Job Requirements
Arlington, VA
Top Secret/SCI Polygraph not specified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
We are seeking a Cyber Security Analyst to support the DISA GSMO-II program in the Washington, DC area. This position provides 24x7 cybersecurity monitoring and analysis services for Department of Defense networks above the SECRET level, including real-time cyber threat intelligence analysis, correlation of actionable security events, network traffic analysis using raw packet data, and participation in the coordination of resources during the incident response process.
Qualifications
Bachelor's Degree and 4+ years of prior relevant experience; additional work experience or cyber courses/certifications may be substituted in lieu of a degree
Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, the OSI model, defense-in-depth, and common security elements
Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings
DoD 8570 IAT Level II or higher certification (such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC) prior to starting
DoD 8570 CSSP-A level certification (such as CEH, CySA+, or GCIA) or other qualifying certification required within 180 days of hire
Demonstrated commitment to training, self-study, and maintaining proficiency in the technical cybersecurity domain, with the ability to think and work independently
Strong analytical and troubleshooting skills
Willingness to perform shift work
U.S. Citizenship required
Active DoD TOP SECRET clearance with SCI eligibility required
Preferred Qualifications
CND experience (Protect, Detect, Respond, and Sustain) within a Computer Incident Response organization
Demonstrated understanding of the life cycle of network threats, attacks, attack vectors, and methods of exploitation, with an understanding of intrusion set tactics, techniques, and procedures (TTPs)
Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, the OSI model, defense-in-depth, and common security elements
Experience with development and incorporation of AI and automation tools into incident response processes
Demonstrated hands-on experience analyzing high volumes of logs and network data (e.g., Splunk, Suricata, Zeek, Full Packet Capture) and other attack artifacts in support of incident investigations
In-depth knowledge of the architecture, engineering, and operations of at least one enterprise SIEM platform (e.g., Splunk ES, Elastic)
Experience and proficiency with any of the following: Splunk, Suricata, Zeek, Full Packet Capture, Network Forensics, Endpoint Detection and Response, Corelight, Elastic
Experience with malware analysis concepts and methods
Unix/Linux command line experience
Scripting and/or programming experience to write Suricata and Zeek rule sets
Familiarity or experience with Intelligence Driven Defense, MITRE ATT&CK, and/or the Cyber Kill Chain methodology
Qualifications
Bachelor's Degree and 4+ years of prior relevant experience; additional work experience or cyber courses/certifications may be substituted in lieu of a degree
Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, the OSI model, defense-in-depth, and common security elements
Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings
DoD 8570 IAT Level II or higher certification (such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC) prior to starting
DoD 8570 CSSP-A level certification (such as CEH, CySA+, or GCIA) or other qualifying certification required within 180 days of hire
Demonstrated commitment to training, self-study, and maintaining proficiency in the technical cybersecurity domain, with the ability to think and work independently
Strong analytical and troubleshooting skills
Willingness to perform shift work
U.S. Citizenship required
Active DoD TOP SECRET clearance with SCI eligibility required
Preferred Qualifications
CND experience (Protect, Detect, Respond, and Sustain) within a Computer Incident Response organization
Demonstrated understanding of the life cycle of network threats, attacks, attack vectors, and methods of exploitation, with an understanding of intrusion set tactics, techniques, and procedures (TTPs)
Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, the OSI model, defense-in-depth, and common security elements
Experience with development and incorporation of AI and automation tools into incident response processes
Demonstrated hands-on experience analyzing high volumes of logs and network data (e.g., Splunk, Suricata, Zeek, Full Packet Capture) and other attack artifacts in support of incident investigations
In-depth knowledge of the architecture, engineering, and operations of at least one enterprise SIEM platform (e.g., Splunk ES, Elastic)
Experience and proficiency with any of the following: Splunk, Suricata, Zeek, Full Packet Capture, Network Forensics, Endpoint Detection and Response, Corelight, Elastic
Experience with malware analysis concepts and methods
Unix/Linux command line experience
Scripting and/or programming experience to write Suricata and Zeek rule sets
Familiarity or experience with Intelligence Driven Defense, MITRE ATT&CK, and/or the Cyber Kill Chain methodology
group id: 10471702