CSOC/CERT - Instrusion Detection Analyst (3rd Shift)

7/26/17
ManTech (www.mantech.com)
Other

/yr

  Full Time   Employee   Contractor


Mclean
Virginia
United States

Can you build a team to protect and defend the largest target in the world? This McLean based position will lead Jr. and Mid Level Intrusion Detection Analysts charged with incident response, incident handling, network analysis, threat detection and trend analysis. The Detection Shift Lead will be an individual contributor and team lead to the Shift. Manage day to day scheduling, training and quality control of Analyst work. At ManTech, you will help protect our national security while working on innovative projects that offer opportunities for advancement.
Position Requirements:
Clearance Level: Top Secret SCI ++
Required Experiences/Skills:
? Excellent interpersonal, organizational, writing, communications, and briefing skills
? Strong analytical and problem solving skills
? Minimum of three years of progressively responsible experience in Cyber Security, InfoSec, Security Engineering, Network Engineering with emphasis in cyber security issues and operations, computer incident response, systems architecture, data management
Responsibilities include, but are not limited to:
The CIRT Detection Shift Lead on this agency-level Cyber Security Operations and Engineering support contract provides oversight of a shift of analysts performing the following duties:

? Analyze all relevant cyber security event data and other data sources for attack indicators and potential security breaches; produce report
Assist in coordination during incidents; and coordinate with the O&M team to maintain all security monitoring systems are on-line, up to date, and fully operational
? Monitor intrusion detection and prevention systems and other security event data sources on 24x7x365 basis. Determine if security events monitored should be escalated to incidents and follow all applicable incident response and reporting processes and procedures
? Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs.
? Responsible for tuning and filtering of events and information, creating custom views and content using all available tools following an approved methodology and with approval of concurrence from the Staff management
? Provide support for the Government CIRT Hotline and appropriately document each call in an existing tracking database for this purpose
? Coordinate with the O&M team to ensure production CIRT systems are operational
? Review assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given event
? Establish procedures for handling each security event detected
? Develop and utilize ?Case Management? processes for incident and resolution tracking. The processes should also be used for historic recording of all anomalous or suspicious activity. Currently, processes in place now use the JIRA tool
? Identify misuse, malware, or unauthorized activity on monitored networks. Report the activity appropriately as determined by CIRT Management
? Monitoring and responding to the CIRT e-mail addresses
Required Tools:
Familiarity with the following classes of enterprise cyber defense technologies:

? Security Information and Event Management (SIEM) systems
? Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)
? Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)
? Network and Host malware detection and prevention
? Network and Host forensic applications
? Web/Email gateway security technologies

Required Certifications:
DOD 8570 IAT Level I or CND-IR
Required Degree:
BS (bachelor's degree in electrical engineering, computer engineering, computer science, or other closely related IT discipline)


Security Requirements:
TS/SCI with Poly


Advertisement

 

Save This Job

Email This Job to a Friend