Cyber Malware Analyst

Arlington, VA
Feb 20, 2021
Feb 24, 2021
Full Time
Job DescriptionRaytheon Intelligence and Space (RIS) - Cybersecurity, Training & Services (CTS) has an immediate job opening for a Cyber Malware Analyst to support a US Federal Agency contract to enable mission accomplishment by having experience understanding and analyzing cyber tools and malware samples in support of active investigations, creating cyber intelligence products. The analyst will utilize tools, sources, methods and data to provide context about the evolving threat landscape. The successful candidate must have the ability to interpret and analyze large, ambiguous data sets and experience in writing analysis reports.Work Location: National Capital Region (Rosslyn, VA)Job Description:Resolves highly complex malware and intrusion issues using computer host analysis, forensics, and reverse engineering. Discovers, analyzes, diagnoses, and reports on malware events, files and network intrusion and vulnerability issues. Recommends counter measures to malware and other malicious type code and applications that exploit customer communication systems. Conducts reverse engineering for known and suspected malware files. Develops analysis and make recommendations for the purchase of hardware and or software that will mitigate malware intrusions. Develops policies and procedures to investigate malware incidents for the entire computer network. Assists in the development and delivery of malware security awareness products and briefings.Job Responsibilities:Shall perform specific activities that include, but not limited to the following:Provide analysis support 24x7x365Render technical assistance for criminal investigations and non-security related operational events as neededContribute input to the Cyber Security Daily (CSD)Conduct advance analysis and recommend remediation steps for cyber security events and incidentsRequired Skills:Experience with malware analysis and reverse engineering, network analysis tools, static and dynamic analysis tools Ability to automate analysis tasks, develop scripts to decode obfuscated data and network communications, analyze obfuscated code Understanding of software exploits, identifying host- and network-based indicators, using leading forensic tools such as but not limited to Access Data FTK, Guidance EnCase, Paraben P2 eXplorer, X-Ways Forensics, FireEye, Volatility, CloudStrikeKnowledge with using mobility and open source forensic tools like Magnet Axiom, BlackBag Mobilyze, Cellebrite UFED, Paraben E3:DS, The Sleuth Kit (TSK) and Autopsy, BlackBag toolsProficient with malware analysis, sandboxing, and software reverse engineeringExperience with scripting languages such as Python and PowerShellKnowledge of MITRE ATT&CK framework, and its uses within the cybersecurity communityKnowledge of and practical experience of integration of COTS or open source toolsPersonality traits: Naturally curious and inquisitive nature; persistent and determined; loves solving problems and puzzles; analytically rigorous; uncompromising integrityDemonstrated ability to document processesProficiency with MS Office ApplicationsMust be able to work collaboratively across teams and physical locationsWilling to work rotating shiftsMust have a Top Secret Clearance or the ability to obtain a TS/SCI clearanceRequired Certifications:Possess at least one relevant professional designation or related advanced IT certification, but not limited to the following:Certified Information Systems Security Professional (CISSP)GIAC Reverse Engineering Malware (GREM)GIAC Certified Incident Handler (GCIH)GIAC Network Forensic Analyst (GNFA)GIAC Intrusion Analyst (GCIA)Desired Skills:Experience with RSA Netwitness, Splunk, FireEye NX, EX, HX, AX, Carbon Black Response, RSA ArcherCurrent experience with network intrusion detection and response operations (Protect, Defend, Respond and Sustain methodology)Experience in the detection, response, mitigation, and/or reporting of cyber threats affecting client networks and one or more of the following:Experience in computer intrusion analysis and incident responseWorking knowledge of Intrusion detection/protection systemsKnowledge and understanding of network devices, multiple operating systems, and secure architecturesWorking knowledge of network protocols and common servicesSystem log analysisExperience with SIEMS content analysis, development and testing, tools such as NetWitness, Splunk, SumoLogic, QRadarExperience with EDR solutions (Carbon Black, Crowdstrike, FireEye, SentinelOne)Familiarity with packet analysis to include: HTTP Headers & Status codes, SMTP Traffic & Status codes, FTP Traffic & Status CodesExcellent written and verbal communication skillsPrior experience working in any of the following:Security Operations Center (SOC)Network Operations Center (NOC)Computer Incident Response Team (CIRT)Desired Certifications:Possess at least one relevant professional designation or related advanced IT certification, but not limited to the following:GIAC Certified Enterprise Defender (GCED)GIAC Security Expert (GSE)Certified Information Security Manager (CISM)Certified Ethical Hacker (CEH)Required Education (including Major):Bachelor of Science Degree with major in Computer Science/Electrical Engineering, Engineering, Science or related field. Must have a minimum of 5+ years' experience or equivalent education and experience.*Occasional travel within CONUS and OCONUS is requiredBusiness Unit ProfileRaytheon Intelligence & Space delivers the disruptive technologies our customers need to succeed in any domain, against any challenge. A developer of advanced sensors, training, and cyber and software solutions, Raytheon Intelligence & Space provides a decisive advantage to civil, military and commercial customers in more than 40 countries around the world. Headquartered in Arlington, Virginia, the business generated $15 billion in pro forma annual revenue in 2019 and has 39,000 employees worldwide. Raytheon Intelligence & Space is one of four businesses that form Raytheon Technologies Corporation.BusinessIntelligence, Information&Svcs Relocation EligibleNoTalent AreaComputer Engineering, Computer Science, Cyber JobsType Of JobFull TimeJob FunctionInformation Technology Clearance TypeTS/SCI US FLSA ClassificationExempt Work Location: VA - Rosslyn Requisition ID: 165387BRSDL2017