Jr Cyber Defense Analyst / Incident Responder IRES - HSV
Amentum · Redstone Arsenal, AL · 1 mo ago
On-siteInformation TechnologyFull-time
Description of Duties
- Perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties outlined in Evaluator Scoring Metrics (ESM).
- Perform cybersecurity duties on customer networks (proactively and reactively) to improve enterprise-wide security posture.
- Perform preliminary analysis, identification, and response actions to detect, characterize, and respond to cyber incidents IAW CJCSM 6510.01B.
- Perform event/incident investigations from start to conclusion, to include gathering data, analysis, and reporting.
- Properly document all steps in the incident response process while taking care to preserve and protect incident artifacts, evidence, and chain of custody.
- Analyze correlated asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture.
- Support the development, establishment, review and update of DCO procedures, processes, manuals, and other documentation.
- Leverage actionable Cyber Threat Intelligence data to search for indicators of compromise and make recommendations for improvements.
- Review data of ongoing intrusions or cybersecurity incidents and report, analyze, and document/report the findings in accordance with CJCSM 6510.01B guidelines.
- Provide support to internal and external Insider threat and law enforcement / counterintelligence (LE/CI) agencies during cyber incidents / investigations.
Basic Requirements
- Must have 6, or more, months of directly related experience in information security, physical security, or cybersecurity, or a combination thereof.
- Must possess one of the following certifications: CC, (ISC)2 CEH, EC Council GFACT, GIAC GISF, CySA+.
- Must have an active DoW Secret Security Clearance.
Desired Requirements
- Have an Associate's degree, or higher, in Cybersecurity, Computer Science or related field.
- Have experience with security analysis and solutions in a WAN/LAN environment to include Routers, Switches, Network Devices, and Operating Systems (e.g., Windows, and Linux).
- Have experience with other Security Operations Centers (SOC)/DCO tools/applications, such as Firewalls, Intrusion Detection Systems / Intrusion Prevention Systems, Network Security Manager, Forward Proxy, Spam Firewall, etc.
- Have experience analyzing security compliance scans performed across a WAN (ACAS/Nessus preferred).
- Have experience analyzing network and host-based threats (ESS preferred).
- Be able to obtain a DoD Top Secret clearance.
- Be familiar with Security Operations Centers (SOC)/DoD.
- Be familiar with DCO/Cybersecurity Service Provider (CSSP)-guiding security policies and procedures.
- Have an active DoW Top Secret clearance.
Compensation Details
$101,000 – $115,000
Benefits Overview
- Health, dental, and vision insurance.
- Paid time off and holidays.
- Retail benefits (including 401(k) matching).
- Retirement benefits.
- Education reimbursement.
- Parental leave.
- Employee stock purchase plan.
- Tax-saving options.
- Disability and life insurance.
- Pet insurance.