Responsibilities:

    • Assist customer with coordinating preliminary incident response investigations
    • Assist customer interface with external customers
    • Determine appropriate course of action in response to identified and analyses anomalous network activity
    • Assesses network topology and device configurations identifying critical security concerns and providing security best practice recommendations
    • Collect network intrusion artifacts (e.g., PCAP, domains, URI’s, certificates, etc.) and uses discovered data to enable mitigation of potential Computer Network Defense incidents
    • Analyze identified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and information
    • Collect network device integrity data and analyze for signs of tampering or compromise
    • Assist customer with real-time CND incident handling (i.e., forensic collections, intrusion correlation and tracking, threat analysis, and advising on system remediation) tasks to support onsite engagements

    Required Skills:

    • U.S. Citizenship
    • Must have an active TS/SCI clearance
    • Must be able to obtain DHS Suitability
    • 8+ years of directly relevant experience in network investigations
    • In depth knowledge of CND policies, procedures and regulations
    • In depth knowledge of TCP/IP protocols
    • In depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.
    • In depth knowledge and experience of Wifi networking
    • In depth knowledge and experience of network topologies - DMZ’s, WAN’s, etc.
    • Substantial knowledge of Splunk (or other SIEM’s)
    • Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
    • Knowledge of Computer Network Defense policies, procedures, and regulations
    • Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
    • Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
    • Ability to identify and analyze anomalies in network traffic using metadata
    • Experience with reconstructing a malicious attack or activity based on network traffic
    • Experience examining network topologies to understand data flows through the network
    • Must be able to work collaboratively across physical locations

    Desired Skills:

    • Substantial knowledge of network device integrity concepts and methodologies
    • Experience with or knowledge of two or more of the following tools: WireShark, Splunk, Snort, Corelight, Suricata, Arkime
    • Experience with EDR Tools (Crowdstrike, Carbon Black, Etc)
    • Proficiency with virtualized environments
    • Proficiency with conducting all-source research.
    • Proficiency with carving and extracting information from PCAP data
    • Proficiency with non-traditional network traffic (e.g. Command and Control)
    • Familiarity with ICS/SCADA protocols
    • Familiarity with Python or other scripting languages

    Required Education:

    BS Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 10+ years of network investigation experience

    Desired Certifications:

    GCFA, GCFE, EnCE, CCE, CFCE, CISSP, IASAE II, GCIA, GCIH, CSSP Analyst, CSSP Incident Responder, CEH, SANS GIAC GNFA preferred