Network Based Systems Analyst

PassionHR Inc

  • Arlington, VA
  • Permanent
  • Full-time
  • 22 days ago
  • Apply easily
NETWORK BASED SYSTEMS ANALYSTWe are seeking to hire an experienced Cyber Network Defense Analysts (CNDA) to support this critical customer mission in Arlington, Virginia. The CDNA uses information collected from a variety of sources to monitor network activity and analyze it for evidence of suspicious behavior. Monitoring and analysis are performed to identify and report events that occur, or might occur, within the network, in order to protect information, information systems, and networks from threats.RESPONSIBILITIESAssists the Government lead in coordinating teams in preliminary incident response investigationsAssists the Government lead with interfacing with the customer while on siteDetermines appropriate courses of actions in response to identified and analyses anomalous network activityAssesses network topology and device configurations identifying critical security concerns and providing security best practice recommendationsCollects network intrusion artifacts (e.g., PCAP, domains, URI's, certificates, etc.) and uses discovered data to enable mitigation of potential Computer Network Defense incidentsAnalyzes identified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and informationCollects network device integrity data and analyzes for signs of tampering or compromiseAssists with real-time CND incident handling (i.e., forensic collections, intrusion correlation and tracking, threat analysis, and advising on system remediation) tasks to support onsite engagementsREQUIREMENTSUS CitizenshipMust have an active TS/SCI clearanceMust be able to obtain DHS Suitability5+ years of directly relevant experience in network investigationsIn depth knowledge of CND policies, procedures and regulationsIn depth knowledge of TCP/IP protocolsIn depth knowledge of standard protocols ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.In depth knowledge and experience of Wifi networkingIn depth knowledge and experience of network topologies DMZ's, WAN's, etc.Substantial knowledge of Splunk (or other SIEM's)Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)Knowledge of Computer Network Defense policies, procedures, and regulationsKnowledge of defense-in-depth principles and general attack stages with respect to network security architectureAbility to characterize and analyze network traffic to identify anomalous activity and potential threats to network resourcesAbility to identify and analyze anomalies in network traffic using metadataExperience with reconstructing a malicious attack or activity based on network trafficExperience examining network topologies to understand data flows through the networkMust be able to work collaboratively across physical locationsEDUCATIONBS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 7-9 years of network investigations experience.DESIREDSubstantial knowledge of network device integrity concepts and methodologiesProficiency with network analysis software (e.g. Wireshark)Proficiency with carving and extracting information from PCAP dataProficiency with non-traditional network traffic (e.g. Command and Control)Proficiency with preserving evidence integrity according to standard operating procedures or national standardsProficiency with virtualized environmentsCERTIFICATIONSDoD 8140.01 IAT Level II, IASAE II, CSSP Analyst, GCIA, GCIH, CSSP Analyst/CSSP Incident Responder, CEHSANS GIAC GNFA preferred

PassionHR Inc