user avatar

Cyber Threat Emulation Analyst

Blackstone Talent Group

Today
Secret
58
Unspecified
IT - Security
schriever sfb, CO (On-Site/Office)

Blackstone Talent Group, an award-winning technology consulting and talent agency, is seeking a Mid-Level Cyber Threat Emulation Analyst to join our Client's team.

Description of Duties:

The Mid-Level Cyber Threat Emulation Analyst supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. This position can be located in Colorado Springs or Huntsville.

The candidate will:
  • Perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties outlined in Evaluator Scoring Metrics (ESM).
  • Perform cybersecurity duties on customer networks (proactively and reactively) to improve enterprise-wide security posture.
  • Analyze correlated assets, threats, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture.
  • Support the development, establishment, review, and update of DCO procedures, processes, manuals, and other documentation.
  • Measures the effectiveness of the defense-in-depth architecture against known vulnerabilities.
  • Generate vulnerability assessment reports for customers and escalate for further review.
  • Support Incident Response across the enterprise IAW DoD regulations and instructions.
  • Lead cyber events and incident investigations from start to conclusion, to include gathering data, analysis, and reporting.
  • Assist in developing an Exploitation Analyst training plan by instructing, evaluating, and mentoring junior, mid, and senior analysts.
  • Receive, review, and implement directed Higher Headquarters Tasking Orders (HHQ) and/or Fragmentary Orders weekly.
  • Perform Cyber Threat Emulation (CTE) actions with the Automated Security Validation toolset as directed by HHQ
  • Execute CTE actions within the approved network zones with the specific adversary tactics, techniques, and procedures (TTPs) documented in each engagement to assess toolset detection and alerting.
  • Create custom dashboards and reports to communicate post-engagement analysis of each CTE engagement, including identified vulnerabilities, recommended remediation steps, assessment of the system's security posture, and incident response to the government within a specified amount of time after completion of engagement.
  • Draft and submit Cyber Tasking Orders (CTOs) to remediate issues found in the report findings during CTE actions.
  • Collaborate with the Cyberspace Domain Awareness (CDA) to develop evaluation criteria and methodologies aligned with HHQ inspection requirements and industry best practices.

Basic Requirements:
  • Must have 6 or more years of general (full-time) work experience
  • Must have 4 years of combined experience with:
    • Performing manual or automated penetration test in an enterprise environment
    • Practical experience with vulnerability assessment, cybersecurity frameworks, or conducting risk assessments
    • Experience performing the full life cycle of incident response and enterprise-level monitoring
  • Must have 1 year of experience in management or leadership in a team environment
  • Must have a current DoD 8570.01-M IAT Level II certification with Continuing Education (CE) - (CySA+, GICSP, GSEC, Security+ CE, SSCP)
  • Must have, or obtain within 6 months of start date, a PenTest+ certification
  • Must have an active DoD Secret Security Clearance

Desired Requirements:
  • Have a Bachelor's degree, or higher, in Cybersecurity, Computer Science, or a related field
  • Have experience with Cyber Threat Emulation tools, policies, and procedures
  • Have experience operating custom software on top of a Linux platform
  • Have experience with security analysis and solutions in a WAN/LAN environment to include Routers, Switches, Network Devices, and Operating Systems (e.g., Windows, and Linux)
  • Have experience with other Security Operations Centers (SOC)/DCO tools/applications, such as Firewalls, Intrusion Detection Systems / Intrusion Prevention Systems, Network Security Manager, Bluecoat, Barracuda, etc.
  • Have experience performing security compliance scans across a WAN (ACAS/Nessus preferred)
  • Have a background in configuration, troubleshooting, and deployment of host-based security (ESS preferred)
  • Be able to mentor and train personnel in an evolving, high-paced environment
  • Be familiar with DoD Security Operations Centers (SOC) (aka CSSP)
  • Be familiar with DCO/Cybersecurity Service Provider (CSSP)-guiding security policies and procedures
  • Have an active DoD Top Secret clearance

Security Clearance Required: Secret

Blackstone Talent Group is a wholly owned subsidiary of Blackstone Technology Group, a global IT services and software firm that implements technological solutions across commercial industry verticals and the US Federal Government. Blackstone's global talent augmentation practice was founded in 1998. Blackstone Talent Group has offices in San Francisco, Denver, Houston, Colorado Springs, and Washington, DC. We specialize in providing clients the best talent across a variety of industries and sectors.

EOE of Minorities/Females/Veterans/Disabilities

Pay Range: $58/hr - $65/hr
group id: bstone
job ad image
Find Blackstone Talent Group on Social Media
Network Employers
user avatar
About Us
Blackstone Talent Group is a division of Blackstone Technology Group with offices in DC, Denver, Colorado Springs and San Francisco. We specialize in providing clients with the best talent in the industry and serve commercial, government and non-profit clients across the US. Blackstone Government Services specializes in building high-performing IT teams for federal civilian, DoD and intel agencies.
job ad2 image

Blackstone Talent Group Jobs


Job Category
IT - Security
Clearance Level
Secret