Network Defense Analyst
$31,200–$31,200 year
On-siteHuntsville, Alabama, United States
Job Summary
Analyze network data using packet capture, network flow, and cloud logs to identify security incidents and report high-risk findings. Assist customers with remediation of vulnerabilities, misconfigurations, and cyber incidents while enforcing endpoint quarantine policies on high-risk devices. Conduct daily reviews of open vulnerabilities using network and endpoint security solutions, tracking mitigation efforts until resolved. Generate monthly reports summarizing cyber security posture and coordinate with operational teams to prepare for assessments. Provide analysis and recommendations to achieve acceptable mitigation of security incidents and ensure policy compliance across firewalls, routers, and cloud services.
Required Qualifications
- Bachelor's degree or higher in a related field
- Minimum of 1-4 years of related experience
- Active CompTIA Security+CE certification with the ability to obtain one of the following certifications within two months of hire: CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, PenTest+
- Strong written and verbal communication skills
- Ability to communicate and present information to customers at varying levels of technical detail
- Comfortable working in a constantly adapting and changing environment that may require learning new skills and the ability to adjust priorities
- Basic knowledge of Computer Network Defense activities to include standard cyber-defense Intrusion Detection Systems (IDS), Intrusion Protection Systems (IPS), network monitoring, packet capture analysis, network flow analysis, network proxy operation, firewalls, and anti-virus capabilities
- Basic knowledge of vulnerability and risk management techniques in a cyber security setting, including handling risk/severity-based prioritization and decision making
- One of the following active certifications (or ability to obtain within two months of hire): CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, PenTest+
Desired Qualifications
- Experience analyzing alerts using PCAPs and/or cloud logs, as well as an understanding of network threats, potential network exploitation, and methods to defend against potential malicious activity
- Proficiency in Office 365 tools at a professional level
- Experience using vulnerability scanning solutions such as Tenable Nessus
- Experience using data presentation/automation tools such as PowerBI or Tableau
- Experience assessing Security Technical Implementation Guide (STIG) findings
- Experience working with Endpoint Security Solutions such as Trellix or Microsoft Defender Endpoint
- Experience handling risk/severity-based prioritization and decision making
- CySA+ or CEH certification
- Top Secret Clearance
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.