Posted in

Cybersecurity Analyst

Cybersecurity Analyst

CompanyLeidos
LocationScott AFB, IL, USA
Salary$67600 – $122200
TypeFull-Time
DegreesBachelor’s
Experience LevelJunior, Mid Level

Requirements

  • Bachelor’s degree and 2+ years of prior relevant experience (related DISA customer experience and Cyber courses/certifications may be substituted in place of degree)
  • Active DoD 8570, IAT Level II Certification, and CSSP-Analyst1 certification at your start date
  • Demonstrated understanding of the life cycle of network threats, attacks, attack vectors, and methods of exploitation with an understanding of intrusion set tactics, techniques, open-source, and procedures (TTPs)
  • Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
  • Experience and proficiency with any of the following: Anti-Virus, HIPS, ID/PS, Full Packet Capture, Host-Based Forensics, Network Forensics
  • Experience with malware analysis concepts and methods
  • Familiarity or experience in Intelligence Driven Defense
  • Willing to perform rotating shift work

Responsibilities

  • Review DoD and open-source intelligence for threats
  • Identify Indicators of Compromise (IOCs) and integrate those into sensors and SIEMs
  • Triage and review system alerts to identify malicious actors on customer networks
  • Assist T1 analysts with triage and analysis
  • Complete moderate-level analysis of potential cybersecurity events that could threaten IT Systems
  • Report incidents to customers and USCYBERCOM
  • Create complex technical reports on analytic findings

Preferred Qualifications

  • Advanced certifications such as SANS GIAC/GCIA/GCIH, CISSP or CASP and/or SIEM-specific training and certification (Security+ CE, CISSP or equivalent)
  • Demonstrated commitment to training, self-study, and maintaining proficiency in the technical cyber security domain
  • CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization or Security Operations Center
  • In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. Nitro/McAfee Enterprise Security Manager, ArcSight, QRadar, LogLogic, Splunk)