Network Based Systems Analyst IV
$131,000–$150,000 year
On-siteArlington, Virginia, United States
Job Summary
Coordinate teams for preliminary incident response investigations and interface with the customer during onsite engagements. Determine courses of action for anomalous network activity while assessing topology and device configurations to identify security concerns. Collect intrusion artifacts such as PCAPs and certificates to enable mitigation of Computer Network Defense incidents. Analyze malicious activity to determine exploited weaknesses and provide technical briefings on incident findings. Support real-time incident handling including forensic collections, intrusion correlation, and threat analysis to advise on system remediation.
Required Qualifications
- US Citizen
- active TS/SCI clearance
- DHS Suitability
- 8+ years of directly relevant experience in network investigations
- In depth knowledge of CND policies, procedures and regulations
- In depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, TCP/IP
- In depth knowledge and experience of Wifi networking
- In depth knowledge and experience of network topologies - DMZ's, WAN's, etc.
- Substantial knowledge of Splunk (or other SIEM's)
- Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
- Knowledge of Computer Network Defense policies, procedures, and regulations
- Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
- Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
- Ability to identify and analyze anomalies in network traffic using metadata
- Experience with reconstructing a malicious attack or activity based on network traffic
- Experience examining network topologies to understand data flows through the network
- Must be able to work collaboratively across physical locations
- BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma and 10+ years of network investigations experience
Desired Qualifications
- Substantial knowledge of network device integrity concepts and methodologies
- Proficiency with network analysis software (e.g. Wireshark)
- Proficiency with carving and extracting information from PCAP data
- Proficiency with non-traditional network traffic (e.g. Command and Control)
- Proficiency with preserving evidence integrity according to standard operating procedures or national standards
- Proficiency with virtualized environments
- DoD 8140.01 IAT Level II, IASAE II, CSSP Analyst, GCIA, GCIH, CSSP Analyst/CSSP Incident Responder, CEH
- SANS GIAC GNFA preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.