Network Defense Analyst


AT&T Government Solutions


Columbia, MD 21044

Seeking experienced computer network defense analysts to improve the availability and survivability of customer networks and protection of vital information from cyber adversaries. The ideal candidate must have relevant networking experience (e.g. TCP/IP stack, DNS, BGP, metadata, IDS/IPS) and be able to serve as a Subject Matter Expert in security event identification, threat analysis, and network vulnerability analysis and reporting. Candidates must have expertise in collecting and analyzing host-based (Windows, Linux, or Solaris) and network-based data, utilizing Computer Network Defense or forensic tools, gathering and interpreting information, performing Internet research, identifying mitigation strategies, and effectively communicating results. Should have demonstrated analytic ability to discover unknown, suspicious or exploitation activity and analyze exploitation opportunities and expertise to evaluate and recommend information security enhancements, product upgrades, and tools to ensure minimal exposures. Prior experience with open source vulnerability tools such as nmap, autoscan, nessus, wireshark, snort, etc is desired. Great communications skills, that include the ability to provide formal documentation of analysis and/or research results to include briefings, writing, and editing at a technical/professional level, are required.
Core knowledge, skills:
• knowledge of IP Protocols; experience in protocol research
• knowledge of Internet architecture and routing
• knowledge of Internet security
• familiarity with Linux (commands, scripting and programming languages [e.g., Perl, Python])
• familiarity with pcap tools (e.g., WireShark)
• familiarity with postgres or other SQL DB
• experience with data analysis (especially large data sets, e.g., Netflow)
• knowledge of snort rules and rule writing
• familiarity with Intrepid (has a new name) or other IDS platform
• experience with Cyber Security analyses and reporting
Intel Agency (NSA, CIA, FBI, etc) - w/ fullscope polygraph
No Traveling
5+ yrs experience
IT - Security
