CACI International - Burke, VA

posted 4 months ago

Full-time - Mid Level
Burke, VA
Professional, Scientific, and Technical Services

About the position

CACI is seeking a Cybersecurity Operations Analyst II to support the National Geospatial-Intelligence Agency (NGA) under the Transport & Cybersecurity Services (TCS) contract. This role is critical in providing IT infrastructure services that ensure timely, relevant, and accurate support for national security. The Cybersecurity Operations Analyst II will be responsible for coordinating and implementing tasks related to cybersecurity incident response, which includes performing analysis and documenting response activities. This may involve implementing containment measures, blocking IPs and domains, and disabling user accounts as directed by the Government. The analyst will work closely with various security and counterintelligence offices, including the Security and Installations Directorate and the Insider Threat Office, to conduct advanced investigations and triage incidents. They will also collaborate with other organizations to ensure incidents are reported, contained, and eradicated effectively. The role requires building timelines, documentation, and briefings to inform stakeholders about incident response actions and the impact of adversary activities. In addition to incident response, the Cybersecurity Operations Analyst II will perform malware analysis, develop signatures, and contribute to daily and weekly reports on cybersecurity operations. They will also execute Defensive Cyberspace Operations on behalf of the NGA and conduct digital media analysis to respond to incidents. The position demands a high level of detail in documenting actions taken and analysis performed, ensuring that all activities can be systematically reconstructed. The analyst will also be responsible for developing and maintaining custom scripts and tools for data collection and analysis, as well as providing adversary attribution and identifying indicators of compromise.

Responsibilities

  • Coordinate and implement tasks for cybersecurity incident response.
  • Perform analysis and document response activities during incidents.
  • Implement containment measures, IP blocks, domain blocks, and disable user accounts as directed by the Government.
  • Collaborate with Security and Installations Directorate and Insider Threat Office for incident investigation and triage.
  • Produce security incident reports and categorize incidents and events.
  • Coordinate with other contracts and organizations to ensure proper incident reporting and eradication.
  • Build timelines, documents, and briefings to inform stakeholders of incident response actions.
  • Document actions taken and analysis in the authorized ticketing system.
  • Develop and update reports in the Joint Incident Management System and other authorized reporting systems.
  • Perform digital media analysis on host, server, and network data for incident response.
  • Develop indicators of compromise and provide adversary attribution.
  • Conduct Quality Control reviews of closed CSOC Tier 2 tickets.

Requirements

  • Must be a US Citizen with an Active TS/SCI clearance to start work, required to obtain a CI Poly within 6 months.
  • Typically has a University Degree (BA/BS) or equivalent experience and minimum 4 years of related work experience.
  • All Contractor personnel performing CSOC Tier 3 services must have a certification compliant with DoD 8140.01 and DoD 8570.01-M IAT Level II and CSSP Analyst Certification.
  • Ability to work 1 or more of 5 work shifts.

Nice-to-haves

  • IAT Level III certification.
  • Active TS/SCI with polygraph.
  • 5+ years of related CSOC tier 2 or 3 work experience.

Benefits

  • Comprehensive healthcare coverage.
  • Wellness programs.
  • Financial and retirement benefits.
  • Family support programs.
  • Continuing education opportunities.
  • Flexible time off benefits.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service