Location work will be performed: NC O024 - Morrisville -
Job Description: Cyber Threat Analyst II
Description:
Identifies and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; produces finds to help initialize or support law enforcement and counterintelligence investigations or activities.
Details:
• Identify and develop threat signatures from all available sources
• Maintain threat indicators within the threat intelligence platform
• Implement and support standard procedures for incident response
• Interface with Business Unit Information System Security Officers and Incident Response Teams
Key Responsibilities:
• Implement a dynamic, advanced Risk-Based Alerting (RBA) security framework within Splunk
• Create and test detections written in advanced Splunk Programming Language (SPL)
• Perform analysis on hosts running on a variety of platforms and operating systems, to include, Microsoft Windows & Linux.
• Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system logs) to identify possible threats to network security.
• Leverage tools including Splunk, Tanium, Firepower, Azure, Google Cloud, SentinelOne, SESC suite as part of duties performing cyber incident response analysis.
• Act as an observer to Red Team penetration testing exercises and collaborating with Cybersecurity Operations Center (CSOC)
• Correlate event or incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.
• Work with a diverse team of analysts in conducting incident triage, incident handling, and remediation.
EXPERIENCE LEVEL:
3-5 years of experience with security operations and incident response
EDUCATION:
Bachelor's OR Master's Degree in Computer Science, Information Systems, or other related field. Or equivalent work experience.
CERTIFICATIONS: (One or more desired)
One or more of the following Certification(s): CISSP, CISA, CISM, GIAC, RHCE.
Additional Provisions:
• Must be able to obtain a Position of Public Trust Clearance • Pass both a client mandated clearance process to include drug screening, criminal history check and credit check.
• Once candidate’s resume is approved and interview passed, the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
• If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
• All candidates must be a US Citizen, or have permanent residence status (Green Card).
• Candidate must have lived in the United States for the past 5 years.
• Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)
• All overtime must be pre-approved in writing by the client manager or his/her designated representative.
• Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time