user avatar

Analyst Cyber Security

Premier Technical Services Corp

Posted today

Job Requirements

San Antonio, TX
Top Secret/SCI Polygraph not specified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries

Job Description

We are targeting a candidate who:

Has stable job history (not a job hopper)
Possess relevant network defense experience
Is willing to work 7a-7p/day & 7p-7a/night shifts on a Panama schedule (for example, a 4-3 schedule which is every Sun, Mon, Tue & every-other Wed; or the inverse of that); potential rotations occur every ~3-months
Holds a DoD 8570 IAT-II certification at time of hire
Ideally, they also hold a CSSP-Analyst certification, though we can allow up to 6 months post-hire to obtain it

Additional Requirements:

Must hold a current TS/SCI clearance (not just TS, SCI eligibility is required)
Must be eligible for customer SAP read-ons, which is a separate customer-driven process post-hire. In our 7.5 years of operation, none of our employees have been denied.

Primary Responsibilities

Identify and offer solutions to gaps in capabilities and visibility
Promote and drive research and implementation of automation and process efficiencies
Intermediate command line experience that includes chaining Linux utilities such as tcpdump, sed, awk, and grep together
Intermediate IDS (Snort, Bro/Zeek, etc.) creation and tuning, to include performing impact analysis on customer environments and review and correction of Tier I rules
Analysis of alerts plus surrounding network traffic to provide remediation context
Ability to consume open and closed source and search indicators in customer data, then generate new IDS configurations for future detection
Basic hunt experience that includes sifting non-alert-based traffic and deriving meaningful results in the absence of corresponding OSINT
Vulnerability awareness and able to determine applicability to customer environments, using data to establish attack attempts and success/failure
Maintaining current threat awareness
Ability to analyze complex (multipacket, multi-vector, multi-exploit, large volume) traffic and derive meaningful conclusions
Self-directed research, development, customization, or other contributions to process improvement
Continual enrichment of IDS and moderate ability to tune on the fly
Ability to self-educate with non-comprehensive or incomplete documentation on new concepts, protocols, and data formats
Basic Qualifications:

Hands-on cybersecurity network defense experience (Detect and Respond) within a Computer Incident Response organization. Hands-on experience with a Security Information and Event Management tool (ArcSight, Security Onion, etc.)
Fluent in computer network Packet Capture (PCAP) analysis
DoD 8570 IAT-II and CSSP-Analyst certifications required prior to starting
Demonstrated advanced knowledge of industry accepted standards.
Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic finding.
Strong analytical and troubleshooting skills.
Must be a US Citizen
Candidate must possess an active TS/SCI and be approved customer SAP read-ons
Bachelor of Science degree and 4-8 years of prior IT experience.
3+ years’ experience working in a SOC environment

Preferred Qualifications:

Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.
Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and MITRE ATT&CK framework.
group id: 10115149
N
Name HiddenSenior Vice President