Cyber Defense Analyst Suitland, MD Top Secret/SCI R-00190180
R-00190180
Location: Suitland, MD
Category: Cyber Operations
Schedule (FT/PT): Full Time
Travel Required: Yes, 10% of the time
Shift: Day
Remote Type: No Remote
Clearance: Top Secret/SCI
External Referral Program: Eligible
Referral Bonus Amount: $2,000
Sector: Defense
Share:share to twittershare to facebookshare to linkedin
Apply Now Save Job
Cyber Defense Analyst
Location: Suitland, MD
Clearance: Active TS/SCI
Day Shift Work Hours: 0730 - 1530
Primary Responsibilities
Perform first line monitoring of security tools and conduct initial analysis of alerts for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
Monitor organizational cybersecurity tools for alerts, anomalies, and indicators of compromise.
Investigate and perform initial technical analysis of cybersecurity alerts and events, escalating potential incidents to Tier 2 as appropriate.
Create, update, and manage incident and event tickets within the approved ticketing system.
Conduct proactive threat hunting activities to identify potential malicious activity and emerging threats.
Perform wireless security scans of facilities and document and report findings.
Correlate alerts and security events across multiple platforms to identify patterns, trends, and potential threats.
Prepare and deliver operational and situational awareness briefings.
Support annual cyber defense exercises.
Required Qualifications
Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired, with 5+ years of experience.
8+ years of relevant professional experience in lieu of a degree.
Active TS/SCI security clearance.
5+ years of concentrated experience in the CND discipline, regardless of degree.
3+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.
Strong analytical, conceptual, and problem solving skills.
Required Certifications
Must possess one of the following certifications: CompTIA CySA+, CompTIA PenTest+, CompTIA Cloud+, EC Council CEH, GIAC GCIA, GIAC GCIH, GICSP, or Cisco CyberOps.
NITESONI
DABAOPP1
Hello Candidates and New Clients:
Candidates - want a new job? Are you hiring and need help with a job placement?
https://www.linkedin.com/company/executive-staff-recruiters
Send us your resume: jonathan@executivestaffrecruiters.us
Clients: post jobs here:
https://esrhealthcare.mysmartjobboard.com/employer-products/
Visit us here:
https://www.careers-page.com/esr-healthcare
https://www.linkedin.com/company/executive-staff-recruiters
Check our profile below with more healthcare jobs posted:
Looking for new Healthcare clients (and other verticals) and candidates - please email us directly.
more open jobs (many verticals):
Send us your resume: jonathan@executivestaffrecruiters.us