Cyber Network Forensic Analyst II (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cyber Network Forensic Analyst II (Cybersecurity): Providing onsite incident response and network forensic investigations for US Government agencies with an accent on breach characterization and mitigation planning. Focus on analyzing anomalous network traffic, reconstructing attacks from PCAP data, and identifying exploited weaknesses.
Location: Onsite in Sterling, VA or Arlington, VA
Company
provides advanced cyber, data operations, and intelligence mission support services to the defense and intelligence communities.
What you will do
- Coordinate preliminary incident response investigations and interface with government customers onsite.
- Analyze anomalous network activity to determine appropriate courses of action and mitigation strategies.
- Collect and analyze network intrusion artifacts such as PCAP, domains, and certificates to enable mitigation.
- Assess network topology and device configurations to identify security concerns and provide best-practice recommendations.
- Analyze malicious network activity to determine exploited weaknesses, methods, and effects on information.
- Perform real-time CND incident handling, including forensic collections and threat analysis.
Requirements
- U.S. Citizenship and active TS/SCI clearance.
- Ability to obtain DHS Suitability.
- 5+ years of directly relevant experience in network investigations.
- In-depth knowledge of TCP/IP, standard protocols (HTTP/S, DNS, SSH, SMTP, SMB, NFS), and Wifi networking.
- Substantial knowledge of Splunk (or other SIEMs) and understanding of MITRE ATT&CK.
- BS in Computer Science, Cyber Security, Computer Engineering, or related degree (or 7-9 years of experience with HS Diploma).
Nice to have
- Proficiency with Wireshark and extracting information from PCAP data.
- Experience with non-traditional network traffic, such as Command and Control (C2).
- Relevant certifications: DoD 8140.01 IAT Level II, GCIA, GCIH, or SANS GIAC GNFA.
- Proficiency with virtualized environments and designing security in Linux and/or Windows.
Culture & Benefits
- Collaborative team environment focused on innovation and solving complex problems.
- Opportunity to work on critical national security missions for high-profile government agencies.
- Engagement with talented professionals passionate about cybersecurity and intelligence.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →