Skip to main content

This job has expired

Cyber Detection Analyst (Incident Response)

Employer
Raventek Solution Partners LLC
Location
Mclean, VA
Closing date
Oct 24, 2021

View more

Description:RavenTek is seeking a Cyber Detection Analyst that specializes in Incident Response. The Cyber Detection Analyst will hone your cyber skills with the latest technologies to take your career to a whole new level. You will help protect our national security while working on innovative projects that offer opportunities for advancement.The Cyber Detection Analyst on this agency-level Cyber Security support contract performs the following duties:Identify misuse, malware, or unauthorized activity on monitored networksAnalyze all relevant cyber security event data and other data sources for attack indicators and potential security breachesAssist in coordination during incidentsIdentify intrusions utilizing various detection and prevention systems and other security event data sources on 24x7x365 basisAnalyze intrusion-related data to determine root cause and identify follow on activity while coordinating with Incident Handlers, Hunters, and various partnersCorrelate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs, to include netflow, metadata, and pcap analysisContributes to tuning and filtering of events and information, creating custom views and content using all available toolsReview assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given eventContribute to the development of playbooks and procedures for handling each security event detected. Requirements:Required Security Clearance: TS/SCI with FSPQualification Requirements:Familiarity with the following classes of enterprise cyber defense technologies:Security Information and Event Management (SIEM) systems.Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS).Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS).Network and Host malware detection and prevention.Network and Host forensic applications.Web/Email gateway security technologies.Sysmon.Log aggregation tools.Strong analytical and problem-solving skills.Excellent interpersonal, organizational, writing, communications, and briefing skills.Required Education and Experience:Bachelor of ScienceMinimum of three years of progressively responsible experience in Cyber Security, InfoSec, Security Engineering, Network Engineering with emphasis in cyber security issues and operations, computer incident response, systems architecture, data management.DOD 8570 IAT Level I or CSSP-AEmployment Type: Full Time / PermanentWorking Conditions:This McLean, VA based position will be fixed shift, 4 days per week (10-hour shifts).Maybe required to COVID vaccine or negative testing requirement.Physical Requirements:Employee needs to be able to sit at a workstation for extended periods; use hand(s) to handle or feel objects, tools, or controls; reach with hands and arms; talk and hear. Most positions require ability to work on desktop or laptop computer for extended periods of time reading, reviewing/analyzing information, and providing recommendations, summaries and/or reports in written format. Must be able to effectively communicate with others verbally and in writing. Employee may be required to occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Regular and predictable attendance is essential.Background Screening/Check/Investigation:Successful Completion of a Background Screening/Check/Investigation will/may be required as a condition of hire.ADA: RavenTek will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990.EEO/AA: RavenTek does not discriminate on the basis of race, color, national origin, sex, religion, age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status in employment or the provision of services and is an equal access/equal opportunity/affirmative action employer.PM20

Get job alerts

Create a job alert and receive personalized job recommendations straight to your inbox.

Create alert