CSOC Tier 3 Cyber Engineer

General Dynamics Information Technology, Inc.

Springfield (VA)

On-site

USD 147,000 - 199,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

General Dynamics Information Technology, Inc. is seeking a Senior CSOC Tier 3 Analyst for a Springfield, VA-based role focused on 24x7 containment, eradication, and recovery of cyber incidents.

The candidate will perform malware analysis and artifact handling as part of advanced cyber defense operations. The role requires Top Secret/SCI clearance with polygraph, DoD 8140.01 and DoD 8570.01-M IAT Level II, CSSP Incident Responder certification, and 8+ years of cyber security experience.

Qualifications

  • 8+ years of related Cyber Security experience.
  • Active TS/SCI clearance with Polygraph
  • Must meet DoDD 8140.01 and DoD 8570.01-M IAT Level II CSSP Incident Responder requirements.

Responsibilities

  • Coordinate and implement cyber incident response tasks and containment actions.
  • Perform malware analysis, artifact handling, and forensic data reviews.
  • Collaborate with government SI and counterintelligence offices and other stakeholders.
  • Prepare and deliver incident reports detailing lifecycle, actions, and recommendations.

Skills

Cyber Defense
Malware
Malware Analysis
Network Analysis
Security Incident Response

Education

Bachelor's Degree
DoDD 8140.01 / DoD 8570.01-M IAT Level II CSSP Incident Responder

Job description

Type of Requisition: Pipeline Clearance Level Must Currently Possess: Top Secret/SCI Clearance Level Must Be Able to Obtain: Top Secret SCI + Polygraph Public Trust/Other Required: None Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Cyber Defense, Malware, Malware Analysis, Network Analysis, Security Incident Response Certifications: CompTIA Security+ CE | CompTIA - CompTIA Experience: 8 + years of related experience US Citizenship Required: Yes

Job Description:

Candidate will provide Expert CSOC Tier 3 services, which is 24x7x365 coordination, execution, and implementation of all actions required for the containment, eradication, and recovery measures for events and incidents. CSOC Tier 3 services includes malware and implant analysis, and forensic artifact handling and analysis. All Contractor personnel performing CSOC Tier 3 services shall have or obtain, within six months of start, a certification that is compliant with DoDD 8140.01 and DoD 8570.01-M IAT Level II and CSSP Incident Responder.

Job Duties:

Coordinate and implement tasks, performing analysis, and building/documenting response activities required during cyber security incident response, to include but not limited to actions such as implementing containment measures, IP blocks, domain blocks, and disabling user accounts on direction of the Government. Coordinates with Security and Installations Directorate (SI) Office of Counterintelligence (SIC), Insider Threat Office (SIII), in addition to other law enforcement and counter intelligence personnel as required to perform advanced investigation and triage of incidents; Collaborates with appropriate authorities in the production of security incident reports; Categorizes incidents and events; Coordinates with other contracts, organizations, activities, and other services as appropriate to ensure incidents are properly reported, contained, and eradicated; Coordinates with other contracts, organizations, activities, and other services as appropriate to de-conflict blue / red team activity with open incidents/events; and analyze data, and to respond to incidents/events; Performs digital media analysis on host, server, and network data as required to analyze and respond to an incident, to include but not limited to volatile and non-volatile memory and/or system artifact collection and analysis; Develops and identifies indicators of compromise to send to Cybersecurity stakeholders and other Contract Services; Performs malware analysis and signature development; Coordinate with CSOC Tier 1 and 2 services to remediate all discrepancies and provide recommendations to prevent reoccurrence.

Job Requirements:

Bachelors Degree and 8 years’ experience in Cyber Security (CSOS) Active TS/SCI, Polygraph DoDD 8140.01 and DoD 8570.01-M IAT Level II and CSSP Incident Responder. Provides input to and coordinates with all applicable stakeholders to develop and deliver the daily CSOC Significant Activity Report, the daily CSOC Operations Update, and the Weekly CSOC Status Report; Serve as C-IRT members as required and serve under the direct control of, and take direction from, the Government C-IRT Commander; Develop and coordinate courses of action with various Government and contract stakeholders, and when properly authorized by the Government, execute Defensive Cyberspace Operations-Internal Defensive Measures on behalf of the customers’ networks and systems; Performs digital media analysis and malware reverse engineering on host, server, and network data as required to analyze and respond to an incident, to include but not limited to volatile and non-volatile memory and/or system artifact collection and analysis. When properly authorized by the Government, execute custom scripts, tools, and capabilities to collect and analyze data, and to respond to incidents/events; Develops, documents, and provides to the Government incident investigation reports which include sufficient information to document the entire lifecycle of the incident and the response, including but not limited to adversary and friendly forces activity, host and network analysis, timelines, and recommendations for corrective actions, recommendations for new Tactics, Techniques, and Procedures (TTP) and other recommendations as appropriate, within 30 days of C-IRT stand-down; Conduct Quality Control reviews of a percentage closed CSOC Tier 2 tickets each week to ensure proper analysis, categorization, documentation, and notification

Preferred Qualifications:

Masters degree IAT III

The likely salary range for this position is $147,292 - $199,278. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours: 40 Travel Required: None Telecommuting Options: Onsite Work Location: USA VA Springfield Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Opportunity Owned From working with technologies like AI, cyber and cloud to careers in intelligence and health, we offer endless opportunities to apply your expertise to create a safer, smarter world.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CSSP DCO Analyst
CSSP DCO Analyst

General Dynamics Information Technology, Inc. • Bellevue Second IV Precinct (NE)

On-site
USD 98,000 - 117,000
Health benefits
401K with company match
Educational Assistance
CSSP DCO Analyst
CSSP DCO Analyst

General Dynamics Information Technology • Omaha (NE)

On-site
USD 87,000 - 117,000
Health benefits (Medical/Dental/Vision
401K with company match
Educational Assistance and eLearning
+2
Cyber Intrusion Detection System Administrator - TS/SCI with Polygraph
Cyber Intrusion Detection System Administrator - TS/SCI with Polygraph

General Dynamics Information Technology, Inc. • Reston (VA)

On-site
USD 149,000 - 201,000
Growth opportunities
Internal mobility team
Comprehensive benefits & 401K
+1
Information Security Director
Information Security Director

General Dynamics Information Technology, Inc. • Bellevue Second IV Precinct (NE)

On-site
USD 170,000 - 205,000
Health benefits
401(k)
Education assistance
+2
Cyber Security Operations Specialist - Tier 2
Cyber Security Operations Specialist - Tier 2

D2 Consulting • Springfield (VA)

On-site
USD 90,000 - 95,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
CSSP DCO Analyst
CSSP DCO Analyst

General Dynamics Information Technology, Inc. • Bellevue (NE)

On-site
USD 98,000 - 117,000
Health benefits
401K with company match
Educational Assistance
Cyber Security Analyst Senior Advisor
Cyber Security Analyst Senior Advisor

General Dynamics Information Technology, Inc. • Tampa (FL)

On-site
USD 110,000 - 150,000
401K with company match
Health and wellness packages
Internal mobility
+3
Cybersecurity Operations Specialist -SIEM Services (Evergreen)
Cybersecurity Operations Specialist -SIEM Services (Evergreen)

General Dynamics Information Technology, Inc. • St. Louis (MO)

On-site
USD 128,000 - 173,000
Medical plan with HSA
Dental plan
Vision plan
+3
Cyber Threat Intelligence (Fusion) Analyst - TS/SCI with Polygraph
Cyber Threat Intelligence (Fusion) Analyst - TS/SCI with Polygraph

General Dynamics Information Technology • Reston (VA)

On-site
USD 145,000 - 196,000
Cyber Analyst Principal - TS/SCI with Polygraph
Cyber Analyst Principal - TS/SCI with Polygraph

General Dynamics Information Technology, Inc. • McLean (VA)

On-site
USD 170,000 - 230,000