Advanced Cybersecurity Analytics

Abile Group, LLC

St. Louis (MO)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Abile Group, LLC is seeking an Advanced Cyber Analyst to provide Network and Cybersecurity services for an Intelligence Community customer. This role involves analyzing data trends, coordinating with Cyber Operations, and developing measures for effective incident response.

The ideal candidate will have at least a Bachelor’s degree and 8+ years of relevant experience in cyber security analytics, along with necessary certifications. TS/SCI clearance with the ability to obtain a CI Poly is required.

Qualifications

  • 8+ years of related advanced cyber security analytics work experience.
  • Must obtain TS/SCI clearance with ability to obtain a CI Poly.

Responsibilities

  • Analyze trends and patterns of data on networks to identify events and incidents.
  • Coordinate with Cyber Operations to develop or tune rules/signatures/scripts.
  • Investigate potential sources of compromise on enterprise systems.
  • Analyze precursors to incidents and develop or tune necessary measures.
  • Work with Cyber Incident Response Team to predict adversary responses.
  • Document work in the ticketing system with appropriate detail.

Skills

Data mining or building queries in a SIEM
Signature development and tuning
Network protocols and analysis
Static file signature knowledge
Regular expressions

Education

Bachelor’s degree

Job description

Abile Group has an exciting and challenging opportunity for an Advanced Cyber Analyst on a contract providing Network and Cybersecurity services supporting an Intelligence Community customer. All the personnel on the team will work together to support transport and cybersecurity information technology (IT) services on multiple networks and security domains, at multiple locations worldwide, inclusive of new facilities and building constructions to support the IC mission.

Responsibilities
  • Analyzes trends and patterns of data on networks to identify and predict previously undiscovered events and incidents, and develop or tune rules/signatures/scripts as needed.
  • Coordinates with Defensive Cyber Operations and Focused Operations to develop or tune rules/signatures/scripts.
  • Coordinates with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on enterprise systems, and develop or tune rules/signatures/scripts as needed.
  • Correlates and analyzes precursors to incidents, and develop or tune rules/signatures/scripts as needed.
  • Collaborates with the Cyber Data Analytics team to achieve SIEM alert efficiency through evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed.
  • Works with the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise to assist with triage.
  • Documents all work in the authorized ticketing system with a sufficient level of detail to ensure all stakeholders can systematically reconstruct the analysis.
  • Provides input to recurring meetings and briefings as required.
Clearance Required

TS/SCI with ability to obtain a CI Poly.

Degree and Years of Experience

Bachelor’s degree and 8+ years of related advanced cyber security analytics work experience.

Required Certifications
  • Must have a certification that is compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.
Required Skills
  • Experience with data mining or building queries in a SIEM.
  • Strong understanding of signature development and tuning.
  • Strong understanding of network protocols and analysis with protocol analyzers.
  • Knowledge of static file signatures, i.e. "magic numbers" and how it applies to developing countermeasures for files in transit and that reside locally on a host.
  • Good working knowledge of regular expressions.
Desired Skills
  • Comfortable in a hex editor.
  • Ability to write python/bash/powershell scripts.
  • Ability to analyze each use case, as it pertains to detection logic, and identify the corresponding capability.
  • Good understanding of Purple Team Tactics.
  • Familiarity with security in a cloud environment and how it applies to visibility gaps, data lakes and data mining.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Advanced Cybersecurity Analytics
Advanced Cybersecurity Analytics

Abile Group, Inc • St. Louis (MO)

On-site
USD 80,000 - 120,000
Elite Cyber Analytics Specialist | SIEM & Threat Intel
Elite Cyber Analytics Specialist | SIEM & Threat Intel

Abile Group, LLC • St. Louis (MO)

On-site
USD 90,000 - 120,000
Cyber Data Analysis Engineer
Cyber Data Analysis Engineer

Abile Group, Inc • St. Louis (MO)

On-site
USD 85,000 - 115,000
Cyber Data Analysis Engineer
Cyber Data Analysis Engineer

Abile Group, Inc • Springfield (VA)

On-site
USD 80,000 - 110,000
Senior Advanced Cybersecurity Analytics Specialist
Senior Advanced Cybersecurity Analytics Specialist

Abile Group, Inc • St. Louis (MO)

On-site
USD 80,000 - 120,000
Cyber Hunt Analyst
Cyber Hunt Analyst

Synergy ECP • Columbia (MD)

On-site
USD 90,000 - 130,000
Cybersecurity Implementation Engineer
Cybersecurity Implementation Engineer

Abile Group, Inc • Springfield (VA)

On-site
USD 95,000 - 130,000
Cyber Capability Developer
Cyber Capability Developer

AnaVation, LLC • Chantilly (VA)

On-site
USD 120,000 - 150,000
NOSC Cyber Analyst
NOSC Cyber Analyst

Abile Group, LLC • New York (NY)

On-site
USD 125,000 - 155,000
Cyber Analyst
Cyber Analyst

BWM Outcomes • Manassas Park (VA)

On-site
USD 85,000 - 110,000