Cyber Network Forensic Analyst III (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cyber Network Forensic Analyst III (Cybersecurity): Providing onsite incident response and network investigations for U.S. Government agencies with an accent on characterizing breaches and developing mitigation plans. Focus on analyzing anomalous network activity, collecting intrusion artifacts, and reconstructing malicious attacks using network traffic.
Location: Sterling, VA / Arlington, VA. Must be a U.S. Citizen with an active TS/SCI clearance
Company
provides technically advanced full-spectrum cyber, data operations, and intelligence mission support services to government and commercial markets.
What you will do
- Lead preliminary incident response investigations and interface with customers onsite.
- Analyze anomalous network activity to determine exploitation methods and effects on systems.
- Collect and analyze network intrusion artifacts including PCAP, domains, and certificates.
- Assess network topology and device configurations to identify security concerns.
- Handle real-time CND incidents, including forensic collections and threat analysis.
- Write and publish Computer Network Defense guidance and incident findings reports.
Requirements
- U.S. Citizenship and an active TS/SCI clearance are mandatory.
- Ability to obtain DHS Suitability.
- 8+ years of experience in network investigations.
- In-depth knowledge of TCP/IP, standard protocols (HTTP/S, DNS, SSH, etc.), and Wifi networking.
- Expertise in network topologies (DMZ, WAN) and SIEM tools like Splunk.
- Strong understanding of MITRE ATT&CK and defense-in-depth principles.
Nice to have
- Proficiency with Wireshark and PCAP data extraction.
- Experience with non-traditional network traffic (C2) and virtualized environments.
- Certifications: GCIA, GCIH, CEH, or SANS GIAC GNFA.
Culture & Benefits
- Opportunity to work on critical national security missions.
- Collaborative environment with a team of passionate experts.
- Focus on innovation and solving complex cybersecurity challenges.
- Equal Opportunity/Affirmative Action employer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →