Cyber Hunt Analyst
Synergy ECP · Columbia, SC · 1 mo ago
EngineeringFull-time
About the role
Synergy ECP is a Service-Disabled Veteran-Owned Small Business (SD(VOSB)) that provides a broad range of services to the defense, intelligence, and health care industries. We thrive by adhering to our mission to display excellence in employees, customers, and performance.
Responsibilities
- Discover and characterize network and platform anomalies, including cross-domain violations, and submit findings to the Reporting Team Lead for analysis and report generation.
- Maintain vigilance over network activities, identifying and analyzing anomalous activities on various networks.
- Conduct multi-source threat analyses to examine host behaviors and network traffic for high-priority malicious attacks, anomalous traffic, or other incidents of interest, and generate reports as necessary.
- Integrate Cyber Threat Intelligence to inform customers about newly discovered threats and vulnerabilities associated with the technologies used in the enterprise, and develop hunt analytics.
- Monitor adversarial capabilities, exploits, vulnerabilities, mitigation techniques, and best practices information and guidance through all-source research.
- Identify areas for deeper dive analysis of threat and vulnerabilities, and examine network topologies to understand data flows through networks and provide mechanisms to tip countermeasures.
- Implement the applicable reporting guidelines outlined in applicable directives and guidance, conduct research/planning for strategy development in response to real-time operational requirements, and identify and document gaps in all data affecting the customer mission.
- Develop, document, and synchronize the recommendations and tasking of signature and rule sets across all sensors used by the customer, such as IDS, FW, etc.
- Conduct research and planning for strategy development in response to real-time operational requirements, and identify and document gaps in all data affecting the customer mission.
- Support external investigations, handle and escalate security issues or emergencies appropriately, and provide incident response capabilities to isolate and mitigate threats to maintain confidentiality, integrity, and availability for protected data.
- Support the development of malware analysis, reverse engineering, and incident investigations, and demonstrate strong comfort with IPv4, TCP/IP, and RFC data, low-level networking and protocols, TCP/UDP ports for apps, and understanding of what is normal/abnormal endpoint and on-wire activity.
- Support the development of malware analysis, reverse engineering, and incident investigations, and demonstrate strong comfort with IPv4, TCP/IP, and RFC data, low-level networking and protocols, TCP/UDP ports for apps, and understanding of what is normal/abnormal endpoint and on-wire activity.
Qualifications
- U.S. Citizenship
- Clearance Required: TS/SCI
Skills
- Tier III Analyst experience
- Network Analytics
- Incident Investigations
- Reverse Engineering and Malware Analysis
- Task Prioritization
- Strong comfort level with IPv4, TCP/IP, and RFC data, low level networking and protocols, TCP/UDP ports for apps, and understanding of what is normal/abnormal endpoint and on-wire activity
- Experience with Red Team and/or Penetration Testing
- Experience with scripting (PowerShell, Python, Java)
- Experience with Cloud Environment using cloud analytics and PIG scripts/jobs to present data and using the Hadoop Distributed File System
- Experience with SIEMs or scripting to pull data into usable formats
- Experience with Wireless and SCADA
Benefits
- Equal Opportunity Employer