Mid-Level Cyber Defense Analyst / Incident Responder IRES - HSV
Amentum · Redstone Arsenal, AL · 1 mo ago
On-siteInformation TechnologyFull-time
About the role
The Mid-Level Cyber Defense Analyst / Incident Responder supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract.
Responsibilities
- Perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties outlined in Evaluator Scoring Metrics (ESM).
- Perform cybersecurity duties on customer networks (proactively and reactively) to improve enterprise-wide security posture.
- Perform preliminary analysis, identification, and response actions to detect, characterize, and respond to cyber incidents IAW CJCSM 6510.01B.
- Lead event/incident investigations from start to conclusion, to include gathering data, analysis, and reporting.
- Properly document all steps in the incident response process while taking care to preserve and protect incident artifacts, evidence, and chain of custody.
- Analyze correlated asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture.
- Support a Cyber Defense Analyst and Cyber Defense Incident Responder training plan by instructing, evaluating, and mentoring Junior Cyber Defense Analyst and Cyber Defense Incident Responders.
- Support the development, establishment, review and update of DCO procedures, processes, manuals, and other documentation.
- Leverage actionable Cyber Threat Intelligence data to search for indicators of compromise and develop SIEM content/signatures to detect known attack patterns and make recommendations for improvements.
- Carefully coordinate with CSSP-CERT subscribers to develop current configurations, rules, and signatures for cyber security related toolsets.
- Carefully coordinate with CSSP-CERT subscribers to notify, investigate, and remediate discrepancies in security logging and CSSP-CERT alignment.
- Provide standardized and targeted training in support of CSSP-CERT subscriber cyber defense and incident response programs.
- Review data of ongoing intrusions or cybersecurity incidents and report, analyze, and document/report the findings in accordance with CJCSM 6510.01B guidelines.
- Provide support to internal and external Insider threat and law enforcement / counterintelligence (LE/CI) agencies during cyber incidents / investigations.
Requirements
- Must have 4, or more, years of general (full-time) work experience.
- May be reduced with completion of advanced education.
- Must have 4 years of directly related experience in information security, physical security, or cybersecurity, or a combination thereof.
- Must have 1, or more, years of experience working in a management or leadership role.
- Must possess one of the following certifications: FITSP-O | Federal IT Security Institute, CEH(P) | EC-Council, GMON | GIAC, GRID | GIAC, GCED | GIAC, GDSA | GIAC, GSEC | GIAC, PenTest+ | CompTIA, CySA+ | CompTIA, Cloud+ | CompTIA, or MCTS+ | Microsoft.
- Must have an active DoW Secret Security Clearance.
Qualifications
- Have experience with most MS Office applications (Word, Excel, PowerPoint, and Visio).
- Be able to multi-task and prioritize various projects and assignments in a dynamic work environment in order to meet scheduled/unscheduled customer requests.
- Be willing to travel 25% of the time.
- Be willing to work rotating shifts in a 24x7x365 operational environment and respond quickly to emergencies as needed.
Skills
- Experience with security analysis and solutions in a WAN/LAN environment to include Routers, Switches, Network Devices, and Operating Systems (e.g., Windows, and Linux).
- Experience with other Security Operations Centers (SOC)/DCO tools/applications, such as Firewalls, Intrusion Detection Systems / Intrusion Prevention Systems, Network Security Manager, Forward Proxy, Spam Firewall, etc.
- Experience analyzing security compliance scans performed across a WAN (ACAS/Nessus preferred).
- Experience analyzing network and host-based threats (ESS preferred).
Benefits
- Health, dental, and vision insurance.
- Paid time off and holidays.
- Retail retirement benefits (including 401(k) matching).
- Education reimbursement.
- Parental leave.
- Employee stock purchase plan.
- Tax-saving options.
- Disability and life insurance.
- Pet insurance.