Cyber Security Analyst (S-NET)
Annapolis Junction, MD, United States
Full Time Entry-level / Junior Clearance required USD 69K - 129K * est.
Abile Group
Overview
Abile Group has an exciting and challenging opportunity for a Cyber Security Analyst (S-NET) supporting an Intelligence Community Customer.
The right candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.
Responsibilities
- Performs technical analysis on a wide range of cybersecurity issues, with a focus on network activity, host activity, and data. This includes, but is not limited to: network flow (i.e. netflow) or related forms of session summary data, signature-based IDS/IPS alert/event data, full packet capture (PCAP) data, proxy and application server logs (various types).
- Triages IDS/IPS alerts, collects related data from various systems, reviews open and closed source information on related threats & vulnerabilities, diagnose observed activity for likelihood of system infection, compromise or unintended/high-risk exposure.
- Prepares analysis reports detailing background, observables, analysis process & criteria, and conclusions.
- Analyzes large volumes of network flow data for specific patterns/characteristics or general anomalies, to trend network activity and to correlate flow data with other types of data or reporting regarding enterprise-wide network activity.
- Leverages lightweight programming/scripting skills to automate data-parsing and simple analytics. Documents key event details and analytic findings in analysis reports and incident management systems. Identifies, extracts and characterizes network indicators from cyber threat intelligence sources, incident reporting and published technical advisories/bulletins.
- Assesses cyber indicators/observables for technical relevance, accuracy, and potential value/risk/reliability in monitoring systems. Recommends detection and prevention/mitigation signatures and actions as part of a layered defensive strategy leveraging multiple capabilities and data types.
- Develops IDS/IPS signatures, tests and tunes signature syntax, deploys signatures to operational sensors, and monitors and tunes signature and sensor performance.
- Fuses open-source threat & vulnerability information with data collected from sensors across the enterprise into cohesive and comprehensive analysis.
- Develops security metrics and trend analysis reports.
Qualifications
Clearance Required: TS/SCI.
Degree and Years of Experience: 5 to 8 years with BS/BA or 3 to 5 years with MS/MA or 0 to 2 years with PhD.
Required Certifications:
- Current DoD 8570.1-M IAT Level II certification.
Desired Certifications:
- CEH, GCIH, GCIA, GCFA.
Desired Skills:
- 3+ years in a SOC or Incident Response role.
- Experience with Cisco Firepower, Cisco Sourcefire, Cisco Advanced Malware Protection, Cisco Stealthwatch, Cisco Umbrella.
- Experience with deploying and writing signatures (Snort, YARA, HIPS).
- Experience with network hunting utilizing Zeek/Bro.
- Experience with McAfee ePO, HBSS.
- Splunk: Create log searches, dashboards, setting up alerts, and scheduled reports to help detect and remediate security concerns.
- Experience with ArcSight.
- Experience with Wireshark and packet analysis.
- Experience with Tanium or other endpoint solutions.
- Working knowledge of scripting languages such as Python, PowerShell, Shell.
- Knowledge of Regular Expressions.
- Knowledge of server and client operating systems.
- Participate in development and reporting of security metrics.
- Experience in a SOC or Incident Response role.
About Abile Group, Inc.
Abile Group, Inc. was formed in July 2004 to partner with the Intelligence Community and their Contractors in the areas of Enterprise Analytics & Performance Management, IT & Systems Engineering and Program & Project Management. We have significant experience with the Federal Government and are an EDWOSB dedicated to our employees and clients. We are looking for high performing employees who enjoy providing advice and guidance along with solutions development and implementation support, crafted by combining industry best practices with the clients’ subject matter experience and Abile’s breadth of expertise.
Hiring Statement
Abile Group, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Anyone requiring reasonable accommodations should email careers@abilegroup.com with requested details. A member of the HR team will respond to your request within 2 business days.
Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics ArcSight CEH Clearance Clearance Required DoD DoDD 8570 GCFA GCIA GCIH IDS Incident response IPS Malware Monitoring PCAP PhD PowerShell Python Scripting Snort SOC Sourcefire Splunk Strategy Threat intelligence TS/SCI Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.