Critical Infrastructure Cyber Protection & Defense Analyst
About the role
Deliver professional advice, expertise, strategic insight, and other cyber-related consulting services to advance industrial control systems (ICS) cybersecurity for critical infrastructure. Provide advice and expertise in cybersecurity designs, implementation, vulnerability identification, and mitigation techniques and procedures that will aid industry and the Nation in securing critical infrastructure systems against current and emerging threats.
Monitor critical infrastructure sector networks to actively remediate unauthorized activities. Respond to crises or urgent situations within critical infrastructure sectors to mitigate immediate and potential threats. Develop, research, and apply advanced mitigation, preparedness, response, and recovery approaches to maximize survival of life, preservation of property, and information security.
Lead cyber security efforts and deliver capability to customers. Promote an open and informal communication environment with both internal and external stakeholders at all levels to develop mutual trust and teamwork. Conduct information collection and analysis of United States critical infrastructure with particular emphasis on control systems and technology-controlled processes. Manage teams in the creation of cyber security products, create related reports, and provide briefings on these issues.
Conduct technical analysis projects to fill gaps in current situational awareness across sectors and develop products addressing the needs of a diverse customer set spanning multiple classification levels, federal, private, and international organizations.
Other duties as assigned.
Responsibilities
- Deliver cybersecurity consulting services for industrial control systems (ICS) in critical infrastructure.
- Provide expertise in cybersecurity designs, vulnerability identification, and mitigation techniques.
- Monitor and remediate unauthorized activities on critical infrastructure sector networks.
- Respond to crises or urgent situations to mitigate threats to critical infrastructure.
- Develop and apply advanced mitigation, preparedness, response, and recovery approaches.
- Lead cybersecurity efforts and deliver capabilities to customers.
- Promote open communication with stakeholders to build trust and teamwork.
- Conduct information collection and analysis of U.S. critical infrastructure, focusing on control systems.
- Manage teams in creating cybersecurity products, reports, and briefings.
- Conduct technical analysis projects to address situational awareness gaps.
- Develop products for diverse customers across multiple classification levels and organizations.
Requirements
- Bachelor of Science degree in mechanical or electrical engineering, cyber security/computer sciences, and/or business/financial management from an accredited institution.
- Relevant experience commensurate with level:
- EX3: Bachelor’s and 5 years, Master’s and 2 years, PhD and 2 years.
- EX4: Bachelor’s and 9 years, Master’s and 6 years, PhD and 4 years.
- Experience designing or applying control systems cybersecurity solutions in critical infrastructure at the system and/or regional level.
- Obtain and maintain a Q security clearance and special access as required.
- Ability to work in a secure environment handling classified and CUI information, adhering to physical and electronic protection standards.
- Must be a U.S. citizen.
- Must be eligible for a DOE Q clearance (equivalent to Top Secret) and SCI access.
- Ability to work under pressure, manage multiple complex tasks, and maintain quality and professionalism.
Skills
- Expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization.
- Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework.
- Hands-on experience with the Splunk Monitoring Console for monitoring and maintaining a distributed Splunk ecosystem.
- Experience with data transformation using props and transforms configurations and Splunk regular expressions.
- Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections.
- Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment.
- Strong understanding of the MITRE ATT&CK framework and detection engineering methodology.
- Experience with detection-as-code practices and tools (Git, CI/CD pipelines).
- Proficiency in Python for data processing and model development.
- Knowledge of SOAR platforms and detection automation.
- Relevant certifications (e.g., Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC).
Preferred Qualifications
- Professional Engineer and/or Certified Information Systems Security Professional (CISSP) certifications.
- Program/project management experience at INL, particularly in cybersecurity.
- Familiarity with industrial control systems.
- In-depth knowledge of the U.S. energy sector and experience working with DOE, DOD, DHS, and private industry on grid security-related projects.
Physical Requirements
- Frequently required to stand, walk, sit, stoop, kneel, bend, use hands to handle materials, manipulate tools, keyboard, and type.
- Occasionally lift and/or move up to 30 pounds.
- Sufficient visual acuity and hearing capacity to perform essential functions and interact with people.
- Reasonable accommodations may be made for individuals with disabilities.
Pay
Level #3: $95,256 - $195,288
Level #4: $114,360 - $234,366
Compensation decisions are based on education, relevant experience, and other credentials.
Benefits
- Medical, Dental, Vision, and Flexible Spending Accounts.
- 401(k) with a 4.2% employer contribution and up to 4.8% match (regular positions) or self-contribute access (postdoctoral positions).
- Paid time off (personal leave).
- Employee Education Program (tuition assistance for eligible positions).
- Comprehensive Relocation Package.
Benefit eligibility is subject to multiple factors, including employment status and position classification.