Cyber Network Defense Analyst

UIC Arctic Response Services, LLC

Bath Township (OH)

On-site

USD 85,000 - 115,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bowhead seeks a Cybersecurity Network Defense Analyst to join our team in Dayton, OH. The analyst analyzes events from IDS alerts, firewalls, and logs to mitigate threats and provide 24x7x365 incident handling for subscribers.

You will operate in the AS&W division, monitor ISCM platforms, correlate data, and develop countermeasures. Must have secret clearance, bachelor's degree, 2+ years IDS experience, DOD 8570 IAT II and CSSP qualifications.

Qualifications

  • Bachelor's degree or equivalent experience.
  • At least 2 years intrusion detection experience.
  • At least 2 years IT and/or System Administration experience and 2 years Information Security experience.
  • DoD 8570 IAT Level II minimally.
  • DoD 8570 CSSP-Analyst or CSSP-Incident Responder certifications.
  • Ability to earn DoD 8570 computing environment certification within 6 months.
  • Experience with network hardware devices and ACL/Firewall/Router configuration.
  • Strong knowledge of computer security concepts and communication to a wide audience.
  • Complete Joint Qualification Requirement training within 180 days of hire.

Responsibilities

  • Receive and distribute AS&W information.
  • Conduct AS&W activities to develop appropriate response.
  • Coordinate AS&W information to aid analysis of alerts.
  • Analyze IDS alerts to identify unauthorized or anomalous activity.
  • Document and report unauthorized activity/attacks with IOCs.
  • Propose countermeasures to mitigate threats on the DODIN.
  • Monitor ISCM platform for cyber intrusions and insider threats.
  • Collect intrusion artifacts for analysis and sharing with Warning Intelligence.
  • Correlate incidents to identify vulnerabilities and remediation steps.
  • Notify subscribers of incidents and assess mission impact.
  • Provide 24/7 incident handling and analysis capability.
  • Maintain operations log of all reportable cyber events/incidents.
  • Analyze events to identify incidents and categorize them.

Skills

Intrusion detection
Network security
ISCM monitoring
Communication

Education

Bachelor's degree or equivalent experience

Tools

Firewall configuration

Job description

Overview

Bowhead seeks a Cybersecurity Network Defense Analyst to join our team in Dayton, OH. The Cybersecurity Network Defense Analyst uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats. They provide on-site 24x7x365 operational support in the form of event/incident handling and analysis capability to cybersecurity service subscribers. These highly skilled individuals will work in various capacities alongside Warning Intelligence Analysts and Engineers.

The Cybersecurity Network Defense Analyst will work in the Attack Sensing and Warning (AS&W) division which senses changes in subscriber networks through comparison to established baselines and the fusion/integration of closed and open source intelligence to enhance sensing capability. They will perform the analysis of disparate data sources to form a cohesive view of the current cyber security state. They will characterize and analyze network traffic to identify anomalous activity and potential threats to network resources.

These positions are in a 24x7x365 Cybersecurity environment and selected candidates must be able to work 12 hour night shifts.

Responsibilities
  • Receive and distribute AS&W information
  • Conduct AS&W activities to develop appropriate response (receives and archive task orders, directives, and other required actions, and maintain internal and external source location information)
  • Coordinate AS&W information from other sources to aid in analysis of alerts
  • Analyze the Intrusion Detection System alerts to identify unauthorized or anomalous activity
  • Identify, documents, and reports unauthorized activity/attacks (including IP addresses and ports, attack vector, and attack timeframe) in all incidents and reports per HPCMP CSSP sops
  • Take action, if appropriate, to prevent or mitigate potential impact to the DODIN based on cyber threats, and develop and distribute countermeasures and interim guidance to prevent or mitigate threats and/or attacks on DODIN
  • Monitor a platform capable of performing information security continuous monitoring (ISCM) for the purposes of detecting cyber intrusions, attacks, anomalous behavior, and possible insider threats
  • Collect intrusion artifacts (e.g., source code, malware, and trojans)
  • Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation
  • Report incidents and events within proper channels and within timelines identified in the CJCSM 6510.01B
  • Provide a 24/7x365 event/incident handling and analysis capability
  • Provide operations log accessible to personnel documenting all mandated reportable cyber events/incidents
  • Analyze detected cyber events to identify incidents
  • Categorize and characterize cyber incidents
  • Notify affected Subscribers of cyber incidents and collect assessments of mission impact for the loss of the system during the incident response process
  • Analyze cyber incidents to develop specific responses
  • Distribute tailored countermeasures or interim guidance to Subscribers to eradicate and prevent cyber incidents across all subscribers
  • Perform forensic analysis of systems and malware in cases where subscribers lack the capability and ensure relevant IOCs are shared with Warning Intelligence
  • Mitigate operational and/or technical impact due to cyber incidents
  • Contain the spread of malware to prevent further damage to IT systems through detection, analysis, and execution of containment measures
Qualifications
  • Must possess Bachelor's degree or equivalent experience
  • Must have at least 2 years intrusion detection experience
  • Must have at least 2 years relevant IT and/or System administrator experience and 2 years relevant Information Security experience
  • Must have the certifications for DOD 8570 IAT Level II minimally
  • Must have the certifications for DOD 8570 CSSP-Analyst or CSSP-Incident Responder
  • Must have the ability to earn DoD 8570 computing environment certification within 6 months
  • Understanding of network hardware devices and experience configuring Access Control Lists or other Firewall or Router configuration experience
  • Ability to demonstrate strong knowledge of computer security concepts
  • Ability to communicate effectively, interpret regulatory guidance and identified vulnerabilities to a wide audience
  • Advanced knowledge of network technologies and protocols
  • Advanced understanding of current threats and trends present in the Information Security and Technology field
  • Must complete the specified Joint Qualification Requirement training within 180 days of date of hire, unless otherwise specified

SECURITY CLEARANCE REQUIRED: Must have an in-scope secret clearance. US Citizenship is a requirement for Secret clearance at this location.

Physical Demands:
  • Must be able to lift up to 25 pounds
  • Must be able to stand and walk for prolonged amounts of time
  • Must be able to twist, bend and squat periodically

#LI-MN1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Defense Analyst – 12-Hour Night Shifts, 24/7 Response
Cyber Defense Analyst – 12-Hour Night Shifts, 24/7 Response

UIC Arctic Response Services, LLC • Bath Township (OH)

On-site
USD 85,000 - 115,000
Cyber Security Operations Jr Analyst
Cyber Security Operations Jr Analyst

Spahrsolutionsgroup • Fort Belvoir (VA)

On-site
USD 90,000 - 120,000
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 130,000
401(k)
401(k) matching
Dental insurance
+6
Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

On-site
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
SOC Operations Analyst - 175027
SOC Operations Analyst - 175027

Piper Companies • Fort Meade (MD)

On-site
USD 125,000 - 145,000
Cyber Defense Analyst
Cyber Defense Analyst

G2IT, LLC. • Suitland (MD)

On-site
USD 120,000 - 180,000
Cyber Network Defense Analyst
Cyber Network Defense Analyst

Base One Technologies • Washington

On-site
USD 65,000 - 85,000
Cyber Defense Analyst Suitland, MD Top Secret/SCI R-00190180
Cyber Defense Analyst Suitland, MD Top Secret/SCI R-00190180

ESR Healthcare • Suitland (MD)

On-site
USD 120,000 - 160,000
Referral bonus $2,000
Cyber Network Defense Analyst
Cyber Network Defense Analyst

Base One Technologies • Springfield (MA), Northern (KY)

On-site
USD 55,000 - 85,000
Network Based Systems Analyst - II
Network Based Systems Analyst - II

Beyond SOF • Arlington (VA)

On-site
USD 110,000 - 160,000