Cyber Network Defense Analyst (CNDA)

bcmcllc

Arlington (VA)

Hybrid

USD 110,000 - 170,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Extremely competitive salary
Employer paid health, dental, & vision
Employer paid life, STD & LTD
401k with company match
FSA for dependents
Holiday & annual leave

Job summary

BCMC provides remote and onsite advanced cybersecurity support, including incident response and DFIR activities. We seek a CNDA to support this critical mission, with duties spanning coordination, data collection, threat analysis, and on-site remediation guidance.

Requirements include U.S. citizenship, TS/SCI clearance, and 5+ years in network investigations. DoD certifications and experience with SIEMs like Splunk are desirable. Relocation and travel may be involved.

Qualifications

  • U.S. citizenship is required.
  • Active TS/SCI clearance required.
  • Ability to obtain DHS suitability.
  • 5+ years of direct experience in network investigations.
  • Deep knowledge of CND policies, procedures, and regulations.
  • Strong understanding of TCP/IP protocols.
  • Familiarity with common protocols (ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS).
  • Experience with wifi networking.
  • Experience with network topologies (DMZs, WANs).
  • Proficient with Splunk or similar SIEMs.
  • Knowledge of MITRE ATT&CK framework.
  • Understanding of defense-in-depth and attack stages in network security.
  • Ability to analyze network traffic and identify anomalies.
  • Experience reconstructing attacks from network data.
  • Ability to work across physical locations.

Responsibilities

  • Assist Government lead in coordinating incident response investigations.
  • Interface with the customer on site as needed.
  • Determine courses of action in response to network anomalies.
  • Assess topology and configurations to identify security concerns.
  • Collect intrusion artifacts (PCAP, domains, URI, certificates) for mitigation.
  • Analyze malicious activity to identify exploitation methods and effects.
  • Collect device integrity data to detect tampering.
  • Support on-site real-time CND incident handling tasks.

Skills

Citizenship
TS/SCI clearance
DHS suitability
Experience in network investigations
CND policies & regulations
TCP/IP protocols
Common protocols (ICMP, HTTP/S, DNS, S
WiFi networking
Network topologies (DMZ, WAN)
Splunk/SIEM
MITRE ATT&CK knowledge
Defense-in-depth concepts
Analyze network traffic
Anomaly detection in traffic
Reconstructing attacks from traffic
Data flow analysis in networks
Collaborative work across locations

Education

BS in CS/Cyber Security/Computer Eng
HS Diploma + 7-9 years exp

Tools

Wireshark

Job description

BCMC provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line response for digital forensics/incident response (DFIR) and proactively hunting for malicious cyber activity. We are seeking Cyber Network Defense Analysts (CNDA) to support this critical customer mission.

Responsibilities
  • Assists the Government lead in coordinating teams in preliminary incident response investigations
  • Assists the Government lead with interfacing with the customer while on site
  • Determines appropriate courses of actions in response to identified and analyses anomalous network activity
  • Assesses network topology and device configurations identifying critical security concerns and providing security best practice recommendations
  • Collects network intrusion artifacts (e.g., PCAP, domains, URI’s, certificates, etc.) and uses discovered data to enable mitigation of potential Computer Network Defense incidents
  • Analyzes identified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Collects network device integrity data and analyze for signs of tampering or compromise
  • Assists with real-time CND incident handling (i.e., forensic collections, intrusion correlation and tracking, threat analysis, and advising on system remediation) tasks to support onsite engagements
Required Skills
  • U.S. Citizenship
  • Must have an active TS/SCI clearance
  • Must be able to obtain DHS Suitability
  • 5+ years of directly relevant experience in network investigations
  • In depth knowledge of CND policies, procedures and regulations
  • In depth knowledge of TCP/IP protocols
  • In depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.
  • In depth knowledge and experience of Wifi networking
  • In depth knowledge and experience of network topologies - DMZ’s, WAN’s, etc.
  • Substantial knowledge of Splunk (or other SIEM’s)
  • Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
  • Knowledge of Computer Network Defense policies, procedures, and regulations
  • Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
  • Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
  • Ability to identify and analyze anomalies in network traffic using metadata
  • Experience with reconstructing a malicious attack or activity based on network traffic
  • Experience examining network topologies to understand data flows through the network
  • Must be able to work collaboratively across physical locations
Desired Skills
  • Substantial knowledge of network device integrity concepts and methodologies
  • Proficiency with network analysis software (e.g. Wireshark)
  • Proficiency with carving and extracting information from PCAP data
  • Proficiency with non-traditional network traffic (e.g. Command and Control)
  • Proficiency with preserving evidence integrity according to standard operating procedures or national standards
  • Proficiency with virtualized environments
Required Education

BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 7-9 years of network investigations experience.

Desired Certifications
  • DoD 8140.01 IAT Level II, IASAE II, CSSP Analyst, GCIA, GCIH, CSSP Analyst/CSSP Incident Responder, CEH
  • SANS GIAC GNFA preferred
Our Company Overview

Business Computers Management Consulting Group, LLC (BCMC) is a small business specializing in Information Technology (IT), Cybersecurity, Information Assurance (IA), SOA, Big Data Management, Program Management, and more for Federal, State, and Local agencies. We possess highly skilled engineers, providing innovative solutions backed by strong past performances. We are ISO 9001:2015, ISO 27001:2013, 20000:2018, and CMMI L3 certified and registered promising highest quality and services to all of our clients.

Benefits
  • Extremely competitive salary
  • 95% employer paid for employee medical, dental, & vision coverages
  • 100% employer paid for employee life, STD & LTD disability coverages
  • 401k with company match and profit sharing
  • Flexible Spending Account (FSA) for dependent & health care
  • 11standard holidays & 3 weeks of annual leave
  • ESS 3205
  • ESS 3249
  • ESS 3597
  • Network Based Systems Analyst - III - NBA03
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Based System Analyst
Network Based System Analyst

Node.Digital LLC • Arlington (VA)

Hybrid
USD 90,000 - 120,000
Medical
Dental
Vision
+3
Cyber Network Defense Analyst III
Cyber Network Defense Analyst III

NewGen Technologies • Arlington (VA)

On-site
USD 120,000 - 160,000
Cyber Network Defense Analysts (CNDA)
Cyber Network Defense Analysts (CNDA)

bcmcllc • Arlington (VA)

On-site
USD 90,000 - 120,000
Employer paid medical, dental, and vision coverages
401(k) with company match
11 standard holidays & 3 weeks annual leave
Network Based Systems Analyst III
Network Based Systems Analyst III

Base One Technologies • Arlington (VA)

Hybrid
USD 90,000 - 120,000
Host Based Systems Analyst II
Host Based Systems Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 140,000
Network Based Systems Analyst III
Network Based Systems Analyst III

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 150,000
Remote Cyber Network Defense Analyst & Incident Responder
Remote Cyber Network Defense Analyst & Incident Responder

bcmcllc • Arlington (VA)

Hybrid
USD 110,000 - 170,000
Extremely competitive salary
Employer paid health, dental, & vision
Employer paid life, STD & LTD
+3
Network Based Systems Analyst II
Network Based Systems Analyst II

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 170,000
Network Based Systems Analyst - II
Network Based Systems Analyst - II

Beyond SOF • Arlington (VA)

Hybrid
USD 110,000 - 160,000
Host Based Systems Analyst II
Host Based Systems Analyst II

Solutions³ LLC • Arlington (VA)

On-site
USD 120,000 - 180,000