Clearance Required: Secret
Position Description: The Cyber Hunt and Threat Analysis team is seeking a motivated individual with strong technical competency that will research and implement detection measures using data from a wide spectrum of sources. The candidate will also perform opportunistic threat hunting and forensic analysis when required during incidents.
Qualifications:
· Minimum 3-5 years of comparable experience performing Incident Response, Forensics, Malware Analysis, or Penetration Testing
· 5-7 years of experience if no degree
· Must be proficient in at least three of the following disciplines:
o Network traffic analysis and host based log analysis
o Comprehensive understanding of enterprise Windows security (Active Directory)
o Static and Dynamic malware analysis
o Disk and Memory forensics
o Practical knowledge in at least one scripting or development language (e.g. PowerShell or Python)
Recommended Education:
· Bachelor’s degree or higher from accredited university/technical college in Cybersecurity, Computer Science, Information Systems, or other related scientific or technical discipline
Certifications:
· 8570 Classification IAT –II & CSSP Certification (Can Attain within 90 Days)
Required Skills:
· Strong written and verbal communication skills
· Strong understanding of common enterprise technologies
· Ability to convey extremely technical concepts to audiences with varying technical understanding
Responsibilities:
· Use Network and Host Based data to drive detection, monitoring, and response capabilities
· Create detection analytics based off the MITRE ATT&CK Framework and other security frameworks
· Perform unique research on adversarial Tools, Techniques, and Procedures (TTPs)
· Provide assistance to the Network Security Monitoring team in response to incidents by analyzing host behavior and network traffic
· Perform static and dynamic malware analysis to feed Indicators of Compromise into the Incident Response process
Additional Information:
· Authorized to update signatures and view alerts of IDS/ IPS
· Authorized to view audit records on Central Log Server
· Authorized to modify auditable events on Central Log Server