Network Intrusion Specialist
Booz Allen Hamilton has been at the forefront of strategy and technology for more than 100 years Today, the firm provides management and technology consulting and engineering services to leading Fortune 500 corporations, governments, and not-for-profits across the globe. Booz Allen partners with public and private sector clients to solve their most difficult challenges through a combination of consulting, analytics, mission operations, technology, systems delivery, cybersecurity, engineering and innovation expertise.Network Intrusion Specialist
Apply experience with network security principles and technologies to analyzing Packet Capture (PCAP), Netflow, Firewall/IDS alerts, and system logs in support of investigations and operations. Leverage open source tools to analyze common network traffic, including HTTP, DNS, FTP, and various Web application protocols to detect anomalies. Analyze anomalies by using knowledge of network security devices, including firewalls, IDS, IPS, and proxy and Web service security configurations to detect common exploits, indicators of compromise, and attack patterns and provide detailed documentation of findings.
-3 years of experience with conducting PCAP analysis
-2 years of experience with using TCPDUMP
-Experience with Linux and open source tools
-HS diploma or GED
-One or more of the following certifications: Certified Ethical Hacker (CEH), Security+, Certified Information Systems Security Professional (CISSP), GIAC Certified Intrusion Analysts (GCIAs), GIAC Certified Incident Handler (GCIH), or GIAC Certified Forensic Analyst (GCFA)
-Experience with data management
-Experience with using Splunk
-Experience with Linux scripting and command line tools such as awk, cut, or grep
-Experience with coding in one programming language, including Python, PHP, or similar
-EnCase Certified Forensic Examiner (EnCE), EnCase Certified eDiscovery Practitioner (EnCEP), Certified Forensic Security Responder (CFSR), GIAC Reverse Engineering Malware (GREM), Certified Reverse Engineering Analyst (CREA), Wireshark Certified Network Analyst (WCNA), Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), or Network+ Certification preferred
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required.
Integrating a full range of consulting capabilities, Booz Allen is the one firm that helps clients solve their toughest problems by their side to help them achieve their missions. Booz Allen is committed to delivering results that endure.
We are proud of our diverse environment, EOE, M/F/Disability/Vet.