Cyber Network Defense Analyst III

NewGen Technologies

Arlington (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NewGen Technologies seeks Cyber Network Defense Analysts to support national security missions with remote and on-site advanced technical assistance. The team handles DFIR, proactive hunting, incident response, and forensic data analysis to mitigate cyber threats.

Qualified candidates will have 5+ years in network investigations, deep CND knowledge, TCP/IP proficiency, and experience with SIEMs (Splunk) and Wireshark. U.S. citizenship and ability to obtain DHS suitability are required.

Qualifications

  • Minimum 5+ years of directly relevant experience in network investigations.
  • In-depth knowledge of CND policies, procedures and regulations.
  • Strong understanding of TCP/IP and common protocols (HTTP/S, DNS, SSH, SMTP, SMB, NFS).
  • Experience with network topologies (DMZs, WANs) and Wireshark.

Responsibilities

  • Assist Government lead in coordinating teams during preliminary incident response investigations.
  • Interface with the customer on-site as needed.
  • Determine courses of action in response to anomalous network activity.
  • Assess network topology and device configurations for security risks.
  • Collect network intrusion artifacts (pcap, domains, URIs, certificates) for mitigation.
  • Analyze malicious activity to identify exploitation methods and effects.
  • Collect device integrity data and check for tampering.
  • Support real-time CND incident handling (forensics, correlation, remediation).

Skills

Network investigations
CND knowledge
MITRE ATT&CK
Wireshark
Team collaboration

Education

BS in CS/Cyber Security/CE or related (or HS Diploma with 7-9 yrs exp)

Tools

Splunk
TCP/IP analysis

Job description

Our Partner provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line response for digital forensics/incident response (DFIR) and proactively hunting for malicious cyber activity. They are seeking Cyber Network Defense Analysts (CNDA) to support this critical customer mission.

Responsibilities
  • Assistthe Government lead in coordinating teams in preliminary incident response investigations
  • Assistthe Government lead with interfacing with the customer while on site
  • Determineappropriate courses of actions in response to identified and analyses anomalous network activity
  • Assessnetwork topology and device configurations identifying critical security concerns and providingsecurity best practice recommendations
  • Collectnetwork intrusion artifacts (e.g., PCAP, domains, URI’s, certificates, etc.) and usediscovered data to enable mitigation of potential Computer Network Defense incidents
  • Analyzeidentified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Collectnetwork device integrity data and analyze for signs of tampering or compromise
  • Assistwith real-time CND incident handling (i.e., forensic collections, intrusion correlation and tracking, threat analysis, and advising on system remediation) tasks to support onsite engagements
Requirements
  • U.S. Citizenship
  • Active TS/SCI Clearance
  • Must be able to obtain DHS Suitability
  • BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 7-9 years of network investigations experience
  • 5+ years of directly relevant experience in network investigations
  • In depth knowledge of CND policies, procedures and regulations
  • In depth knowledge of TCP/IP protocols
  • In depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.
  • In depth knowledge and experience of Wifi networking
  • In depth knowledge and experience of network topologies - DMZ’s, WAN’s, etc.
  • Substantial knowledge of Splunk (or other SIEM’s)
  • Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
  • Knowledge of Computer Network Defense policies, procedures, and regulations
  • Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
  • Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
  • Ability to identify and analyze anomalies in network traffic using metadata
  • Experience with reconstructing a malicious attack or activity based on network traffic
  • Experience examining network topologies to understand data flows through the network
  • Must be able to work collaboratively across physical locations
Desired Skills
  • Substantial knowledge of network device integrity concepts and methodologies
  • Proficiency with network analysis software (e.g. Wireshark)
  • Proficiency with carving and extracting information from PCAP data
  • Proficiency with non-traditional network traffic (e.g. Command and Control)
  • Proficiency with preserving evidence integrity according to standard operating procedures or national standards
  • Proficiency with virtualized environments
Desired Certifications
  • DoD 8140.01 IAT Level II, IASAE II, CSSP Analyst, GCIA, GCIH, CSSP Analyst/CSSP Incident Responder, CEH
  • SANS GIAC GNFA preferred
About Us

For more than 20 years, NewGen Technologies has solved our clients’ toughest IT challenges with integrity, security, and outstanding service by delivering both technology and talent. We have helped secure borders, have used artificial intelligence (AI) to fight terror, aided the identification of criminals, and have helped to prevent crime through the introduction of biometrics.Our team of Highly Cleared Specialists have hard-to-find skills and expertise in a wide spectrum of technologies to provide solutions that transform business processes and solve problems of national significance. #CJ

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Computer Network Defense Analyst (CNDA) III
Computer Network Defense Analyst (CNDA) III

NewGen Technologies • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Host Based Systems Analyst II
Host Based Systems Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 140,000
Network Based Systems Analyst III
Network Based Systems Analyst III

Base One Technologies • Arlington (VA)

Hybrid
USD 90,000 - 120,000
Network Forensics Cybersecurity Analyst
Network Forensics Cybersecurity Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 120,000 - 160,000
Network Based System Analyst
Network Based System Analyst

Node.Digital LLC • Arlington (VA)

Hybrid
USD 90,000 - 120,000
Medical
Dental
Vision
+3
Network Based Systems Analyst III
Network Based Systems Analyst III

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 150,000
Host Based Systems Analyst II
Host Based Systems Analyst II

Solutions³ LLC • Arlington (VA)

On-site
USD 120,000 - 180,000
Network Based Systems Analyst - II
Network Based Systems Analyst - II

Beyond SOF • Arlington (VA)

Hybrid
USD 110,000 - 160,000
Network Based Systems Analyst II
Network Based Systems Analyst II

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 170,000
Cyber Network Defense Analysts (CNDA)
Cyber Network Defense Analysts (CNDA)

bcmcllc • Arlington (VA)

On-site
USD 90,000 - 120,000
Employer paid medical, dental, and vision coverages
401(k) with company match
11 standard holidays & 3 weeks annual leave