Loading ...
Loading ...
工作类型: Full-time
Loading ...
工作内容
2022-123327We are seeking Cyber Incident Analyst to join our Incident Response Operation team in support of the U.S. Army Europe Regional CyberCenter (RCC-E) in Wiesbaden, Germany. Working as expert to perform analysis of cyber relate events to detect and deter malicious actors using SIEM technologies focused on the threat to networked weapons platforms and US DoD information networks. Analyzes host and network events to determine the impact on current operations, conduct research to determine advisory capability, and develop analytics based on indicators of compromise to leverage the SIEM. Dissect detailed host data dumps to determine route cause of malicious tool, tactics, and techniques used to compromise the system. Produces high-quality papers, presentations, recommendations, and findings for senior US government intelligence and network operations officials.
Job Duties
- Determine IDS/IPS rule false positives to recommend tuning of rules to reduce noise and inceae fidelity
- Respond to the higher headquarters on incidents and daily reports
- Provide daily updates to Defensive Cyber Operations staff on intrusion detection operation and trends of events causing incidents
- Prepare charts and diagrams to assist in metrics analysis and problem evaluation, and submit recommendations for data mining and analytical solutions
- Write reports of remotely exploitable vulnerabilities to increase customer situational awareness and improve the customer’s cyber security posture
- Assist all sections of the Defensive Cyber Operations team as required in performing Analysis and other duties as assigned
- Travel to customer sites to perform network security evaluations
- May perform documentation and vetting of identified vulnerabilities for operational use
- BA/BS in Engineering, Computer Science, Science, Business Administration or Mathematics. Bachelor degree plus 3 years of specialized experience, or an Associate degree plus 7 years of specialized experience, or a major certification plus 7 years of specialized experience, or 11 years of specialized experience.
- A current TS with SCI Clearance (ICD 706 Eligibility)
- US citizenship required
- Must possess the following Specialized Certifications:
- -- One of DoD 8570 IAT II or higher (SSCP, CCNA-Security, GSEC, Security+ CE)
- -- One of DoD 8570 CSSP Incident Responder (CEH, GCIH, GCFA, CySA+, or other as listed on the DoD 8570)
- -- A current computing environment certification such as MCSA, RHCSA, CCNA, CEH, ArcSight, etc.
- Must have a full, complete, and in-depth understanding of all aspects of Defensive Cyber Operations
- Must be fluent in all aspects of government and corporate communications media to include all MS Office products and common task ticketing systems
- Must have a good breadth of knowledge of common ports and protocols of system and network services
- Experience in packet captures and analyzing a network packet
- Experience with intrusion detection systems such as Snort, Suricata, and Zeek
- Experience with SIEM systems such as Splunk, ArcSight, or Elastic
- Must have the demonstrated ability to communicate with a variety of stakeholders in a variety of formats
- Ability to work independently as well as part of a team
- Ability to work periodically on shift to assist the team
- DoD 8570 IAT III (CISSP, CASP, CISA, GCED, GCIH)
- Experience with writing Snort or Suricata IDS rules
- Experience in developing complex dashboards, report, and automated searches in Splunk, ArcSight, or Elastic/Kibana
- Experience with analyzing packets using Arkime
- Experience with Microsoft Windows event IDs
- Experience with Linux audit log analysis
- Familiarity with Git and VScode
- Experience with one or more scripting languages such as PowerShell, Bash, Python
Colorado Salary Minimum: $68,500
Colorado Salary Maximum: $166,300
The estimate displayed represents the typical salary range for this position, and is just one component of Peraton’s total compensation package for employees. Other rewards may include annual bonuses, short- and long-term incentives, and program-specific awards. In addition, Peraton provides a variety of benefits to
Loading ...
Loading ...
最后期限: 06-12-2024
点击免费申请候选人
报告工作
Loading ...
相同的工作
-
⏰ 09-11-2024🌏 Offenbach, Hesse
-
⏰ 10-11-2024🌏 Fulda, Hesse
-
⏰ 08-11-2024🌏 Wetzlar, Hesse
-
⏰ 16-11-2024🌏 Wiesbaden, Hesse
Loading ...
-
⏰ 13-11-2024🌏 Darmstadt, Hesse
-
⏰ 26-11-2024🌏 Frankfurt am Main, Hesse
-
⏰ 20-11-2024🌏 Eschborn, Hesse
-
⏰ 08-11-2024🌏 Neu Isenburg, Hesse
Loading ...
-
⏰ 08-11-2024🌏 Limburg an der Lahn, Hesse
-
⏰ 08-11-2024🌏 Fulda, Hesse