Cyber Hunt Analyst

Synergy ECP

Columbia (MD)

On-site

USD 120,000 - 160,000

Full time

45 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Synergy ECP in Columbia, MD seeks a Tier III Cyber Analyst to discover and characterize network anomalies, monitor activities across networks, and generate actionable reports for the Reporting Team Lead. Candidates should have TS/SCI clearance and U.S.

citizenship, with experience in threat intelligence, incident response, Windows/Linux, and scripting in PowerShell/Python/Java. The role requires strong analytical abilities, familiarity with EnCase or open-source forensics tools, and the ability

Qualifications

  • Tier III Analyst experience with network analytics, incident investigations, reverse engineering and malware analysis.
  • Strong comfort with IPv4, TCP/IP, RFC data, and low-level networking.
  • Cloud analytics experience and Hadoop/PIG scripting is a plus.
  • Familiarity with SIEMs and scripting to extract data from security tools.
  • Experience with Windows and Linux operating systems.
  • PowerShell, Python or Java scripting experience.

Responsibilities

  • Discover and characterize network and platform anomalies and report findings to the team lead.
  • Monitor, identify and analyze anomalous network activities across multiple networks.
  • Conduct multi-source threat analyses and generate reports on incidents.
  • Integrate Cyber Threat Intelligence to inform customers about threats and vulnerabilities.
  • Monitor adversarial capabilities, exploits, and mitigations through all-source research.
  • Identify gaps in data (netflow, syslog) affecting customer mission and posture.
  • Develop, document and synchronize signatures and rules across IDS and firewalls.

Job description

Synergy ECP is a Service-Disabled Veteran-Owned Small Business SD(VOSB) that was formed in July 2007 with Headquarters in Columbia, MD and is made up of talented, dedicated staff to provide a broad range of services to the defense, intelligence and health care industries.

In an ultra-competitive environment, Synergy ECP has thrived by adhering to our name, making sure excellence is displayed by our Employees, to our Customers and by Improving Performance (ECP).

It’s what sets us apart, enabling us to be an autonomous yet agile business that delivers huge results - showing we’re ready to meet our customers’ evolving demands.

Synergy ECP has earned a client list that includes numerous Fortune 100 companies, in addition to multiple branches of the US government and military services.

Synergy ECP is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, creed, religion, national origin, sex, sexual orientation, gender identity and expression, age, disability, veteran status, or any other protected class.

Clearance Required: TS/SCI
Other Requirements: U.S. Citizenship
Description
  • Discover and characterize network and platform anomalies to include cross domain violations and submit findings to the Reporting Team Lead for analysis and report generation
  • Monitor, identify and analyze anomalous network activities on various networks
  • Conduct multi-source threat analyses to examine host behaviors and network traffic for high priority malicious attacks, anomalous traffic, or other incidents of interest, as well as generate reports as appropriate
  • Integrate Cyber Threat Intelligence to inform customer on newly discovered threats and vulnerabilities associated with the technologies used in the enterprise for the purpose of developing hunt analytics. Any shareable vulnerability information will be made available for traditional tipping and alerting to the broader customer base
  • Monitor adversarial capabilities, exploits, vulnerabilities, mitigation techniques, and best practices information and guidance through all-source research
  • Identify areas for deeper dive analysis of threat and vulnerabilities
  • Examine network topologies to understand data flows through networks and provide mechanisms to tip countermeasures
  • Employ analysis and tools to discover new threat actors
  • Implement the applicable reporting guidelines outlined in applicable directives and guidance
  • Conduct research/planning for strategy development in response to real-time operational requirements
  • Identify and document gaps in all data (e.g., netflow, syslog, etc.) that affect the customer mission in order to determine how to better posture mission capabilities
  • Develop, document and synchronize the recommendations and the tasking of signature and rule sets across ail sensors e.g., IDS, FW, etc. used by the customer
  • Knowledge of systems configuration and management of firewalls, IDS, servers and workstations
  • Experience with Red Team and/or Penetration Testing
  • Knowledge of incident categories, incident responses, and timelines for responses
  • Experience collecting data and reporting results; handling and escalating security issues or emergency situations appropriately; providing incident response capabilities to isolate and mitigate threats to maintain confidentiality, integrity, and availability for protected data
  • Demonstrated experience supporting external investigations
  • Familiarity with software development and network operations concepts and methodologies
  • Advanced knowledge of information systems security concepts and technologies; network architecture; general database concepts; document management; hardware and software troubleshooting; intrusion tools; and computer forensic tools such as EnCase and open source alternatives
  • Experience with the Windows and Linux operating systems
  • Experience with investigating malicious code
  • Experience with scripting (PowerShell, Python, Java)
Desired Skills
  • Tier III Analyst experience, Network Analytics, Incident Investigations, Reverse Engineering and Malware Analysis, Task Prioritization
  • Strong comfort level with IPv4, TCP/IP, and RFC data, low level networking and protocols, TCP/UDP Ports for Apps, and understanding of what is normal/abnormal endpoint and on-wire activity
  • Experience in Cloud Environment using cloud analytics and PIG scripts/jobs to present data and using the Hadoop Distributed File System
  • Use of SIEMs or scripting to pull data into usable formats. Notification sources are Antivirus, HIDS, NIDS, IPS, and Firewalls
  • Experience with Wireless and SCADA are a plus
  • Ability to work extremely well under pressure while maintaining a professional image and approach
  • Exceptional information analysis abilities; ability to perform independent analysis and distill relevant findings and root cause
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Intrusion Analyst
Intrusion Analyst

Synergy ECP • Columbia (MD)

On-site
USD 90,000 - 130,000
Advanced Cybersecurity Analytics
Advanced Cybersecurity Analytics

Abile Group, Inc • St. Louis (MO)

On-site
USD 80,000 - 120,000
Advanced Cybersecurity Analytics
Advanced Cybersecurity Analytics

Abile Group, LLC • St. Louis (MO)

On-site
USD 90,000 - 120,000
Cyber Threat Hunter - TS/SCI
Cyber Threat Hunter - TS/SCI

Synergy ECP • Columbia (MD)

On-site
USD 120,000 - 160,000
Cyber Data Analysis Engineer
Cyber Data Analysis Engineer

Abile Group, Inc • Springfield (VA)

On-site
USD 80,000 - 110,000
Network Based Systems Analyst II
Network Based Systems Analyst II

Solutions³ LLC • Arlington (VA)

On-site
USD 95,000 - 130,000
Cyber Data Analysis Engineer
Cyber Data Analysis Engineer

Abile Group, Inc • St. Louis (MO)

On-site
USD 85,000 - 115,000
Network Based Systems Analyst IV
Network Based Systems Analyst IV

Solutions³ LLC • Arlington (VA)

On-site
USD 140,000 - 180,000
Cyber Analyst
Cyber Analyst

BWM Outcomes • Manassas Park (VA)

On-site
USD 85,000 - 110,000
Network Based Systems Analyst II
Network Based Systems Analyst II

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 170,000