Cybersecurity - Cyber Defense Analyst - Malware, Vulnerability, Incidents
$210,000–$232,000 year
On-siteFort Meade, Maryland, United States
Job Summary
Monitor network activity using cyber defense tools to detect, analyze, and triage anomalous behavior, then generate cybersecurity cases detailing event history, status, and potential impact. Isolate indicators of compromise by conducting PCAP analysis, protocol-level traffic evaluation, and netflow analysis to identify attack phases and Command and Control channels. Perform advanced manual analysis to hunt previously unidentified threats, correlate events across enterprise sources for situational awareness, and recommend proactive security measures. Lead and mentor team members while documenting after-action reviews to ensure analysis completion.
Required Qualifications
- Current Top-Secret/SCI with polygraph security clearance
- Eight (8) years of demonstrated experience as a CDA in programs and contracts of similar scope, type, and complexity
- Technical bachelor's degree from an accredited college or university (substitutable for two years of CDA experience)
- Two (2) years of demonstrated and practical experience in TCP/IP fundamentals
- Two (2) years of demonstrated experience with network traffic analysis tools such as Bricata, tcpdump or Wireshark
- Three (3) years of demonstrated experience using security information and event management suites (such as Splunk, ArcSight, Kibana, LogRhythm)
- Three (3) years of demonstrated experience in network analysis and threat analysis software utilization
- DoD 8570 compliance with CSSP Analyst baseline certification
- Information Assurance Technical (IAT) Level I or Level II certification
- Computing Environment (CE) certification (Microsoft OS, Cent OS/Red Hat OS)
- Global Information Assurances Certification (GIAC) Certified Incident Handler (GCIH) certificate or Certified Intrusion Analyst (GCIA) certificate
- Successful completion of the Splunk software training course 'Fundamentals 1'
- Three (3) years of demonstrated experience maintaining or managing Cloud environments such as Microsoft Azure, Amazon Web Services (AWS), using tools like Microsoft Sentinel
- Availability for 8x5 shift
Desired Qualifications
- Knowledge of commonly used network protocols and detection methods
- Application of cybersecurity and privacy principles to organizational requirements (confidentiality, integrity, availability, authentication, non-repudiation)
- Advanced manual analysis to hunt previously unidentified threats
- PCAP analysis skills
- Identification of cyber-attack phases based on knowledge of common attack vectors and network layers, models and protocols
- Techniques for detecting host- and network-based intrusions
- Working knowledge of enterprise-level network intrusion detection/prevention systems and firewall capabilities
- Understanding of the foundations of a hardened windows network and native services/protocols subject to abuse (RDP, Kerberos, NTLM, WMI, SMB)
- Familiarity with fragmentation of network traffic and detection of fragmentation related attacks in raw packet captures
- Conduct of network – traffic, protocol and packet-level – and netflow analysis for anomalous values using appropriate tools (Wireshark, tshark, tcpdump)
- Understanding of snort filters and how they are crafted and tuned to feed IDS alerting
- Understanding of system and application security threats and vulnerabilities (buffer overflow, SQL injection, race conditions, covert channel, replay, return-oriented attacks, malicious code, malicious scripting)
- Analysis of malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information
- Performance of event correlation using information gathered from a variety of sources within the enterprise
- Familiarity with indications of Command and Control (C2) channels and strategies attackers use to bypass enterprise defenses
- Demonstration of advanced knowledge of how adversaries penetrate networks and how those attacks map to detectable events across the ATTACK framework
- Understanding of how VBS, Jscript, and Powershell can be maliciously used within a network and required monitoring/auditing
- Deep knowledge of active directory abuse used by attackers for lateral movement and persistence
- Expertise in the identification of adversarial Tactics, Techniques, and Procedures (TTPs) and in the development and deployment of signatures
- Performance of after-action reviews of team products to ensure completion of analysis
- Ability to lead and mentor team members as a technical expert
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.