Quick Overview
Job Description
TEKsystems is hiring 6 Cyber Intrusion Analysts for a long-term contract. Must have DoD Top-Secret clearance and strong cyber incident handling experience. The Cyber Intrusion Analysts will supporting an enterprise DOD/DISA program. The Cyber Intrusion Analysts will be responsible for performing network incident detection and response activities to detect, correlate, identify and characterize anomalous activity, Monitor various security tools and applications (Splunk and Elastic primarily), conduct near real-time event triage, analyze logs, perform network traffic analysis utilizing raw packet data, net flow, IDS, IPS and custom sensor output, etc.
Required Skills
- 4 years of overall experience, preferably with a bachelor’s degree.
- Must have at least an active Secret clearance, active Top-Secret clearance preferred.
- Prior experience working CND duties, e.g. Protect, Defend, Respond and Sustain, specifically experience configuring firewalls, IDS / IPS, auditing network traffic, hardening devices and implementing security policies.
- Command line scripting experience, specifically with PERL, Python and / or Shell Scripting to automate tasks.
- Monitoring of IDS and computer defense appliances (Splunk, Elastic).
- Experience evaluating packet captures.
- Prior experience supporting DOD related projects or programs.
The Cyber Intrusion Analyst will work closely with Government counterparts to provide guidance within the CND-SP area. Provide CND reports, trends, responses, mitigations, analysis & information dissemination. Provide C2 support, situational awareness support, and provide leadership & support for all CND applicable activities within Protect, Detect, Respond, and Sustain. Work as a technical leader within the CSSP Team, responsible for maintaining the integrity & security of enterprise-wide systems & networks. Provide technical leadership to CND Teams supporting security initiatives through predictive & reactive analysis, and by articulating emerging trends to leadership & staff.
Responsibilities Include
- Perform computer network incident detection, and response activities to detect, correlate, identify and characterize anomalous activity that may be indicative of threats to the enterprise.
- Monitor various security tools and applications for possible malicious activities, investigate any associated alerts or indicators, and develop recommendations for a course of action, including mitigation strategies as necessary.
- Conduct analysis of low-level (“low and slow”) events to identify unauthorized activity utilizing exploratory problem-solving or self-learning techniques.
- Conduct near real-time event triage and analysis, which can result in network traffic validations or a Mission Partner’s incident report.
- Utilize formal monitoring policies and procedures that include the appropriate use of DoD-approved network monitoring and traffic analysis tools to assist with identifying suspicious, anomalous, or overtly malicious network traffic on a 24/7/365 basis.
- Review and analyze available logs in a timely manner to detect intruders and notify Mission Partners of activity through a formal reporting process/pending an incident report.
- Apply, develop, tune, and distribute or optimize new and existing countermeasures or guidance to prevent or mitigate potential cyber event impacts when possible.
- Perform network traffic analysis. -------------
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
- Medical, dental & vision
- Critical Illness, Accident, and Hospital
- 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
- Life Insurance (Voluntary Life & AD&D for the employee and dependents)
- Short and long-term disability
- Health Spending Account (HSA)
- Transportation benefits
- Employee Assistance Program
- Time Off/Leave (PTO, Vacation or Sick Leave)
Similar jobs
- CT
TS / SCI cleared Cyber Real Time Analyst
NewClearBridge Technology Group
HI🇺🇸$56 - $81/hrOn-siteYesterdayELKLogstashDNS+3Technology - LT
Info Security Analyst
NewLedgent Technology
Irvine, CA🇺🇸$50 - $58/hrHybridYesterdayTechnology - TI
Cybersecurity Analyst with Security Clearance
NewThe Informatics Applications Group
Arlington, VA🇺🇸On-siteYesterdayAWSTechnology - GO
Cyber Security Analyst SME
NewGovCIO
United States🇺🇸$143.2k - $160k/yrOn-siteYesterdayEncryptionTechnology - TT
SOC Analyst
NewTandym Tech
Kenneth City, FL🇺🇸HybridYesterdayELKTechnology - RH
Cyber Security Engineer
NewRobert Half
Brookfield, WI🇺🇸HybridYesterdaySplunkTechnology