Jobs · Information Technology · Alabama

Jr Cyber Defense Analyst / Incident Responder IRES - HSV

Amentum · Redstone Arsenal, AL · 1 mo ago
On-siteInformation TechnologyFull-time

Description of Duties

  • Perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties outlined in Evaluator Scoring Metrics (ESM).
  • Perform cybersecurity duties on customer networks (proactively and reactively) to improve enterprise-wide security posture.
  • Perform preliminary analysis, identification, and response actions to detect, characterize, and respond to cyber incidents IAW CJCSM 6510.01B.
  • Perform event/incident investigations from start to conclusion, to include gathering data, analysis, and reporting.
  • Properly document all steps in the incident response process while taking care to preserve and protect incident artifacts, evidence, and chain of custody.
  • Analyze correlated asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture.
  • Support the development, establishment, review and update of DCO procedures, processes, manuals, and other documentation.
  • Leverage actionable Cyber Threat Intelligence data to search for indicators of compromise and make recommendations for improvements.
  • Review data of ongoing intrusions or cybersecurity incidents and report, analyze, and document/report the findings in accordance with CJCSM 6510.01B guidelines.
  • Provide support to internal and external Insider threat and law enforcement / counterintelligence (LE/CI) agencies during cyber incidents / investigations.

Basic Requirements

  • Must have 6, or more, months of directly related experience in information security, physical security, or cybersecurity, or a combination thereof.
  • Must possess one of the following certifications: CC, (ISC)2 CEH, EC Council GFACT, GIAC GISF, CySA+.
  • Must have an active DoW Secret Security Clearance.

Desired Requirements

  • Have an Associate's degree, or higher, in Cybersecurity, Computer Science or related field.
  • Have experience with security analysis and solutions in a WAN/LAN environment to include Routers, Switches, Network Devices, and Operating Systems (e.g., Windows, and Linux).
  • Have experience with other Security Operations Centers (SOC)/DCO tools/applications, such as Firewalls, Intrusion Detection Systems / Intrusion Prevention Systems, Network Security Manager, Forward Proxy, Spam Firewall, etc.
  • Have experience analyzing security compliance scans performed across a WAN (ACAS/Nessus preferred).
  • Have experience analyzing network and host-based threats (ESS preferred).
  • Be able to obtain a DoD Top Secret clearance.
  • Be familiar with Security Operations Centers (SOC)/DoD.
  • Be familiar with DCO/Cybersecurity Service Provider (CSSP)-guiding security policies and procedures.
  • Have an active DoW Top Secret clearance.

Compensation Details

$101,000 – $115,000

Benefits Overview

  • Health, dental, and vision insurance.
  • Paid time off and holidays.
  • Retail benefits (including 401(k) matching).
  • Retirement benefits.
  • Education reimbursement.
  • Parental leave.
  • Employee stock purchase plan.
  • Tax-saving options.
  • Disability and life insurance.
  • Pet insurance.

Similar jobs