Senior Fusion Analyst with Security Clearance

Employer
Leidos
Location
Alexandria, VA
Posted
Sep 25, 2022
Closes
Oct 02, 2022
Ref
669111731
Hours
Full Time
R-00093880 Description Job Description: Looking for an exciting new opportunity? Leidos is looking to hire a Senior Cyber Threat Analyst. This position will support the Joint Service Provider (JSP) Defensive Cyber Operations (DCO) organization with Cyber Threat Intelligence products, management of adversary indicators of compromise, tracking and monitoring of adversary tactics, techniques, and procedures, and leading cyber threat intelligence collaboration internally and externally to JSP. This role will be based onsite at the Mark Center in Alexandria, VA. Some remote work may be allowed. An active TS/SCI security clearance is required prior to start. PRIMARY RESPONSIBILITIES: * Implement the core Threat Intelligence concepts (ex. Cyber Kill Chain, MITRE ATT&CK, DoDCAR). * Lead creation and review of reporting on new or emerging threats and threat vectors * Mentor and train more junior fusion analysts on team tactics, techniques, and procedures. * Utilize SIEM technologies to correlate security events and logs and identify threats. * Coordinate with SOC and network security team to incorporate threat intelligence into countermeasures to detect and prevent intrusions and malware infections. * Identify threat actor tactics, techniques and procedures and work with countermeasures team to develops custom signatures, blocks, and correlation logic to detect and/or mitigate adversary activity. * Understand and employ the MITRE ATT&CK Matrix. * Understand concepts of log and packet analysis. * Handle and organize disparate data about detections, attacks, and attackers * Employ discovery techniques and vetting of new intelligence. * Create Situational Awareness Reports and Threat Briefs * Deliver threat briefs to Senior JSP Leadership * Draft and maintain process documentation for fusion team Required Skills: * 8570 IAT III and CSSP Analyst certifications required prior to start. * Must possess an active TS/SCI security clearance. * 12+ years of cyber security experience * 2+ years of cyber threat intelligence experience * Bachelor s Degree of Science in IT or Engineering field; additional years of experience may be substituted in lieu of a degree. * Very familiar with computer defense technologies spanning endpoint, network, and open source * Significant experience leveraging Cyber Kill Chain, Diamond Model, and/or MITRE ATT&CK frameworks. * Threat actor TTP and indicator identification using large data sources. * Possess a strong understanding how enterprise endpoint and network components contribute to Threat Intelligence and adversary detection. * Strong written and verbal communication skills and ability to brief senior JSP leadership on cyber threat activity and cybersecurity trends. Preferred Skills: * Experience working for a Cybersecurity Service Provider (CSSP) or Security Operations Center (SOC) * Experience using a prominent Security Information and Event Management (SIEM) (ex. Splunk, Elasticsearch, ArcSight, QRadar) * Custom signature development experience. * Packet analysis experience. * Leadership experience. Pay Range: Pay Range $113,100.00 - $174,000.00 - $234,900.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.