Cyber Fusion Analyst
1677 DISA-Pacific Ford Island HI, United States
Full Time Mid-level / Intermediate Clearance required USD 85K - 153K
GSM-O II provides network operations and cyber defense support to the Defense Information Systems Agency (DISA) in support of the DOD and COCOMs. In this role, you will provide support with cyber threat intelligence analysis, incident handling, triage of events, threat detection, trend analysis, metric development, vulnerability information dissemination and conduct network traffic analysis using raw packet data, netflow, IDS, IPS and custom sensor output as it pertains to the cyber security of communications networks.
We support 24/7 operations and shift assignments are based on both preference and contract requirements, so we ask our team members to remain flexible to potential shift modifications to meet minimum staffing requirements.
Primary Responsibilities:
- Maintain situational awareness of cyber activity by reviewing DoD, Intelligence Community and open-source reporting for new threat actors, vulnerabilities, malware, or other threats that have the potential to impact the DoDIN.
- Synthesize, summarize, consolidate, and share potentially malicious activities on the DoDIN with DISA and mission partner organizations by creating incident reports, wiki updates, collaboration/chat tippers and notifications, DoD incident handling database queries, metrics, and trend reports.
- Identify threats to the enterprise and provide mitigation strategies to improve security and reduce the attack surface.
- Perform analysis by leveraging serialized threat reporting, intelligence product sharing, OSINT, and open-source vulnerability information to ensure prioritized plans are developed.
- Analyze and document malicious cyber actors TTPs, providing recommendations and alignment to vulnerabilities and applicability to the enterprise operational environment.
- Discover adversary campaigns, anomalies and inconsistencies in sensor and system logs, SIEMs, and other data.
- Identify, investigate, and rule out system compromises, with the capacity to provide written analytic summaries and attack life cycle visualizations.
- Provide risk assessments and recommendations based on analysis of technologies, threats, intelligence, and vulnerabilities.
- Offer recommendations to adjust enterprise or tactical countermeasures to for threats impacting the DODIN.
- Collect analysis metrics and trending data, identify key trends, and provide situational awareness on these trends.
Required Qualifications:
- Active DoD TS/SCI Clearance
- Bachelor’s Degree in related discipline and 4+ years of related experience. Additional experience may be accepted in lieu of degree. Current DoD 8570 IAT Level II Certification (e.g. Sec+ CE) or higher at time of start.
- Current DoD 8570 CSSP Analyst Certification (e.g. CEH, CySA+) or ability to obtain one within 180 days of starting.
- In-depth knowledge of network and application protocols, cyber vulnerabilities and exploitation techniques and cyber threat/adversary methodologies.
- Proficiency with datasets, tools and protocols that support analysis (e.g. passive DNS, Virus Total, Recorded Future, TCP/IP, OSI, WHOIS, enumeration, threat indicators, malware analysis results, Wireshark, Splunk, Elastic etc.).
- Experience with various open-source and commercial vendor portals, services and platforms that provide insight into how to identify and/or combat threats or vulnerabilities to the enterprise.
- Proficiency working with various types of network data (e.g. netflow, PCAP, custom application logs)
Preferred Qualifications:
- Experience with the DISN and other DOD Networks.
- Skilled in building extended cyber security analytics (Trends, Dashboards, etc.).
- Demonstrated experience briefing Senior Executive Service (SES) and General Officer/Flag Officer (GO/FO) leadership.
- Experience in intelligence driven defense and/or Cyber Kill Chain methodology.
- IAT Level III and IAM Level II+III Certifications
- Experience with Splunk Query Language
Original Posting Date:
2024-12-18While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $85,150.00 - $153,925.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Tags: Analytics CEH Clearance Cyber defense Cyber Kill Chain DISA DNS DoD DoDD 8570 GSM IAM IDS IPS Malware NetOps OSINT PCAP Risk assessment SIEM Splunk TCP/IP Threat detection Threat intelligence TS/SCI TTPs Vulnerabilities
Perks/benefits: Equity / stock options Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.