Cyber Security Analyst I

Pensacola, FL, United States

Navy Federal Credit Union

Navy Federal Credit Union is an armed forces bank serving the Navy, Army, Marine Corps, Air Force, Space Force, Coast Guard, veterans, DoD & their families. Join now!

View all jobs at Navy Federal Credit Union

To monitor security tools and systems, and provides first tier response to cyber security incidents in a 24/7/365 Cyber Security Operations Center. Ensure adherence to standard operating procedures for detecting, classifying, and reporting incidents. Works under minimal supervision.

  • Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
  • Coordinate with enterprise-wide cyber defense staff to validate network alerts
  • Document and escalate incidents (including event's history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment
  • Perform cyber defense trend analysis and reporting
  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack
  • Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy
  • Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts
  • Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
  • Use cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity
  • Analyze identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Determine tactics, techniques, and procedures (TTPs) for intrusion sets
  • Examine network topologies to understand data flows through the network
  • Recommend computing environment vulnerability corrections
  • Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings)
  • Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools
  • Isolate and remove malware
  • Identify applications and operating systems of a network device based on network traffic
  • Reconstruct a malicious attack or activity based off network traffic
  • Identify network mapping and operating system (OS) fingerprinting activities
  • Assist in the construction of signatures which can be implemented on cyber defense network tools in response to new or observed threats within the network environment or enclave
  • Notify designated managers, cyber incident responders, and cybersecurity service provider team members of suspected cyber incidents and articulate the event's history, status, and potential impact for further action in accordance with the organization's cyber incident response plan
  • Analyze and report organizational security posture trends
  • Analyze and report system security posture trends
  • Assess adequate access controls based on principles of least privilege and need-to-know
  • Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise
  • Assess and monitor cybersecurity related to system implementation and testing practices
  • Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities
  • Work with stakeholders to resolve computer security incidents and vulnerability compliance
  • Provide advice and input for Disaster Recovery, Contingency, and Continuity of Operations Plans
  • Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents
  • Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation
  • Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security
  • Perform cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation
  • Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems
  • Perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support Incident Response Teams (IRTs)
  • Track and document cyber defense incidents from initial detection through final resolution
  • Employ approved defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, and security robustness).
  • Collect intrusion artifacts (e.g., source code, malware, Trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise
  • Coordinate with intelligence analysts to correlate threat assessment data
  • Write and publish after action reviews
  • Coordinate incident response functions
  • Provide technical summary of findings in accordance with established reporting procedures
  • Coordinate resolution with Tier 2/3 and/or Supervisor for high priority incidents in a timely manner
  • Execute daily adhoc tasks or lead small projects
  • Perform other duties as assigned
  • Basic experience in cybersecurity and/or information technology (IT) security 
  • Basic knowledge of security architectures, firewalls, proxies, and network topologies
  • Basic understanding of cyber-defense signature development
  • Basic skill in using security event correlation tools
  • Basic skill in detecting host and network based intrusions via intrusion detection technologies (e.g., Snort)
  • Basic communication skills for reporting technical solutions to team leadership
  • Foundational research, analytical, and problem-solving skills
  • Highly skilled in collaborating with other team members on time-sensitive incidents

Desired Qualifications

  • Bachelor degree in cybersecurity or related discipline
  • Basic experience with security tools related to enterprise log management, IDP/IDS, antivirus, firewalls, proxies, DLP, forensic analysis and SIEM
  • Experience with Security Tools related to Enterprise Log Management, IDP/IDS, Antivirus, Firewalls, Proxies, DLP, Forensic Analysis, Malware analysis and SIEM
  • Basic experience in Cybersecurity analysis, incident response, or a related field with increasing  responsibility
  • Experience in a Security Operations Center (SOC) or Network Operations Center (NOC)
  • Sec+, Net+, CySA+ or other related Information Security certifications 
  • AZ-900 or other related Cloud Security certifications
  • Working knowledge of IT Security Standards and Frameworks including ISO and NIST 

Hours: Monday - Friday, 6:00AM - 10:30PM (Day or evening shift as needed)

Location: 820 Follin Lane, Vienna, VA 22180 | 5550 Heritage Oaks Dr. Pensacola, FL 32526 | 141 Security Dr. Winchester, VA 22602 

Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks.

  • Best Companies for Latinos to Work for 2024
  • Computerworld® Best Places to Work in IT
  • Forbes® 2024 America’s Best Large Employers
  • Forbes® 2023 The Best Employers for New Grads
  • Fortune Best Workplaces for Millennials™ 2023   
  • Fortune Best Workplaces for Women ™ 2023       
  • Fortune 100 Best Companies to Work For® 2024
  • Military Times 2023 Best for Vets Employers
  • Newsweek Most Loved Workplaces 
  • Ripplematch Campus Forward Award - Excellence in Early Career Hiring
  • Yello and WayUp Top 100 Internship Programs

From Fortune. ©2024 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union.

Equal Employment Opportunity: Navy Federal values, celebrates, and enacts diversity in the workplace. Navy Federal takes affirmative action to employ and advance in employment qualified individuals with disabilities, disabled veterans, Armed Forces service medal veterans, recently separated veterans, and other protected veterans. EOE/AA/M/F/Veteran/Disability EOE/AA/M/F/Veteran/Disability

Hybrid Workplace: Navy Federal Credit Union is a hybrid workplace, and details will be discussed during your interview process.

Disclaimers: Navy Federal reserves the right to fill this role at a higher/lower grade level based on business need. An assessment may be required to compete for this position. Job postings are subject to close early or extend out longer than the anticipated closing date at the hiring team’s discretion based on qualified applicant volume. Navy Federal Credit Union assesses market data to establish salary ranges that enable us to remain competitive. You are paid within the salary range, based on your experience, location and market position.

Bank Secrecy Act: Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  11  4  0
Category: Analyst Jobs

Tags: Antivirus Cloud Compliance Cyber defense Firewalls IDS Incident response Intrusion detection Log files Malware Monitoring NetOps Network security NIST SIEM Snort SOC Strategy TTPs Vulnerabilities

Perks/benefits: Career development Competitive pay Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.