CND/Incident Response Analyst
Fort Meade, Maryland
Applications have closed
Cask Technologies
Cask Government Services provides technology consulting services for government and large enterprises to help achieve your goals. Contact us to learn more.
Cask is a leading Management Consulting firm specializing in delivering business and technical expertise to clients across commercial and government markets. Join the many happy employees at Cask! We have been named a top 5 firm to work for by Consulting Magazine for 5 of the past 6 years.
Responsibilities
- The contractor shall assist with analysis of actions taken by malicious actors in order to determine initial infection vector, establish a timeline of activity, and any data loss associated with incidents.
- Provide Python Programming, PowerShell Programming, and Script Development.
- Coordinate with and provide expert technical support to enterprise-wide CND technicians to document CND incidents, correlate incident data to identify specific vulnerabilities, and make recommendations enabling remediation.
- Monitor external data sources (e.g., computer network defense vendor sites, Computer Emergency Response Teams, Storage Area Networks (SANs), Security Focus), update the CND threat condition, and determine which security issues may have an impact on the enterprise.
- Analyze log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security and perform command and control functions in response to incidents.
- Perform CND incident triage, to include determining, urgency, and potential impact; identifying the specific vulnerability; and making written recommendations that enable expeditious remediation.
- Utilize forensically sound collection techniques of images and inspect to discern mitigation/remediation on enterprise systems, perform real-time CND incident handling (e.g.,
- Forensic collections, intrusion correlation/tracking, threat analysis, and direct system remediation) to support deployable Incident Response Teams (IRTs).
- Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts and track and document CND incidents from initial detection through final resolution.
- Employ approved defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, and security robustness), collect intrusion artifacts (e.g., source code, malware, and trojans), and use discovered data to enable mitigation of potential CND incidents within the enterprise.
Requirements
- Clearance Required: TS/SCI with counter-intelligence polygraph
- IAT level III or CSSP Incident Responder certification with documented additional education, specialization, or certification in one of the technologies or tools listed below:
- 5 years of experience in a majority of the below:
- System Architecture
- - Network Engineering
- - Systems Engineering
- - Virtual Environments
- Scripting
- - Powershell
- - Python
- - RegEx
- Forensics
- - Dead disk and memory interrogations
- - Malware analysis/reverse engineering
- Additional Preferred Experience
- - SCADA Systems
- - Cloud Environments
- - Database Administration
- - Hunt Methodologies
- - SEIM Operations (Splunk/Security Onion)
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
5
0
0
Categories:
Analyst Jobs
Incident Response Jobs
Tags: Clearance Clearance Required Cloud CND Firewalls Forensics IDS Incident response Intrusion detection Log files Malware Network security Polygraph PowerShell Python Reverse engineering SANS SCADA Scripting Splunk TS/SCI Vulnerabilities
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsCyber Security Specialist jobsIT Security Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsSystems Engineer jobsChief Information Security Officer jobsSystems Administrator jobsStaff Security Engineer jobsInformation System Security Officer (ISSO) jobsPrincipal Security Engineer jobsThreat Intelligence Analyst jobsSenior Product Security Engineer jobsCloud Security Architect jobsInformation Systems Security Engineer jobs
GDPR jobsEncryption jobsPowerShell jobsDevSecOps jobsEDR jobsSaaS jobsIDS jobsSplunk jobsSDLC jobsRMF jobsIPS jobsTop Secret jobsSQL jobsIntrusion detection jobsBash jobsThreat detection jobsActive Directory jobsCompTIA jobsDoDD 8570 jobsITIL jobsOWASP jobsDocker jobsBanking jobsCRISC jobsUNIX jobs
Finance jobsTCP/IP jobsClearance Required jobsGIAC jobsCISO jobsIndustrial jobsTerraform jobsHIPAA jobsIT infrastructure jobsSOC 2 jobsSANS jobsJavaScript jobsVPN jobsOSCP jobsCCSP jobsMITRE ATT&CK jobsSOAR jobsJira jobsDNS jobsSOX jobsData Analytics jobsPolygraph jobsNIST 800-53 jobsGCIH jobsSecurity strategy jobs