T1 Cyber Network Defense Analyst – Shift (w/ active TS)
$58,000–$74,000 year
HybridWashington, District of Columbia, United States or Washington, United States
Job Summary
Monitor network traffic and security logs using SIEM tools to detect anomalies, malware patterns, and threats. Investigate cyber security alerts by analyzing PCAP, firewall, proxy, and IDS logs, then create Security Event Notifications to document findings. Collaborate with team members to perform critical thinking analysis while utilizing OSINT and staying current on emerging threats. Review shared email notifications and contribute to content tuning requests. Requires active TS/SCI clearance, ability to work non-core hours, and on-site presence in Washington, DC.
Required Qualifications
- Active TS/SCI and must be able to obtain and maintain an Entry on Duty (EOD) clearance
- Must have the ability to work non-core hours, if necessary
- Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field
- Minimum of two (2) years professional experience in Network Administration
- Minimum of two (2) years professional experience in Unix/Linux Administration
- Minimum of two (2) years professional experience in Software engineering
- Minimum of two (2) years professional experience in Software development
- Minimum of two (2) years professional experience in Systems administration
- Minimum of two (2) years professional experience in Help desk/IT support
- Familiarity with a SOC's purpose and role within an organization
- General understanding of common network ports and protocols (e.g. TCP/UDP, HTTP, ICMP, DNS, SMTP, etc)
- Familiarity with network topologies and network security device functions (e.g. Firewall, IDS/IPS, Proxy, DNS, etc)
- Familiarity with packet analysis tools such as Wireshark
- Able to perform critical thinking and analysis to investigate cyber security alerts
- Familiarity with common malware and attack vectors
- Familiarity with Windows operating systems and standard OS logging
- Familiarity with Antivirus, DLP, and host based firewalls
- Must have one of the following certifications: A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Security+, CySA+
- Must possess an active DoD Top Secret Clearance
- Must undergo background investigation (BI) and finger printing by the federal agency and successfully pass the preceding
- US CITIZENSHIP IS REQUIRED
- Must be willing and able to commute to Washington, DC
Desired Qualifications
- The ideal candidate is a self-motivated individual in pursuit of a career in cyber security
- Familiar with SOC methodologies and processes
- Familiarity with scripting languages (e.g. Python, Powershell, Javascript, VBS etc)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.