We are hiring a Senior Cybersecurity (CND) Analyst at our location in Springfield, VA.

Description

The Senior CND Analyst responsible for identifying, analyzing, and mitigating threats to hosted information systems. Uses Computer Network Defense tools, defensive measures, and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the enterprise network in order to protect information, Information Systems, and networks from threats.

 

Responsible for investigating and analyzing response activities related to cyber incidents within the environment. Responsible for correlating incident data and performing CND trend analysis and reporting. Develops and provides CND activity/incident reports, summaries, and other situational awareness information, and presents to the CIO or designated representative(s). Develops and maintains documentation as it pertains to the use and operation of CND tools (SOPs, playbooks, incident reporting, incident response, etc.).

 

The Senior CND Analyst will prioritize, direct, guide, and evaluate other CND Analysts through training, quality control, and feedback in coordination with the CND Manager.  The Senior CND Analyst shall develop and execute a continuous monitoring and analysis strategy for host information systems to monitor and report on any indications of outsider and insider threats; watch for and report on unauthorized changes; and monitor the operational environment and report on any suspected intrusions. Shall utilize Splunk software to include Splunk Enterprise Security (ES) and Splunk User Behavior Analytics (UBA) for continuous monitoring, incident reviews, investigations, and event correlation.

Qualifications

  • Shall have 7 or more years of experience in Information Security (INFOSEC) operations and/or cybersecurity-related experience.
  • Shall have 5 or more years of experience in operating a SIEM and/or vulnerability scanner product (Splunk, Tenable, etc.).


Education: Bachelor’s Degree from an Accredited University.


Certifications

  • Certified Computer Security Incident Handler (CSIH)
  • GIAC Certified Incident Handler (GCIH).

 

Desired Qualifications

  • 7 or more years of experience working in an operational Security Operations Center (SOC) as a cybersecurity professional, or amongst a team with responsibility for similar functionality and behavior.
  • 7 or more years of hands-on experience working with industry standard solutions for some, or all, of the following: Security Information and Events Management (SIEM), Vulnerability Assessment and Management, Advanced Network Inspection/Analysis, Advanced Malware Detection, Data Loss Prevention (DLP), Incident Response, Forensics Tools, User Activity Monitoring (UAM), and User Behavioral Analytics (UBA) solutions. 

Security Clearance

  • This position requires an active DoD Top Secret clearance, and possess or have the ability to obtain and maintain a Polygraph.
This job is currently not open for applications. Would you like to see our other open positions?