Jobs · Information Technology · Alabama

Mid-Level Cyber Defense Analyst / Incident Responder IRES - HSV

Amentum · Redstone Arsenal, AL · 1 mo ago
On-siteInformation TechnologyFull-time

About the role

The Mid-Level Cyber Defense Analyst / Incident Responder supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract.

Responsibilities

  • Perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties outlined in Evaluator Scoring Metrics (ESM).
  • Perform cybersecurity duties on customer networks (proactively and reactively) to improve enterprise-wide security posture.
  • Perform preliminary analysis, identification, and response actions to detect, characterize, and respond to cyber incidents IAW CJCSM 6510.01B.
  • Lead event/incident investigations from start to conclusion, to include gathering data, analysis, and reporting.
  • Properly document all steps in the incident response process while taking care to preserve and protect incident artifacts, evidence, and chain of custody.
  • Analyze correlated asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture.
  • Support a Cyber Defense Analyst and Cyber Defense Incident Responder training plan by instructing, evaluating, and mentoring Junior Cyber Defense Analyst and Cyber Defense Incident Responders.
  • Support the development, establishment, review and update of DCO procedures, processes, manuals, and other documentation.
  • Leverage actionable Cyber Threat Intelligence data to search for indicators of compromise and develop SIEM content/signatures to detect known attack patterns and make recommendations for improvements.
  • Carefully coordinate with CSSP-CERT subscribers to develop current configurations, rules, and signatures for cyber security related toolsets.
  • Carefully coordinate with CSSP-CERT subscribers to notify, investigate, and remediate discrepancies in security logging and CSSP-CERT alignment.
  • Provide standardized and targeted training in support of CSSP-CERT subscriber cyber defense and incident response programs.
  • Review data of ongoing intrusions or cybersecurity incidents and report, analyze, and document/report the findings in accordance with CJCSM 6510.01B guidelines.
  • Provide support to internal and external Insider threat and law enforcement / counterintelligence (LE/CI) agencies during cyber incidents / investigations.

Requirements

  • Must have 4, or more, years of general (full-time) work experience.
  • May be reduced with completion of advanced education.
  • Must have 4 years of directly related experience in information security, physical security, or cybersecurity, or a combination thereof.
  • Must have 1, or more, years of experience working in a management or leadership role.
  • Must possess one of the following certifications: FITSP-O | Federal IT Security Institute, CEH(P) | EC-Council, GMON | GIAC, GRID | GIAC, GCED | GIAC, GDSA | GIAC, GSEC | GIAC, PenTest+ | CompTIA, CySA+ | CompTIA, Cloud+ | CompTIA, or MCTS+ | Microsoft.
  • Must have an active DoW Secret Security Clearance.

Qualifications

  • Have experience with most MS Office applications (Word, Excel, PowerPoint, and Visio).
  • Be able to multi-task and prioritize various projects and assignments in a dynamic work environment in order to meet scheduled/unscheduled customer requests.
  • Be willing to travel 25% of the time.
  • Be willing to work rotating shifts in a 24x7x365 operational environment and respond quickly to emergencies as needed.

Skills

  • Experience with security analysis and solutions in a WAN/LAN environment to include Routers, Switches, Network Devices, and Operating Systems (e.g., Windows, and Linux).
  • Experience with other Security Operations Centers (SOC)/DCO tools/applications, such as Firewalls, Intrusion Detection Systems / Intrusion Prevention Systems, Network Security Manager, Forward Proxy, Spam Firewall, etc.
  • Experience analyzing security compliance scans performed across a WAN (ACAS/Nessus preferred).
  • Experience analyzing network and host-based threats (ESS preferred).

Benefits

  • Health, dental, and vision insurance.
  • Paid time off and holidays.
  • Retail retirement benefits (including 401(k) matching).
  • Education reimbursement.
  • Parental leave.
  • Employee stock purchase plan.
  • Tax-saving options.
  • Disability and life insurance.
  • Pet insurance.

Similar jobs