Leidos - Scott Air Force Base, IL

posted 22 days ago

Full-time
Scott Air Force Base, IL
Professional, Scientific, and Technical Services

About the position

The Defensive Cyber Operations (DCO) Counter-Measures Engineer at Leidos is responsible for advanced threat detection and hunt engineering, specifically aimed at enhancing cybersecurity measures for the Defense Information Systems Agency (DISA) at Scott Air Force Base, IL. This role involves authoring and deploying countermeasures, assessing their effectiveness, and developing automated cybersecurity solutions to mitigate risks and respond to emerging threats.

Responsibilities

  • Author and deploy novel countermeasures to eliminate threats and illuminate their activities.
  • Assess the effectiveness of countermeasures on an ongoing basis and revector actions as needed.
  • Design and develop solutions to deliver automated cybersecurity services.
  • Conduct agile development & maintenance of automation scripts/tools to scale cybersecurity work across the enterprise.
  • Develop custom integrations, data correlation, and processing strategies to reduce cybersecurity risk.
  • Act as a Subject Matter Expert for the automation team.
  • Maintain situational awareness of cyber activity by reviewing DoD, Intelligence Community, and open-source reporting for new vulnerabilities, malware, or other threats.

Requirements

  • Must have an active DoD Secret clearance and be eligible to obtain TS/SCI.
  • Bachelor's degree in a related discipline with 4+ years of applicable experience; additional related years of experience is accepted in lieu of a degree.
  • DoD-8570 IAT Level 2 baseline certification (Sec+ CE or equivalent) is required to start and CSSP-A certification must be obtained within 180 days of start date.
  • Proficiency in programming in at least one modern language (Java, Python, Ruby, C++).
  • Custom malware detection development experience.
  • Understanding of TCP/IP, networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.
  • Understand the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
  • UNIX Administrative skills.

Nice-to-haves

  • Experience with DISA and DoD Networks.
  • Experience countering APTs or emergent threats to DOD networks.
  • Skilled in developing extended cyber security analytics.
  • Experience in developing and supporting a development environment.
  • Experience automating tasks via Bash, Python, PowerShell, or other scripting tools.
  • Experience in Linux and Windows-based systems administration in a cloud or virtualized environment.
  • Experience with API development and integration.
  • Experience with Git, Sigma, Yara, Snort, and Suricata.
  • Experience with Detection-as-a-Code.
  • Experience with malware analysis concepts and methods.
  • Advanced Certifications such as GREM, OSCP, CISSP or CASP.
Job Description Matching

Match and compare your resume to any job description

Start Matching
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service