Cybersecurity Analyst

$96,754 - $130,902/Yr

GD Information Technology, Inc. - Springfield, VA

posted 3 months ago

Full-time - Mid Level
Remote - Springfield, VA
10,001+ employees

About the position

In this role, you will report to the Lead of Focused Operations under the Branch Chief of Defensive Cyber Operations. Your primary responsibility will be to develop and maintain defensive countermeasures for the enterprise. You will work within a Fusion model, collaborating with various teams in Focused Operations to proactively prevent successful compromises and eradicate persistent adversaries already present in the enterprise. This will involve reviewing both future and past intelligence reports, analyzing incident reports, conducting regular Purple Teaming exercises, and continuously validating the effectiveness of deployed Defensive Countermeasures. Your work will include analyzing trends and patterns of data on confidential networks to identify and predict previously undiscovered events and incidents. You will be responsible for developing or tuning rules, signatures, and scripts as necessary. Coordination with Defensive Cyber Operations and other Cybersecurity Operations Services will be essential to investigate potential sources of compromise on enterprise systems. You will also correlate and analyze precursors to incidents, collaborating with the Cyber Data Analytics team to enhance SIEM alert efficiency by evaluating valid alerts and false positives. Additionally, you will work closely with the Cyber Incident Response Team to assess ongoing incident activity, predict adversary responses, and identify locations of compromise to assist with triage. All your work will be documented in the authorized ticketing system with sufficient detail to allow stakeholders to systematically reconstruct your analysis. You will also provide input during recurring meetings and briefings as required.

Responsibilities

  • Develop and maintain defensive countermeasures for the enterprise.
  • Collaborate with teams within Focused Operations to prevent successful compromises.
  • Review intelligence and incident reports to inform defensive strategies.
  • Conduct regular Purple Teaming exercises to validate defensive measures.
  • Analyze trends and patterns of data on confidential networks to identify incidents.
  • Develop or tune rules, signatures, and scripts as needed.
  • Coordinate with Defensive Cyber Operations to enhance cybersecurity measures.
  • Investigate potential sources of compromise on enterprise systems.
  • Correlate and analyze precursors to incidents to improve response strategies.
  • Work with the Cyber Data Analytics team to enhance SIEM alert efficiency.
  • Assess ongoing incident activity to predict adversary responses and locations of compromise.
  • Document all work in the authorized ticketing system with detailed analysis.
  • Provide input to recurring meetings and briefings.

Requirements

  • Must be a US Citizen with an Active TS/SCI clearance.
  • 8+ years of related advanced cybersecurity analytics work experience.
  • Certification compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.
  • Experience with data mining or building queries in a SIEM.
  • Strong understanding of signature development and tuning.
  • Strong understanding of network protocols and analysis with protocol analyzers.
  • Knowledge of static file signatures and their application in developing countermeasures.
  • Good working knowledge of regular expressions.

Benefits

  • Variety of medical plan options, some with Health Savings Accounts.
  • Dental plan options.
  • Vision plan.
  • 401(k) plan with company match.
  • Full flex work weeks where possible.
  • Paid time off plans including vacation, sick and personal time, holidays, paid parental leave, military leave, bereavement leave, and jury duty leave.
  • Short and long-term disability benefits.
  • Life, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service