifacts in support of incident investigations.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. ArcSight, Splunk, Nitro/McAfee Enterprise Security Manager, QRadar, LogLogic).</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Experience and proficiency with any of the following: Anti-Virus, HIPS/HBSS, IDS/IPS, Full Packet Capture, Network Forensics.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Experience with malware analysis concepts and methods.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Unix/Linux command line experience.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Scripting and programming experience.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Familiarity or experience in Intelligence Driven Defense and/or Cyber Kill Chain methodology.</span></span></span></span></span></span></li>
<li><span><span><span><span><span><span>Existing 8570 CSSP Analyst Certifications (CEH), CySA+ etc.</span></span></span></span></span></span></li>
</ul>
<span><span><span><b><span><span><span>Clearance Level: TSSCI</span></span></span></b></span></span></span><br />
<span><span><span><span><span><span>Certifications: IAT Level II Baseline Certification</span></span></span></span></span></span><br />