Advanced Cyber Security Analytics Engineer with Security Clearance

D2 Consulting

St. Louis (MO)

On-site

USD 90,000 - 100,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health/Dental/Vision
401(k) match
Accrued PTO
STD/LTD/Life Insurance
Referral Bonuses
Professional development reimbursement

Job summary

D2 Consulting is seeking an Advanced Cyber Security Analytics Engineer in St. Louis, MO with an active TS/SCI clearance. You will develop and maintain defensive countermeasures, review intelligence and incident reports, and collaborate across Focused Operations to prevent and eradicate adversaries.

The role requires 8+ years of analytics experience, DoD 8140.01/8570.01-M IAT III CSSP Analyst certification, and proficiency in SIEM rule development, signatures, and script tuning.

Qualifications

  • 8+ years of advanced cyber security analytics experience.
  • Active TS/SCI security clearance required.
  • Must have a DoD 8140.01 DoD 8570.01-M IAT Level III CSSP Analyst certification.

Responsibilities

  • Analyze trends in NGA network data to identify incidents and tune rules/signatures.
  • Coordinate with teams to develop or tune rules/signatures/scripts.
  • Investigate potential sources of compromise and validate defensive countermeasures.
  • Correlate precursors to incidents and improve SIEM ruled detection.
  • Collaborate with Cyber Data Analytics to improve alert efficiency.

Skills

Cyber security analytics
SIEM querying
Signature development
Network analysis
Regex

Education

DoD 8140.01 / DoD 8570.01-M IAT Level III CSSP Analyst

Tools

Python
Bash
PowerShell

Job description

Advanced Cyber Security Analytics Engineer St. Louis, MO Apply **ACTIVE TS/SCI SECURITY CLEARANCE REQUIRED** Reporting to the Lead of Focused Operations, under the Branch Chief of Defensive Cyber Operations, you will be tasked with developing and maintaining defensive countermeasures for the enterprise. Working within a Fusion model, will collaborate with other teams within Focused Operations with the distinct task of proactively preventing a successful compromise and eradicating persistent adversaries already in the enterprise.

This will be done through various means such as reviewing future and past intelligence reports, reviewing incident reports, through regular Purple Teaming exercises, and continuously validating Defensive Countermeasures already deployed. More about your role:

  • Analyzes trends and patterns of data on NGA networks to identify and predict previously undiscovered events and incidents and develop or tune rules/signatures/scripts as needed.
  • Coordinates with Defensive Cyber Operations and Focused Operations to develop or tune rules/signatures/scripts.
  • Coordinates with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on enterprise systems and develop or tune rules/signatures/scripts as needed.
  • Correlates and analyzes precursors to incidents and develop or tune rules/signatures/scripts as needed.
  • Will collaborate with the Cyber Data Analytics team to achieve SIEM alert efficiency through evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed
  • Work with the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise to assist with triage.
  • Documents all work in the authorized ticketing system with a sufficient level of detail to ensure all stakeholders can systematically reconstruct the analysis;
  • Provide input to recurring meetings and briefings as required. Required Qualifications:
  • Must be a US Citizen with an Active TS/SCI.
  • 8+ years of related advanced cyber security analytics work experience.
  • Must have a certification that is compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.
  • Experience with data mining or building queries in a SIEM.
  • Strong understanding of signature development and tuning.
  • Strong understanding of network protocols and analysis with protocol analyzers.
  • Knowledge of static file signatures, i.e. "magic numbers" and how it applies to developing countermeasures for files in transit and that reside locally on a host.
  • Good working knowledge of regular expressions. Preferred Skills:
  • Comfortable in a hex editor.
  • Ability to write python/bash/powershell scripts.
  • Ability to analyze each use case, as it pertains to detection logic, and identify the corresponding capability.
  • Good understanding of Purple Team Tactics.
  • Familiarity with security in a cloud environment and how it applies to visibility gaps, data lakes and data mining. Additional Information
  • All your information will be kept confidential according to EEO guidelines.
  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically $90-$100k. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.
  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Accrued PTO, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and more! D2 Technical Services is committed to a merit-based recruitment process and encourages applications from all qualified individuals.

As a Veteran-Owned Small Business, we particularly welcome applications from veterans who have the requisite skills and experience.

Job applicants that are interested in one of our openings and may require a reasonable accommodation to participate in the job application or interview process, should contact us to request an accommodation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Advanced Cyber Security Analytics Engineer
Advanced Cyber Security Analytics Engineer

D2 Consulting • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Advanced Cyber Security Analytics Engineer
Advanced Cyber Security Analytics Engineer

D2 Technical Services • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
TS/SCI Cyber Defense Analytics Engineer
TS/SCI Cyber Defense Analytics Engineer

D2 Consulting • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Advanced Cybersecurity Analytics
Advanced Cybersecurity Analytics

Abile Group, Inc • St. Louis (MO)

On-site
USD 80,000 - 120,000
Advanced Cybersecurity Analytics
Advanced Cybersecurity Analytics

Abile Group, LLC • St. Louis (MO)

On-site
USD 90,000 - 120,000
Cybersecurity Advanced Analytics Specialist
Cybersecurity Advanced Analytics Specialist

Si Tec Consulting • Springfield (VA)

On-site
USD 150,000 - 210,000
Cybersecurity Advanced Analytics Specialist
Cybersecurity Advanced Analytics Specialist

Si Tec Consulting • West Springfield (VA)

On-site
USD 120,000 - 180,000
Cyber Security Operations Specialist - Tier 2
Cyber Security Operations Specialist - Tier 2

D2 Consulting • Springfield (VA)

On-site
USD 90,000 - 95,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Cybersecurity Advanced Analytics Specialist
Cybersecurity Advanced Analytics Specialist

SITEC Consulting, LLC. • Springfield (VA)

On-site
USD 120,000 - 180,000
Cyber Analytics Engineer III
Cyber Analytics Engineer III

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4