Advanced Cyber Security Analytics Engineer

D2 Technical Services

St. Louis (MO)

On-site

USD 90,000 - 100,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health/Dental/Vision
401(k) match
Accrued PTO
STD/LTD/Life Insurance
Referral Bonuses
Professional development reimbursement

Job summary

D2 Technical Services is seeking a highly experienced cybersecurity analyst with an active TS/SCI clearance to join the Defensive Cyber Operations team in the United States.

You will develop and maintain defensive countermeasures, tune SIEM detections, and coordinate with Purple Teaming exercises to prevent and eradicate adversaries across NGA networks.

The role emphasizes collaboration, documentation in ticketing systems, and regular briefings with stakeholders.

Qualifications

  • Must be a US citizen with an Active TS/SCI.
  • 8+ years of related advanced cyber security analytics work experience.
  • Must have a DoD 8140/8570 IAT Level III CSSP Analyst certification.
  • Experience with data mining or building queries in a SIEM.
  • Strong understanding of signature development and tuning.
  • Strong understanding of network protocols and analysis with protocol analyzers.

Responsibilities

  • Analyze trends in NGA network data to identify incidents and develop or tune rules/signatures/scripts.
  • Coordinate with Defensive Cyber Operations to tune rules/signatures/scripts.
  • Investigate potential sources of compromise with Cyber Operations Services and tune detections.
  • Correlate precursors to incidents and develop or tune detections as needed.
  • Assist SIEM alert optimization by evaluating valid alerts and false positives.
  • Work with Incident Response to assess ongoing activity and assist triage.
  • Document work in the ticketing system with detailed reconstructions for stakeholders.
  • Provide input to recurring meetings and briefings.

Skills

Cyber analytics
SIEM querying
Regex knowledge
Network analysis
Python scripting
PowerShell scripting
Bash scripting
US Citizenship
IAT III CSSP

Education

DoD 8140/8570 IAT III CSSP

Tools

SIEM tooling

Job description

ACTIVE TS/SCI SECURITY CLEARANCE REQUIRED

Reporting to the Lead of Focused Operations, under the Branch Chief of Defensive Cyber Operations, you will be tasked with developing and maintaining defensive countermeasures for the enterprise. Working within a Fusion model, will collaborate with other teams within Focused Operations with the distinct task of proactively preventing a successful compromise and eradicating persistent adversaries already in the enterprise. This will be done through various means such as reviewing future and past intelligence reports, reviewing incident reports, through regular Purple Teaming exercises, and continuously validating Defensive Countermeasures already deployed.


More about your role:



  • Analyzes trends and patterns of data on NGA networks to identify and predict previously undiscovered events and incidents and develop or tune rules/signatures/scripts as needed.

  • Coordinates with Defensive Cyber Operations and Focused Operations to develop or tune rules/signatures/scripts.

  • Coordinates with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on enterprise systems and develop or tune rules/signatures/scripts as needed.

  • Correlates and analyzes precursors to incidents and develop or tune rules/signatures/scripts as needed.

  • Will collaborate with the Cyber Data Analytics team to achieve SIEM alert efficiency though evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed

  • Work with the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise to assist with triage.

  • Documents all work in the authorized ticketing system with a sufficient level of detail to ensure all stakeholders can systematically reconstruct the analysis;

  • Provide input to reoccurring meetings and briefings as required.


Required Qualifications:



  • Must be a US Citizen with an Active TS/SCI.

  • 8+ years of related advanced cyber security analytics work experience.

  • Must have a certification that is compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.

  • Experience with data mining or building queries in a SIEM.

  • Strong understanding of signature development and tuning.

  • Strong understanding of network protocols and analysis with protocol analyzers.

  • Knowledge of static file signatures, i.e. \"magic numbers\" and how it applies to developing countermeasures for files in transit and that reside locally on a host.

  • Good working knowledge of regular expressions.


Preferred Skills:



  • Comfortable in a hex editor.

  • Ability to write python/bash/powershell scripts.

  • Ability to analyze each use case, as it pertains to detection logic, and identify the corresponding capability.

  • Good understanding of Purple Team Tactics.

  • Familiarity with security in a cloud environment and how it applies to visibility gaps, data lakes and data mining.


Additional Information


All your information will be kept confidential according to EEO guidelines.


Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically $90-$100k. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.



  • Health/Dental/Vision

  • 401(k) match

  • Accrued PTO

  • STD/LTD/Life Insurance

  • Referral Bonuses

  • professional development reimbursement

  • and more!


D2 Technical Services is committed to a merit-based recruitment process and encourages applications from all qualified individuals. As a Veteran-Owned Small Business, we particularly welcome applications from veterans who have the requisite skills and experience. Job applicants that are interested in one of our openings and may require a reasonable accommodation to participate in the job application or interview process, should contact us to request an accommodation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Operations Specialist - Tier 2
Cyber Security Operations Specialist - Tier 2

D2 Consulting • Springfield (VA)

On-site
USD 90,000 - 95,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Lead Cyber Defense Incident Responder TS/SCI
Lead Cyber Defense Incident Responder TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 165,000 - 180,000
Network Based Systems Analyst II
Network Based Systems Analyst II

DigiFlight, Inc. • Columbia (MD), Northern (KY)

Hybrid
USD 110,000 - 150,000
Health, Dental, Vision
Paid Time Off
11 paid holidays
+6
Cyber Security Operations Specialist Tier 3
Cyber Security Operations Specialist Tier 3

D2 Consulting • Springfield (VA)

On-site
USD 110,000 - 115,000
Health/Dental/Vision
401(k) match
PTO (paid time off)
+1
Advanced Cybersecurity Analytics
Advanced Cybersecurity Analytics

Abile Group, Inc • St. Louis (MO)

On-site
USD 80,000 - 120,000
Senior TS/SCI Cyber Defense Analytics Engineer
Senior TS/SCI Cyber Defense Analytics Engineer

D2 Technical Services • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Linux SIEM System Engineer
Linux SIEM System Engineer

D2 Consulting • St. Louis (MO)

On-site
USD 90,000 - 95,000
Health/Dental/Vision
401(k) match
Paid time off
+3
Advanced Cybersecurity Analytics Engineer III St. Louis, MO, US
Advanced Cybersecurity Analytics Engineer III St. Louis, MO, US

CACI International Inc. • St. Louis (MO)

On-site
USD 75,000 - 159,000
Flexible time off
Comprehensive healthcare benefits
Continuing education support
Network Based Systems Analyst II
Network Based Systems Analyst II

DigiFlight, Inc. • Arlington (VA)

On-site
USD 90,000 - 120,000
Health, Dental, Vision Insurance
Paid Time Off
Tuition Education Assistance
+1
Linux SIEM System Engineer
Linux SIEM System Engineer

D2 Technical Services • St. Louis (MO)

On-site
USD 90,000 - 95,000
Health and dental coverage
401(k) match
Paid time off
+3