Cybersecurity Service Provider/Incident Response (CSSP/IR) Analyst

Bespoke Corps LLC

Arlington (VA)

On-site

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A cybersecurity firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site support for DoD customers, possessing technical skills in intrusion detection and prevention, and will have a BS in a relevant field. Responsibilities include cybersecurity intelligence research, collaboration, and reporting on threats. Candidates with a current TS security clearance and CEH certification are preferred.

Qualifications

  • Minimum 3 years of CSSP/IR experience in a DoD environment.
  • Current TS security clearance with SCI access or recent SCI access.
  • Active CEH certification and DoD 8570 IAT-II certification.

Responsibilities

  • Provide on-site CSSP/IR support to a DoD customer.
  • Conduct cybersecurity intelligence research and analysis.
  • Create detailed reports on attack trends and mitigations.

Skills

Intrusion detection/prevention
Cybersecurity tools administration
Strong verbal and written communication
Team collaboration
Technical report writing

Education

BS in computer science, engineering, or related field

Tools

SIEM tools
Yara
Snort

Job description

Overview

Bespoke Corps, LLC is looking for a qualified candidate to provide on-site support to one of our valued Department of Defense (DoD) customers. We are seeking a (CSSP/IR) specialist with specific skills in intrusion detection/prevention and cybersecurity tools administration. The specialist will perform full-spectrum CSSP/IR in accordance with DoD and NIST policy and process frameworks, and open and closed source cybersecurity intelligence (fusion) research and analysis. The ideal candidate is self-motivated, thrives in team-based work environments, and has strong verbal and written communication skills. The candidate will demonstrate experience supporting DoD/US Government organizations and agencies. Additionally, the candidate must support rotational weekend and holiday workdays.

Responsibilities
  • Provide on-site CSSP/IR support to a DoD customer.
  • Perform full-spectrum CSSP/IR in accordance with DoD and NIST policy and process frameworks.
  • Conduct open and closed source cybersecurity intelligence research and analysis.
  • Collaborate within a team-based environment and communicate effectively with stakeholders at all levels.
Demonstrated Experience (Minimum 3 years)
  • Strong technical skills and a firm and thorough understanding of CSSP/IR tools (e.g., SIEM tools) and ability to identify new and emerging threats.
  • Providing detailed triage of CSSP/IR incidents including implementing intrusion detection and prevention signatures.
  • Conducting active hunting for network intrusions involving manual packet capture analysis, DNS log review, open source, and closed source intel analysis.
  • Knowledge of Advanced Persistent Threats (APT), network attack patterns, detection techniques, trends, threat actors, and defense strategies.
  • Creating detailed reports on attack trends and recommended mitigations suitable for senior leaders and technical audiences.
  • Extensive experience creating detailed reports pertaining to various cybersecurity-related concerns or events.
  • Gathering, analyzing, and implementing defenses against Indicators of Compromise (IoCs) from open forums, closed forums, mailing lists, and directed research.
  • Ability to collaborate well within a team construct.
Other Skills/Qualifications
  • Current TS security clearance with current SCI access, or have been granted SCI access within the past 24 months.
  • Obtain an active CEH certification.
  • DoD 8570 IAT-II or above professional certification (e.g., Security+, GCIH).
  • Knowledge and experience categorizing CSSP/IR incidents with CJCSM 6510 Incident Response Categories.
  • Experience with creating and implementing custom Yara, Snort, and ESS rules.
  • Knowledge of scripting languages such as Python is a plus.
Academic Qualifications

BS in computer science, engineering, mathematics, business or related field of study from an accredited institution.

Work Demands and Environment

The work environment and physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to talk or hear. The employee is frequently required, sometimes for extended periods, to walk, stand, or sit. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets, and fax machines. The employee must occasionally lift and/or move small or large objects up to 50 pounds. Specific vision abilities required by this job include close vision, distance vision, color vision, depth perception, and the ability to adjust focus.

Travel

There is no travel expected for this position.

Job Location

Arlington, VA

Weekly Schedule

Monday – Friday, 7:00am-3:00pm (Occasional Rotational Holiday Support).

Candidate Type

W-2 candidates are welcome to apply (please include a current version of your resume).

CYBERSECURITY SERVICE PROVIDER/INCIDENT RESPONSE ANALYST
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CSSP/IR Analyst
CSSP/IR Analyst

Bespoke Corps LLC • Ashburn (VA)

On-site
USD 80,000 - 110,000
Cyber Security Operations Jr Analyst
Cyber Security Operations Jr Analyst

Spahrsolutionsgroup • Fort Belvoir (VA)

On-site
USD 90,000 - 120,000
Computer Network Defense Analyst
Computer Network Defense Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
Incident Response Team Lead
Incident Response Team Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Signature Federal Systems , LLC • Aurora (CO)

On-site
USD 110,000 - 150,000
Cybersecurity Service Provider (CSSP) Operations Team Lead
Cybersecurity Service Provider (CSSP) Operations Team Lead

Cwsc • Indianapolis (IN)

On-site
USD 140,000 - 190,000
Lead Cyber Defense Incident Responder TS/SCI
Lead Cyber Defense Incident Responder TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 165,000 - 180,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Cyber Incident Responder (24x7 Days)
Cyber Incident Responder (24x7 Days)

ASRC Federal • Virginia (MN)

On-site
USD 110,000 - 150,000
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC

Peraton • North Carolina

On-site
USD 130,000 - 170,000