Job Requirements
Arlington, VA
Top Secret/SCI Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Job Title: Cyber Network Defense Analyst
Location: Arlington, VA (On-Site)
Clearance: Active TS/SCI Required
Company: Quantum Science Solutions (QSS)
Compensation: Open Rate
Position Overview
Quantum Science Solutions (QSS) is seeking a Cyber Network Defense Analyst (CNDA) to
support a critical customer mission providing remote and onsite advanced technical
assistance, proactive hunting, rapid onsite incident response, and immediate investigation
and resolution using host-based, network-based, and cloud-based cybersecurity analysis
capabilities.
The Cyber Network Defense Analyst will use information collected from a variety of sources
to monitor and analyze network activity for evidence of suspicious behavior. The CNDA will
identify and report cyber events, analyze network environments for trends, patterns, and
anomalies, and recommend proactive measures to contain incidents and protect
information systems and networks from threats.
Key Responsibilities
• Characterize and analyze network traffic to identify anomalous activity and potential
threats to network resources
• Coordinate with enterprise-wide cyber defense staff to validate network alerts
• Document and escalate incidents (including event's history, status, and potential
impact for further action) that may cause ongoing and immediate impact to the
environment
• Perform cyber defense trend analysis and reporting
• Perform event correlation using information gathered from a variety of sources
within the enterprise to gain situational awareness and determine the effectiveness
of an observed attack
• Provide daily summary reports of network events and activity relevant to cyber
defense practices
• Receive and analyze network alerts from various sources within the enterprise and
determine possible causes of alerts
• Provide timely detection, identification, and alerting of possible attacks/intrusions,
anomalous activities, and misuse activities and distinguish these incidents and
events from benign activities
• Use cyber defense tools for continual monitoring and analysis of system activity to
identify malicious activity
• Analyze identified malicious activity to determine weaknesses exploited,
exploitation methods, effects on system and information
• Determine tactics, techniques, and procedures (TTPs) for intrusion sets
• Examine network topologies to understand data flows through the network
• Identify and analyze anomalies in network traffic using metadata
• Conduct research, analysis, and correlation across a wide variety of all source data
sets (indications and warnings)
• Validate intrusion detection system (IDS) alerts against network traffic using packet
analysis tools
• Identify applications and operating systems of a network device based on network
traffic
• Reconstruct a malicious attack or activity based off network traffic
• Identify network mapping and operating system (OS) fingerprinting activities
• Assist in the construction of signatures which can be implemented on cyber
defense network tools in response to new or observed threats within the network
environment or enclave
• Notify designated managers, cyber incident responders, and cybersecurity service
provider team members of suspected cyber incidents and articulate the event's
history, status, and potential impact for further action in accordance with the
organization's cyber incident response plan
• Prepare and update manuals, instructions, and operating procedures
• Evaluate established methods and procedures and prepare recommendations for
changes in methods and practices where appropriate
• Plan and carry out difficult and complex assignments and develop new methods,
approaches, and procedures
• Conduct analyses and recommend resolution of complex issues affecting the
specialty area
• Ensure optimal use of commercially available products
• Prepare and present reports
• valuate the effectiveness of installed systems and services.
Mandatory Skills
• U.S. Citizenship.
• Active Secret clearance.
• Ability to obtain DHS Suitability.
• 5+ years of directly relevant experience in cyber defense analysis using leading
edge technologies and industry-standard cyber defense tools.
• Experience successfully developing and deploying signatures.
• Experience detecting host- and network-based intrusions using intrusion detection
technologies such as Snort.
• Experience implementing incident handling methodologies.
• Experience implementing protocol analyzers.
• Experience collecting data from a variety of cyber defense resources.
• Experience reading and interpreting signatures, such as Snort signatures.
• Experience performing packet-level analysis.
• Experience conducting trend analysis.
Preferred Skills
• GSEC (SANS401).
• ArcSight or other SIEM solution experience.
• Python programming experience.
• Strong math and science background.
• Experience with the Carnegie Mellon SiLK tool suite.
Education
• Bachelor's degree in Computer Science, Cyber Security, Computer Engineering, or a
related field; or
• High School Diploma with 7–9 years of network investigations experience.
Desired Certifications
• GNFA, GCIH, GCIA, GSEC, CASP+, CySA+, PaLMS, and FedVTE
Why QSS?
At QSS, you'll support critical customer mission by applying advanced cyber defense
analysis capabilities to detect suspicious activity, investigate network threats, support
incident response, and help protect critical information systems and networks.
Benefits Include:
• Competitive compensation with annual performance bonuses
• Premium Medical, Dental, & Vision coverage
• Generous PTO plus Federal Holidays
• 401(k) with company match
• Professional development and certification support
Location: Arlington, VA (On-Site)
Clearance: Active TS/SCI Required
Company: Quantum Science Solutions (QSS)
Compensation: Open Rate
Position Overview
Quantum Science Solutions (QSS) is seeking a Cyber Network Defense Analyst (CNDA) to
support a critical customer mission providing remote and onsite advanced technical
assistance, proactive hunting, rapid onsite incident response, and immediate investigation
and resolution using host-based, network-based, and cloud-based cybersecurity analysis
capabilities.
The Cyber Network Defense Analyst will use information collected from a variety of sources
to monitor and analyze network activity for evidence of suspicious behavior. The CNDA will
identify and report cyber events, analyze network environments for trends, patterns, and
anomalies, and recommend proactive measures to contain incidents and protect
information systems and networks from threats.
Key Responsibilities
• Characterize and analyze network traffic to identify anomalous activity and potential
threats to network resources
• Coordinate with enterprise-wide cyber defense staff to validate network alerts
• Document and escalate incidents (including event's history, status, and potential
impact for further action) that may cause ongoing and immediate impact to the
environment
• Perform cyber defense trend analysis and reporting
• Perform event correlation using information gathered from a variety of sources
within the enterprise to gain situational awareness and determine the effectiveness
of an observed attack
• Provide daily summary reports of network events and activity relevant to cyber
defense practices
• Receive and analyze network alerts from various sources within the enterprise and
determine possible causes of alerts
• Provide timely detection, identification, and alerting of possible attacks/intrusions,
anomalous activities, and misuse activities and distinguish these incidents and
events from benign activities
• Use cyber defense tools for continual monitoring and analysis of system activity to
identify malicious activity
• Analyze identified malicious activity to determine weaknesses exploited,
exploitation methods, effects on system and information
• Determine tactics, techniques, and procedures (TTPs) for intrusion sets
• Examine network topologies to understand data flows through the network
• Identify and analyze anomalies in network traffic using metadata
• Conduct research, analysis, and correlation across a wide variety of all source data
sets (indications and warnings)
• Validate intrusion detection system (IDS) alerts against network traffic using packet
analysis tools
• Identify applications and operating systems of a network device based on network
traffic
• Reconstruct a malicious attack or activity based off network traffic
• Identify network mapping and operating system (OS) fingerprinting activities
• Assist in the construction of signatures which can be implemented on cyber
defense network tools in response to new or observed threats within the network
environment or enclave
• Notify designated managers, cyber incident responders, and cybersecurity service
provider team members of suspected cyber incidents and articulate the event's
history, status, and potential impact for further action in accordance with the
organization's cyber incident response plan
• Prepare and update manuals, instructions, and operating procedures
• Evaluate established methods and procedures and prepare recommendations for
changes in methods and practices where appropriate
• Plan and carry out difficult and complex assignments and develop new methods,
approaches, and procedures
• Conduct analyses and recommend resolution of complex issues affecting the
specialty area
• Ensure optimal use of commercially available products
• Prepare and present reports
• valuate the effectiveness of installed systems and services.
Mandatory Skills
• U.S. Citizenship.
• Active Secret clearance.
• Ability to obtain DHS Suitability.
• 5+ years of directly relevant experience in cyber defense analysis using leading
edge technologies and industry-standard cyber defense tools.
• Experience successfully developing and deploying signatures.
• Experience detecting host- and network-based intrusions using intrusion detection
technologies such as Snort.
• Experience implementing incident handling methodologies.
• Experience implementing protocol analyzers.
• Experience collecting data from a variety of cyber defense resources.
• Experience reading and interpreting signatures, such as Snort signatures.
• Experience performing packet-level analysis.
• Experience conducting trend analysis.
Preferred Skills
• GSEC (SANS401).
• ArcSight or other SIEM solution experience.
• Python programming experience.
• Strong math and science background.
• Experience with the Carnegie Mellon SiLK tool suite.
Education
• Bachelor's degree in Computer Science, Cyber Security, Computer Engineering, or a
related field; or
• High School Diploma with 7–9 years of network investigations experience.
Desired Certifications
• GNFA, GCIH, GCIA, GSEC, CASP+, CySA+, PaLMS, and FedVTE
Why QSS?
At QSS, you'll support critical customer mission by applying advanced cyber defense
analysis capabilities to detect suspicious activity, investigate network threats, support
incident response, and help protect critical information systems and networks.
Benefits Include:
• Competitive compensation with annual performance bonuses
• Premium Medical, Dental, & Vision coverage
• Generous PTO plus Federal Holidays
• 401(k) with company match
• Professional development and certification support
group id: 91142086